<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd" pub_date="2012-02-13" nvd_xml_version="1.2">
  <entry type="CVE" severity="High" seq="2006-0001" published="2006-09-12" name="CVE-2006-0001" modified="2011-03-07" discovered="2005-08-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html" source="CERT">TA06-255A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/406236" source="CERT-VN">VU#406236</ref>
      <ref url="http://www.securityfocus.com/bid/19951" source="BID" patch="1">19951</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/445824/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060912 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-054.mspx" source="MS" patch="1">MS06-054</ref>
      <ref url="http://www.computerterrorism.com/research/ct12-09-2006-2.htm" source="MISC" patch="1" adv="1">http://www.computerterrorism.com/research/ct12-09-2006-2.htm</ref>
      <ref url="http://secunia.com/advisories/21863" source="SECUNIA" patch="1" adv="1">21863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28648" source="XF">publisher-pub-code-execution(28648)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3565" source="VUPEN">ADV-2006-3565</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">SSRT061187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">HPSBST02134</ref>
      <ref url="http://securitytracker.com/id?1016825" source="SECTRACK">1016825</ref>
      <ref url="http://securityreason.com/securityalert/1548" source="SREASON">1548</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:590" source="OVAL" sig="1">oval:org.mitre.oval:def:590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0002" published="2006-01-10" name="CVE-2006-0002" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" source="CERT" patch="1" adv="1">TA06-010A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/252146" source="CERT-VN" adv="1">VU#252146</ref>
      <ref url="http://www.securityfocus.com/bid/16197" source="BID" patch="1">16197</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded" source="BUGTRAQ" patch="1">20060110 Microsoft Outlook Critical Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded" source="BUGTRAQ" patch="1">20060110 Microsoft Exchange Critical Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx" source="MS" patch="1" adv="1">MS06-003</ref>
      <ref url="http://securitytracker.com/id?1015461" source="SECTRACK" patch="1">1015461</ref>
      <ref url="http://securitytracker.com/id?1015460" source="SECTRACK" patch="1">1015460</ref>
      <ref url="http://secunia.com/advisories/18368" source="SECUNIA" patch="1" adv="1">18368</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22878" source="XF">win-tnef-overflow(22878)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0119" source="VUPEN" adv="1">ADV-2006-0119</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</ref>
      <ref url="http://securityreason.com/securityalert/331" source="SREASON">331</ref>
      <ref url="http://securityreason.com/securityalert/330" source="SREASON">330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624" source="OVAL" sig="1">oval:org.mitre.oval:def:624</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485" source="OVAL" sig="1">oval:org.mitre.oval:def:1485</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456" source="OVAL" sig="1">oval:org.mitre.oval:def:1456</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316" source="OVAL" sig="1">oval:org.mitre.oval:def:1316</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165" source="OVAL" sig="1">oval:org.mitre.oval:def:1165</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082" source="OVAL" sig="1">oval:org.mitre.oval:def:1082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="5.0" edition="sp1" />
        <vers num="5.0" edition="sp2" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="5.5" edition="sp3" />
        <vers num="5.5" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0003" published="2006-04-11" name="CVE-2006-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT" adv="1">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/234812" source="CERT-VN" adv="1">VU#234812</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx" source="MS" patch="1" adv="1">MS06-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29915" source="XF">ie-wscriptshell-command-execution(29915)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25006" source="XF">mdac-rdsdataspace-execute-code(25006)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2452" source="VUPEN">ADV-2006-2452</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1319" source="VUPEN">ADV-2006-1319</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/20797" source="BID">20797</ref>
      <ref url="http://www.securityfocus.com/bid/17462" source="BID">17462</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487219/100/200/threaded" source="BUGTRAQ">20080128 Re: Exploit in IE6,7</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487216/100/200/threaded" source="BUGTRAQ">20080128 Exploit in IE6,7</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475490/100/100/threaded" source="BUGTRAQ">20070731 Re: Exploit In Internet Explorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475118/100/100/threaded" source="BUGTRAQ">20070730 RE: Exploit In Internet Explorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475108/100/100/threaded" source="BUGTRAQ">20070730 Re: Exploit In Internet Explorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475104/100/100/threaded" source="BUGTRAQ">20070729 Exploit In Internet Explorer</ref>
      <ref url="http://www.osvdb.org/24517" source="OSVDB">24517</ref>
      <ref url="http://www.milw0rm.com/exploits/2164" source="MILW0RM">2164</ref>
      <ref url="http://www.milw0rm.com/exploits/2052" source="MILW0RM">2052</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html</ref>
      <ref url="http://securitytracker.com/id?1015894" source="SECTRACK">1015894</ref>
      <ref url="http://secunia.com/advisories/20719" source="SECUNIA">20719</ref>
      <ref url="http://secunia.com/advisories/19583" source="SECUNIA" adv="1">19583</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1778" source="OVAL" sig="1">oval:org.mitre.oval:def:1778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1742" source="OVAL" sig="1">oval:org.mitre.oval:def:1742</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1511" source="OVAL" sig="1">oval:org.mitre.oval:def:1511</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1323" source="OVAL" sig="1">oval:org.mitre.oval:def:1323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1204" source="OVAL" sig="1">oval:org.mitre.oval:def:1204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="2.5" edition="sp3" />
        <vers num="2.7" edition="sp1" />
        <vers num="2.8" edition="sp1" />
        <vers num="2.8" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0004" published="2006-02-14" name="CVE-2006-0004" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/963628" source="CERT-VN">VU#963628</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-010.mspx" source="MS" patch="1" adv="1">MS06-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0579" source="VUPEN">ADV-2006-0579</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24490" source="XF">powerpoint-tiff-information-disclosure(24490)</ref>
      <ref url="http://www.securityfocus.com/bid/16634" source="BID">16634</ref>
      <ref url="http://securitytracker.com/id?1015632" source="SECTRACK">1015632</ref>
      <ref url="http://secunia.com/advisories/18865" source="SECUNIA">18865</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1555" source="OVAL" sig="1">oval:org.mitre.oval:def:1555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0005" published="2006-02-14" name="CVE-2006-0005" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT">TA06-045A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/692060" source="CERT-VN">VU#692060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24493" source="XF">win-mediaplayer-plugin-embed-bo(24493)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0575" source="VUPEN">ADV-2006-0575</ref>
      <ref url="http://www.securityfocus.com/bid/16644" source="BID">16644</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-006.mspx" source="MS">MS06-006</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393" source="IDEFENSE">20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015628" source="SECTRACK">1015628</ref>
      <ref url="http://secunia.com/advisories/18852" source="SECUNIA" adv="1">18852</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1559" source="OVAL" sig="1">oval:org.mitre.oval:def:1559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows-nt">
        <vers num="2000" />
        <vers num="datacenter_server" edition="sp1" />
        <vers num="datacenter_server" edition="sp2" />
        <vers num="datacenter_server" edition="sp3" />
        <vers num="datacenter_server" edition="sp4" />
        <vers num="xp" edition="sp2" />
        <vers num="xp" edition="sp2:home" />
        <vers num="xp_tablet_pc" edition="sp1" />
        <vers num="xp_tablet_pc" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:pro" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:pro" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:pro" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_advanced_server">
        <vers num="sp1" />
        <vers num="sp2" />
        <vers num="sp3" />
        <vers num="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_edition" />
        <vers num="datacenter_edition_64-bit" />
        <vers num="enterprise_edition" />
        <vers num="enterprise_edition_64-bit" />
        <vers num="standard" />
        <vers num="standard_64-bit" />
        <vers num="web_edition" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2000">
        <vers num="none" />
        <vers num="sp1" />
        <vers num="sp2" />
        <vers num="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="datacenter_sp1" />
        <vers num="enterprise_sp1" />
        <vers num="standard_sp1" />
        <vers num="web_edition_sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition=":pro" />
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:pro" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0006" published="2006-02-14" name="CVE-2006-0006" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT" adv="1">TA06-045A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/291396" source="CERT-VN" adv="1">VU#291396</ref>
      <ref url="http://www.securityfocus.com/bid/16633" source="BID" patch="1">16633</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-005.mspx" source="MS" patch="1" adv="1">MS06-005</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20060214.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20060214.html</ref>
      <ref url="http://securitytracker.com/id?1015627" source="SECTRACK" patch="1">1015627</ref>
      <ref url="http://secunia.com/advisories/18835" source="SECUNIA" patch="1" adv="1">18835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24488" source="XF">win-media-player-bmp-bo(24488)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0574" source="VUPEN" adv="1">ADV-2006-0574</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425158/100/0/threaded" source="BUGTRAQ">20060215 Windows Media Player BMP Heap Overflow (MS06-005)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424983/100/0/threaded" source="BUGTRAQ" adv="1">20060214 [EEYEB-20051017] Windows Media Player BMP Heap Overflow</ref>
      <ref url="http://securityreason.com/securityalert/423" source="SREASON">423</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1661" source="OVAL" sig="1">oval:org.mitre.oval:def:1661</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1598" source="OVAL" sig="1">oval:org.mitre.oval:def:1598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1578" source="OVAL" sig="1">oval:org.mitre.oval:def:1578</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1256" source="OVAL" sig="1">oval:org.mitre.oval:def:1256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="10" />
        <vers num="7.1" />
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0007" published="2006-07-11" name="CVE-2006-0007" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/668564" source="CERT-VN">VU#668564</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx" source="MS" patch="1">MS06-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2757" source="VUPEN">ADV-2006-2757</ref>
      <ref url="http://www.securityfocus.com/bid/18915" source="BID">18915</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439887/100/0/threaded" source="BUGTRAQ">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/27146" source="OSVDB">27146</ref>
      <ref url="http://securitytracker.com/id?1016470" source="SECTRACK">1016470</ref>
      <ref url="http://secunia.com/advisories/21013" source="SECUNIA">21013</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q3/0005.html" source="VULNWATCH">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:21" source="OVAL" sig="1">oval:org.mitre.oval:def:21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0008" published="2006-02-14" name="CVE-2006-0008" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/739844" source="CERT-VN" adv="1">VU#739844</ref>
      <ref url="http://www.securityfocus.com/bid/16643" source="BID" patch="1">16643</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-009.mspx" source="MS" patch="1" adv="1">MS06-009</ref>
      <ref url="http://securitytracker.com/id?1015631" source="SECTRACK" patch="1">1015631</ref>
      <ref url="http://secunia.com/advisories/18859" source="SECUNIA" patch="1" adv="1">18859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24492" source="XF">win-korean-ime-privilege-elevation(24492)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0578" source="VUPEN" adv="1">ADV-2006-0578</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425141/100/0/threaded" source="BUGTRAQ">20060215 Security advisory: Windows IME Vulnerability (MS06-009)</ref>
      <ref url="http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html" source="MISC" adv="1">http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:727" source="OVAL" sig="1">oval:org.mitre.oval:def:727</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1688" source="OVAL" sig="1">oval:org.mitre.oval:def:1688</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1664" source="OVAL" sig="1">oval:org.mitre.oval:def:1664</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1650" source="OVAL" sig="1">oval:org.mitre.oval:def:1650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1595" source="OVAL" sig="1">oval:org.mitre.oval:def:1595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":student_teacher" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0009" published="2006-03-14" name="CVE-2006-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/682820" source="CERT-VN" adv="1">VU#682820</ref>
      <ref url="http://www.securityfocus.com/bid/17000" source="BID" patch="1">17000</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427671/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29009" source="XF">powerpoint-presentation-code-execution(29009)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25009" source="XF">office-routing-slip-bo(25009)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3678" source="VUPEN">ADV-2006-3678</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN">ADV-2006-0950</ref>
      <ref url="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH" source="MISC">http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH</ref>
      <ref url="http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99" source="MISC">http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99</ref>
      <ref url="http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt" source="MISC">http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt</ref>
      <ref url="http://www.securityfocus.com/bid/20059" source="BID">20059</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446425/100/0/threaded" source="BUGTRAQ">20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446370/100/0/threaded" source="BUGTRAQ">20060919 New PowerPoint 0-day Trojan in the wild</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/444051/100/200/threaded" source="BUGTRAQ">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/443890/100/0/threaded" source="BUGTRAQ">20060819 New PowerPoint 0-day and Trojan - FAQ document ready</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432004/30/5340/threaded" source="BUGTRAQ">20060422 PowerPoint Phishing Trojan</ref>
      <ref url="http://www.osvdb.org/23903" source="OSVDB">23903</ref>
      <ref url="http://www.darkreading.com/document.asp?doc_id=101970" source="MISC">http://www.darkreading.com/document.asp?doc_id=101970</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securitytracker.com/id?1016886" source="SECTRACK">1016886</ref>
      <ref url="http://securitytracker.com/id?1016720" source="SECTRACK">1016720</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA">19238</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html" source="FULLDISC">20060919 New PowerPoint 0-day Trojan in the wild</ref>
      <ref url="http://isc.sans.org/diary.php?storyid=1618" source="MISC">http://isc.sans.org/diary.php?storyid=1618</ref>
      <ref url="http://blogs.securiteam.com/?p=559" source="MISC">http://blogs.securiteam.com/?p=559</ref>
      <ref url="http://blogs.securiteam.com/?p=557" source="MISC">http://blogs.securiteam.com/?p=557</ref>
      <ref url="http://blogs.securiteam.com/?author=28" source="MISC">http://blogs.securiteam.com/?author=28</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html" source="FULLDISC">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:798" source="OVAL" sig="1">oval:org.mitre.oval:def:798</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1653" source="OVAL" sig="1">oval:org.mitre.oval:def:1653</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1553" source="OVAL" sig="1">oval:org.mitre.oval:def:1553</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1504" source="OVAL" sig="1">oval:org.mitre.oval:def:1504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2000" />
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0010" published="2006-01-10" name="CVE-2006-0010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" source="CERT">TA06-010A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/915930" source="CERT-VN" adv="1">VU#915930</ref>
      <ref url="http://www.securityfocus.com/bid/16194" source="BID" patch="1">16194</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx" source="MS" patch="1" adv="1">MS06-002</ref>
      <ref url="http://secunia.com/advisories/18365" source="SECUNIA" patch="1" adv="1">18365</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23922" source="XF">win-embedded-fonts-bo(23922)</ref>
      <ref url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525" source="MISC">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0118" source="VUPEN">ADV-2006-0118</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded" source="BUGTRAQ">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/18829" source="OSVDB">18829</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html" source="EEYE">EEYEB20050801</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</ref>
      <ref url="http://securitytracker.com/id?1015459" source="SECTRACK">1015459</ref>
      <ref url="http://secunia.com/advisories/18391" source="SECUNIA" adv="1">18391</ref>
      <ref url="http://secunia.com/advisories/18311" source="SECUNIA" adv="1">18311</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714" source="OVAL" sig="1">oval:org.mitre.oval:def:714</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698" source="OVAL" sig="1">oval:org.mitre.oval:def:698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491" source="OVAL" sig="1">oval:org.mitre.oval:def:1491</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462" source="OVAL" sig="1">oval:org.mitre.oval:def:1462</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185" source="OVAL" sig="1">oval:org.mitre.oval:def:1185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126" source="OVAL" sig="1">oval:org.mitre.oval:def:1126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:advanced_server" />
        <vers num="" edition="sp4:professional" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1" />
        <vers num="3.5.1" edition="sp2" />
        <vers num="3.5.1" edition="sp3" />
        <vers num="3.5.1" edition="sp4" />
        <vers num="3.5.1" edition="sp5" />
        <vers num="3.5.1" edition="sp5:alpha" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":terminal_server_alpha" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":alpha" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:alpha" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:alpha" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:alpha" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:alpha" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:alpha" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6:alpha" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:alpha" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0012" published="2006-04-11" name="CVE-2006-0012" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/641460" source="CERT-VN" adv="1">VU#641460</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-015.mspx" source="MS" patch="1">MS06-015</ref>
      <ref url="http://secunia.com/advisories/19606" source="SECUNIA" patch="1" adv="1">19606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25554" source="XF">win-explorer-com-code-execution(25554)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1320" source="VUPEN">ADV-2006-1320</ref>
      <ref url="http://www.securityfocus.com/bid/17464" source="BID">17464</ref>
      <ref url="http://www.osvdb.org/24516" source="OSVDB">24516</ref>
      <ref url="http://securitytracker.com/id?1015897" source="SECTRACK">1015897</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1764" source="OVAL" sig="1">oval:org.mitre.oval:def:1764</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1743" source="OVAL" sig="1">oval:org.mitre.oval:def:1743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1679" source="OVAL" sig="1">oval:org.mitre.oval:def:1679</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1448" source="OVAL" sig="1">oval:org.mitre.oval:def:1448</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1191" source="OVAL" sig="1">oval:org.mitre.oval:def:1191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0013" published="2006-02-14" name="CVE-2006-0013" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/388900" source="CERT-VN" adv="1">VU#388900</ref>
      <ref url="http://www.securityfocus.com/bid/16636" source="BID" patch="1">16636</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx" source="MS" patch="1">MS06-008</ref>
      <ref url="http://securitytracker.com/id?1015630" source="SECTRACK" patch="1">1015630</ref>
      <ref url="http://secunia.com/advisories/18857" source="SECUNIA" patch="1" adv="1">18857</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24491" source="XF">msrpc-webclient-message-bo(24491)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0577" source="VUPEN">ADV-2006-0577</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:716" source="OVAL" sig="1">oval:org.mitre.oval:def:716</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:683" source="OVAL" sig="1">oval:org.mitre.oval:def:683</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1602" source="OVAL" sig="1">oval:org.mitre.oval:def:1602</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1547" source="OVAL" sig="1">oval:org.mitre.oval:def:1547</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1220" source="OVAL" sig="1">oval:org.mitre.oval:def:1220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0014" published="2006-04-11" name="CVE-2006-0014" modified="2011-03-07" discovered="2005-09-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-016.mspx" source="MS" patch="1">MS06-016</ref>
      <ref url="http://secunia.com/advisories/19617" source="SECUNIA" patch="1" adv="1">19617</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-007.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-06-007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1321" source="VUPEN">ADV-2006-1321</ref>
      <ref url="http://www.securityfocus.com/bid/17459" source="BID">17459</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430645/100/0/threaded" source="BUGTRAQ" adv="1">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25535" source="XF">outlook-express-wab-bo(25535)</ref>
      <ref url="http://securitytracker.com/id?1015898" source="SECTRACK">1015898</ref>
      <ref url="http://securityreason.com/securityalert/691" source="SREASON">691</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html" source="FULLDISC">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:812" source="OVAL" sig="1">oval:org.mitre.oval:def:812</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1791" source="OVAL" sig="1">oval:org.mitre.oval:def:1791</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1780" source="OVAL" sig="1">oval:org.mitre.oval:def:1780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1771" source="OVAL" sig="1">oval:org.mitre.oval:def:1771</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1769" source="OVAL" sig="1">oval:org.mitre.oval:def:1769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1682" source="OVAL" sig="1">oval:org.mitre.oval:def:1682</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1611" source="OVAL" sig="1">oval:org.mitre.oval:def:1611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0015" published="2006-04-11" name="CVE-2006-0015" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17452" source="BID" patch="1">17452</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-017.mspx" source="MS" patch="1">MS06-017</ref>
      <ref url="http://www.argeniss.com/research/ARGENISS-ADV-040602.txt" source="MISC" patch="1" adv="1">http://www.argeniss.com/research/ARGENISS-ADV-040602.txt</ref>
      <ref url="http://securitytracker.com/id?1015896" source="SECTRACK" patch="1">1015896</ref>
      <ref url="http://securitytracker.com/id?1015895" source="SECTRACK" patch="1">1015895</ref>
      <ref url="http://secunia.com/advisories/19623" source="SECUNIA" patch="1" adv="1">19623</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1322" source="VUPEN">ADV-2006-1322</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430803/100/0/threaded" source="BUGTRAQ">20060412 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25537" source="XF">fpse-html-xss(25537)</ref>
      <ref url="http://securityreason.com/securityalert/704" source="SREASON">704</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1748" source="OVAL" sig="1">oval:org.mitre.oval:def:1748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage_server_extensions">
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_team_services">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0018" reject="1" published="2005-11-29" name="CVE-2006-0018" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2006-0019" published="2006-01-20" name="CVE-2006-0019" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422464/100/0/threaded" source="BUGTRAQ" patch="1">20060119 [KDE Security Advisory] kjs encodeuri/decodeuri heap overflow</ref>
      <ref url="http://www.kde.org/info/security/advisory-20060119-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20060119-1.txt</ref>
      <ref url="http://secunia.com/advisories/18500" source="SECUNIA" patch="1" adv="1">18500</ref>
      <ref url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff" source="CONFIRM" patch="1">ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0265" source="VUPEN">ADV-2006-0265</ref>
      <ref url="http://www.ubuntu.com/usn/usn-245-1" source="UBUNTU">USN-245-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422489/100/0/threaded" source="SUSE">SUSE-SA:2006:003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0184.html" source="REDHAT" adv="1">RHSA-2006:0184</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml" source="GENTOO">GLSA-200601-11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-948" source="DEBIAN" adv="1">DSA-948</ref>
      <ref url="http://secunia.com/advisories/18570" source="SECUNIA">18570</ref>
      <ref url="http://secunia.com/advisories/18561" source="SECUNIA" adv="1">18561</ref>
      <ref url="http://secunia.com/advisories/18559" source="SECUNIA">18559</ref>
      <ref url="http://secunia.com/advisories/18552" source="SECUNIA">18552</ref>
      <ref url="http://secunia.com/advisories/18540" source="SECUNIA" adv="1">18540</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11858" source="OVAL">oval:org.mitre.oval:def:11858</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24242" source="XF">kde-kjs-bo(24242)</ref>
      <ref url="http://www.securityfocus.com/bid/16325" source="BID">16325</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.osvdb.org/22659" source="OSVDB">22659</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:019" source="MANDRIVA">MDKSA-2006:019</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.361107" source="SLACKWARE">SSA:2006-045-05</ref>
      <ref url="http://securitytracker.com/id?1015512" source="SECTRACK">1015512</ref>
      <ref url="http://securityreason.com/securityalert/364" source="SREASON">364</ref>
      <ref url="http://secunia.com/advisories/18899" source="SECUNIA">18899</ref>
      <ref url="http://secunia.com/advisories/18583" source="SECUNIA">18583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.0_beta1" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.x" />
        <vers num="3.3" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.x" />
        <vers num="3.4" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0020" published="2006-01-10" name="CVE-2006-0020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/312956" source="CERT-VN" patch="1" adv="1">VU#312956</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT" adv="1">TA06-045A</ref>
      <ref url="http://www.securityfocus.com/bid/16516" source="BID" patch="1">16516</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx" source="MS" patch="1">MS06-004</ref>
      <ref url="http://secunia.com/advisories/18729" source="SECUNIA" patch="1" adv="1">18729</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0469" source="VUPEN">ADV-2006-0469</ref>
      <ref url="http://www.osvdb.org/22976" source="OSVDB">22976</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/913333.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/913333.mspx</ref>
      <ref url="http://secunia.com/advisories/18912" source="SECUNIA" adv="1">18912</ref>
      <ref url="http://linuxbox.org/pipermail/funsec/2006-January/002828.html" source="MLIST" adv="1">[funsec] 20060110 Another WMF flaw without a Microsoft patch</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638" source="OVAL" sig="1">oval:org.mitre.oval:def:1638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0021" published="2006-02-14" name="CVE-2006-0021" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT" adv="1">TA06-045A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/839284" source="CERT-VN" adv="1">VU#839284</ref>
      <ref url="http://www.securityfocus.com/bid/16645" source="BID" patch="1">16645</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-007.mspx" source="MS" patch="1" adv="1">MS06-007</ref>
      <ref url="http://secunia.com/advisories/18853" source="SECUNIA" patch="1" adv="1">18853</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24489" source="XF">win-igmpv3-dos(24489)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0576" source="VUPEN" adv="1">ADV-2006-0576</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482658/30/4350/threaded" source="BUGTRAQ">20071023 SYMSA-2007-012: Microsoft Windows CE IGMP Denial of Service</ref>
      <ref url="http://www.securiteam.com/exploits/5PP0T0KI0O.html" source="MISC">http://www.securiteam.com/exploits/5PP0T0KI0O.html</ref>
      <ref url="http://www.milw0rm.com/exploits/1599" source="MILW0RM">1599</ref>
      <ref url="http://securitytracker.com/id?1015629" source="SECTRACK">1015629</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:678" source="OVAL" sig="1">oval:org.mitre.oval:def:678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1662" source="OVAL" sig="1">oval:org.mitre.oval:def:1662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1647" source="OVAL" sig="1">oval:org.mitre.oval:def:1647</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1425" source="OVAL" sig="1">oval:org.mitre.oval:def:1425</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1310" source="OVAL" sig="1">oval:org.mitre.oval:def:1310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0022" published="2006-06-13" name="CVE-2006-0022" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" source="CERT">TA06-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/190089" source="CERT-VN">VU#190089</ref>
      <ref url="http://www.securityfocus.com/bid/18382" source="BID" patch="1">18382</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-028.mspx" source="MS" patch="1" adv="1">MS06-028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26784" source="XF">powerpoint-record-bo(26784)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2325" source="VUPEN" adv="1">ADV-2006-2325</ref>
      <ref url="http://www.osvdb.org/26435" source="OSVDB">26435</ref>
      <ref url="http://securitytracker.com/id?1016287" source="SECTRACK">1016287</ref>
      <ref url="http://secunia.com/advisories/20633" source="SECUNIA" adv="1">20633</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1984" source="OVAL" sig="1">oval:org.mitre.oval:def:1984</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1836" source="OVAL" sig="1">oval:org.mitre.oval:def:1836</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1069" source="OVAL" sig="1">oval:org.mitre.oval:def:1069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0023" published="2006-02-07" name="CVE-2006-0023" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/953860" source="CERT-VN" adv="1">VU#953860</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-011.mspx" source="MS" patch="1">MS06-011</ref>
      <ref url="http://secunia.com/advisories/18756" source="SECUNIA" patch="1" adv="1">18756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24463" source="XF">win-auth-users-insecure-permissions(24463)</ref>
      <ref url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID=" source="CONFIRM">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID=</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0417" source="VUPEN" adv="1">ADV-2006-0417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded" source="BUGTRAQ">20060131 Windows Access Control Demystified</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/914457.mspx" source="MISC" adv="1">http://www.microsoft.com/technet/security/advisory/914457.mspx</ref>
      <ref url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf" source="MISC">http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securitytracker.com/id?1015765" source="SECTRACK">1015765</ref>
      <ref url="http://securitytracker.com/id?1015595" source="SECTRACK">1015595</ref>
      <ref url="http://secunia.com/advisories/19313" source="SECUNIA" adv="1">19313</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1696" source="OVAL" sig="1">oval:org.mitre.oval:def:1696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1671" source="OVAL" sig="1">oval:org.mitre.oval:def:1671</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0024" published="2006-03-15" name="CVE-2006-0024" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html" source="CERT">TA06-129A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-075A.html" source="CERT">TA06-075A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/945060" source="CERT-VN">VU#945060</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html</ref>
      <ref url="http://secunia.com/advisories/19218" source="SECUNIA" patch="1" adv="1">19218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25005" source="XF">macromedia-swf-code-execution(25005)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1744" source="VUPEN">ADV-2006-1744</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1262" source="VUPEN">ADV-2006-1262</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0952" source="VUPEN">ADV-2006-0952</ref>
      <ref url="http://www.securityfocus.com/bid/17106" source="BID">17106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0268.html" source="REDHAT" adv="1">RHSA-2006:0268</ref>
      <ref url="http://www.osvdb.org/23908" source="OSVDB">23908</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/854/" source="CONFIRM">http://www.opera.com/docs/changelogs/windows/854/</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_15_flashplayer.html" source="SUSE">SUSE-SA:2006:015</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-020.mspx" source="MS">MS06-020</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-20.xml" source="GENTOO">GLSA-200603-20</ref>
      <ref url="http://securitytracker.com/id?1015770" source="SECTRACK">1015770</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA">28136</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
      <ref url="http://secunia.com/advisories/20045" source="SECUNIA">20045</ref>
      <ref url="http://secunia.com/advisories/19328" source="SECUNIA">19328</ref>
      <ref url="http://secunia.com/advisories/19259" source="SECUNIA">19259</ref>
      <ref url="http://secunia.com/advisories/19198" source="SECUNIA">19198</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE">APPLE-SA-2006-05-11</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1922" source="OVAL" sig="1">oval:org.mitre.oval:def:1922</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1894" source="OVAL" sig="1">oval:org.mitre.oval:def:1894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="flash_player">
        <vers num="4.0_r12" />
        <vers num="5.0" />
        <vers num="5.0_r50" />
        <vers num="6.0" />
        <vers num="6.0.29.0" />
        <vers num="6.0.40.0" />
        <vers num="6.0.47.0" />
        <vers num="6.0.65.0" />
        <vers num="6.0.79.0" />
        <vers num="7.0.19.0" />
        <vers num="7.0.60.0" />
        <vers num="7.0.61.0" />
        <vers num="7.0_r19" />
        <vers prev="1" num="8.0.22.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0025" published="2006-06-13" name="CVE-2006-0025" modified="2011-03-07" discovered="2006-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" source="CERT">TA06-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/608020" source="CERT-VN">VU#608020</ref>
      <ref url="http://www.securityfocus.com/bid/18385" source="BID" patch="1">18385</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-024.mspx" source="MS" patch="1" adv="1">MS06-024</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406" source="IDEFENSE" patch="1" adv="1">20060613 Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow</ref>
      <ref url="http://secunia.com/advisories/20626" source="SECUNIA" patch="1" adv="1">20626</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26788" source="XF">win-media-player-png-bo(26788)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2322" source="VUPEN">ADV-2006-2322</ref>
      <ref url="http://www.osvdb.org/26430" source="OSVDB">26430</ref>
      <ref url="http://securitytracker.com/id?1016284" source="SECTRACK">1016284</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1974" source="OVAL" sig="1">oval:org.mitre.oval:def:1974</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1820" source="OVAL" sig="1">oval:org.mitre.oval:def:1820</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1807" source="OVAL" sig="1">oval:org.mitre.oval:def:1807</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1805" source="OVAL" sig="1">oval:org.mitre.oval:def:1805</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1729" source="OVAL" sig="1">oval:org.mitre.oval:def:1729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1230" source="OVAL" sig="1">oval:org.mitre.oval:def:1230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0026" published="2006-07-11" name="CVE-2006-0026" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/395588" source="CERT-VN" patch="1">VU#395588</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26796" source="XF" patch="1">iis-asp-bo(26796)</ref>
      <ref url="http://www.securityfocus.com/bid/18858" source="BID" patch="1">18858</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx" source="MS" patch="1" adv="1">MS06-034</ref>
      <ref url="http://securitytracker.com/id?1016466" source="SECTRACK" patch="1">1016466</ref>
      <ref url="http://secunia.com/advisories/21006" source="SECUNIA" patch="1" adv="1">21006</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2752" source="VUPEN">ADV-2006-2752</ref>
      <ref url="http://www.osvdb.org/27152" source="OSVDB">27152</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html" source="BUGTRAQ">20060718 ASP.DLL Include File Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:435" source="OVAL" sig="1">oval:org.mitre.oval:def:435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0027" published="2006-05-09" name="CVE-2006-0027" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html" source="CERT" patch="1">TA06-129A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/303452" source="CERT-VN" patch="1">VU#303452</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-019.mspx" source="MS" patch="1">MS06-019</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25556" source="XF">exchange-calendar-code-execution(25556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1743" source="VUPEN" adv="1">ADV-2006-1743</ref>
      <ref url="http://www.securityfocus.com/bid/17908" source="BID">17908</ref>
      <ref url="http://www.osvdb.org/25338" source="OSVDB">25338</ref>
      <ref url="http://securitytracker.com/id?1016048" source="SECTRACK">1016048</ref>
      <ref url="http://secunia.com/advisories/20029" source="SECUNIA" adv="1">20029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2035" source="OVAL" sig="1">oval:org.mitre.oval:def:2035</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1996" source="OVAL" sig="1">oval:org.mitre.oval:def:1996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1818" source="OVAL" sig="1">oval:org.mitre.oval:def:1818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0028" published="2006-03-14" name="CVE-2006-0028" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/339878" source="CERT-VN" adv="1">VU#339878</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25225" source="XF">excel-parsing-format-file-bo(25225)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-004.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-004.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427632/100/0/threaded" source="BUGTRAQ" adv="1">20060314 ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability</ref>
      <ref url="http://www.osvdb.org/23899" source="OSVDB">23899</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securityreason.com/securityalert/583" source="SREASON">583</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1635" source="OVAL" sig="1">oval:org.mitre.oval:def:1635</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1509" source="OVAL" sig="1">oval:org.mitre.oval:def:1509</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1411" source="OVAL" sig="1">oval:org.mitre.oval:def:1411</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1158" source="OVAL" sig="1">oval:org.mitre.oval:def:1158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0029" published="2006-03-14" name="CVE-2006-0029" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/235774" source="CERT-VN" adv="1">VU#235774</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25227" source="XF">excel-description-bo(25227)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.osvdb.org/23900" source="OSVDB">23900</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securityreason.com/securityalert/586" source="SREASON">586</ref>
      <ref url="http://securityreason.com/securityalert/585" source="SREASON">585</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1633" source="OVAL" sig="1">oval:org.mitre.oval:def:1633</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1579" source="OVAL" sig="1">oval:org.mitre.oval:def:1579</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1570" source="OVAL" sig="1">oval:org.mitre.oval:def:1570</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1522" source="OVAL" sig="1">oval:org.mitre.oval:def:1522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0030" published="2006-03-14" name="CVE-2006-0030" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/123222" source="CERT-VN" adv="1">VU#123222</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25229" source="XF">excel-graphic-bo(25229)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.securityfocus.com/bid/16181" source="BID">16181</ref>
      <ref url="http://www.osvdb.org/23901" source="OSVDB">23901</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1666" source="OVAL" sig="1">oval:org.mitre.oval:def:1666</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1630" source="OVAL" sig="1">oval:org.mitre.oval:def:1630</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1510" source="OVAL" sig="1">oval:org.mitre.oval:def:1510</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1401" source="OVAL" sig="1">oval:org.mitre.oval:def:1401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0031" published="2006-03-14" name="CVE-2006-0031" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/104302" source="CERT-VN" adv="1">VU#104302</ref>
      <ref url="http://www.securityfocus.com/bid/17101" source="BID" patch="1">17101</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25228" source="XF">excel-record-bo(25228)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427699/100/0/threaded" source="BUGTRAQ">20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/23902" source="OSVDB">23902</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securityreason.com/securityalert/589" source="SREASON">589</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html" source="FULLDISC">20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:763" source="OVAL" sig="1">oval:org.mitre.oval:def:763</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1750" source="OVAL" sig="1">oval:org.mitre.oval:def:1750</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1525" source="OVAL" sig="1">oval:org.mitre.oval:def:1525</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1327" source="OVAL" sig="1">oval:org.mitre.oval:def:1327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0032" published="2006-09-12" name="CVE-2006-0032" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the Indexing service is accessible through IIS.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html" source="CERT">TA06-255A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/108884" source="CERT-VN">VU#108884</ref>
      <ref url="http://www.securityfocus.com/bid/19927" source="BID" patch="1">19927</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-053.mspx" source="MS" patch="1">MS06-053</ref>
      <ref url="http://secunia.com/advisories/21861" source="SECUNIA" patch="1" adv="1">21861</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28651" source="XF">ms-indexing-service-xss(28651)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3564" source="VUPEN">ADV-2006-3564</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447511/100/0/threaded" source="BUGTRAQ">20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447509/100/0/threaded" source="BUGTRAQ">20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">SSRT061187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">HPSBST02134</ref>
      <ref url="http://www.geocities.jp/ptrs_sec/advisory09e.html" source="MISC">http://www.geocities.jp/ptrs_sec/advisory09e.html</ref>
      <ref url="http://securitytracker.com/id?1016826" source="SECTRACK">1016826</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:535" source="OVAL" sig="1">oval:org.mitre.oval:def:535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
        <vers num="resource_kit" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_edition" edition="sp1" />
        <vers num="datacenter_edition" edition="sp1_beta_1" />
        <vers num="datacenter_edition_itanium" edition="sp1" />
        <vers num="datacenter_edition_itanium" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" />
        <vers num="enterprise_edition" edition="sp1" />
        <vers num="enterprise_edition" edition="sp1_beta_1" />
        <vers num="enterprise_edition_itanium" edition="sp1" />
        <vers num="enterprise_edition_itanium" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":enterprise" />
        <vers num="standard" edition="sp1" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0033" published="2006-07-11" name="CVE-2006-0033" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/459388" source="CERT-VN">VU#459388</ref>
      <ref url="http://www.securityfocus.com/bid/18913" source="BID" patch="1">18913</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx" source="MS" patch="1">MS06-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2757" source="VUPEN" adv="1">ADV-2006-2757</ref>
      <ref url="http://www.osvdb.org/27147" source="OSVDB">27147</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html" source="MISC">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html</ref>
      <ref url="http://securitytracker.com/id?1016470" source="SECTRACK">1016470</ref>
      <ref url="http://secunia.com/advisories/21013" source="SECUNIA" adv="1">21013</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:163" source="OVAL" sig="1">oval:org.mitre.oval:def:163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0034" published="2006-05-09" name="CVE-2006-0034" modified="2011-10-17" discovered="2005-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17906" source="BID" patch="1">17906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433430/100/0/threaded" source="BUGTRAQ" patch="1">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx" source="MS" patch="1">MS06-018</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20060509a.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20060509a.html</ref>
      <ref url="http://secunia.com/advisories/20000" source="SECUNIA" patch="1" adv="1">20000</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25559" source="XF">msdtc-network-message-dos(25559)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1742" source="VUPEN" adv="1">ADV-2006-1742</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433677/100/0/threaded" source="BUGTRAQ">20060511 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref>
      <ref url="http://www.osvdb.org/25335" source="OSVDB">25335</ref>
      <ref url="http://securitytracker.com/id?1016047" source="SECTRACK">1016047</ref>
      <ref url="http://securityreason.com/securityalert/863" source="SREASON">863</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0269.html" source="FULLDISC">20060510 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0238.html" source="FULLDISC">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1908" source="OVAL" sig="1">oval:org.mitre.oval:def:1908</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1477" source="OVAL" sig="1">oval:org.mitre.oval:def:1477</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1222" source="OVAL" sig="1">oval:org.mitre.oval:def:1222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="distributed_transaction_coordinator">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0035" published="2006-01-11" name="CVE-2006-0035" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX" patch="1">2006-0004</ref>
      <ref url="http://secunia.com/advisories/18482" source="SECUNIA" patch="1" adv="1">18482</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24202" source="XF">kernel-afnetlink-dos(24202)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0220" source="VUPEN" adv="1">ADV-2006-0220</ref>
      <ref url="http://www.securityfocus.com/bid/16414" source="BID">16414</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961" source="CONFIRM" adv="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.14" />
        <vers num="2.6.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0036" published="2006-01-23" name="CVE-2006-0036" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0220" source="VUPEN">ADV-2006-0220</ref>
      <ref url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab" source="CONFIRM">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24203" source="XF">kernel-pptpincallrequest-dos(24203)</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16414" source="BID">16414</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
      <ref url="http://secunia.com/advisories/18482" source="SECUNIA">18482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0037" published="2006-01-23" name="CVE-2006-0037" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from pointer arithmetic when non-linear SKBs (socket buffers) are used.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0220" source="VUPEN">ADV-2006-0220</ref>
      <ref url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710" source="CONFIRM">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24204" source="XF">kernel-pptpnathelper-dos(24204)</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16414" source="BID">16414</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
      <ref url="http://secunia.com/advisories/18482" source="SECUNIA">18482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0038" published="2006-03-22" name="CVE-2006-0038" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.</descript>
    </desc>
    <sols>
      <sol source="nvd">Linux kernel version 2.6.16 has been released to address this issue.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17178" source="BID" patch="1">17178</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25400" source="XF">linux-netfilter-doreplace-overflow(25400)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1046" source="VUPEN">ADV-2006-1046</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/19330" source="SECUNIA">19330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10945" source="OVAL">oval:org.mitre.oval:def:10945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0039" published="2006-05-19" name="CVE-2006-0039" modified="2011-03-07" discovered="2006-05-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="1.9" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13" source="MISC" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=133465" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=133465</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26583" source="XF">linux-doaddcounters-race-condition(26583)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1893" source="VUPEN">ADV-2006-1893</ref>
      <ref url="http://www.ubuntu.com/usn/usn-311-1" source="UBUNTU">USN-311-1</ref>
      <ref url="http://www.securityfocus.com/bid/18113" source="BID">18113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0689.html" source="REDHAT">RHSA-2006:0689</ref>
      <ref url="http://www.osvdb.org/25697" source="OSVDB">25697</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm</ref>
      <ref url="http://secunia.com/advisories/22945" source="SECUNIA">22945</ref>
      <ref url="http://secunia.com/advisories/22292" source="SECUNIA">22292</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/20991" source="SECUNIA">20991</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20185" source="SECUNIA">20185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10309" source="OVAL">oval:org.mitre.oval:def:10309</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0040" published="2006-03-09" name="CVE-2006-0040" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0801" source="VUPEN">ADV-2006-0801</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426452/100/0/threaded" source="BUGTRAQ">20060301 Evolution Emailer DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25050" source="XF">evolution-email-dos(25050)</ref>
      <ref url="http://www.securityfocus.com/bid/16899" source="BID">16899</ref>
      <ref url="http://secunia.com/advisories/19094" source="SECUNIA">19094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution">
        <vers num="2.4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0042" published="2006-02-18" name="CVE-2006-0042" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16710" source="BID" patch="1">16710</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1000" source="DEBIAN" patch="1" adv="1">DSA-1000</ref>
      <ref url="http://secunia.com/advisories/19139" source="SECUNIA" patch="1" adv="1">19139</ref>
      <ref url="http://secunia.com/advisories/18846" source="SECUNIA" patch="1" adv="1">18846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24917" source="XF">libapreq2-parsing-dos(24917)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0645" source="VUPEN" adv="1">ADV-2006-0645</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml" source="GENTOO">GLSA-200604-08</ref>
      <ref url="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup" source="CONFIRM">http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup</ref>
      <ref url="http://securityreason.com/securityalert/737" source="SREASON">737</ref>
      <ref url="http://secunia.com/advisories/19658" source="SECUNIA" adv="1">19658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libapreq2" name="libapreq2">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.33" />
        <vers num="2.01_dev" />
        <vers num="2.02_dev" />
        <vers num="2.03_dev" />
        <vers num="2.04_dev" />
        <vers num="2.05_dev" />
        <vers num="2.06_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0043" published="2006-01-30" name="CVE-2006-0043" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18638" source="SECUNIA" patch="1" adv="1">18638</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jan/0007.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24347" source="XF">nfs-rpcmountd-realpath-bo(24347)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0348" source="VUPEN">ADV-2006-0348</ref>
      <ref url="http://www.securityfocus.com/bid/16388" source="BID">16388</ref>
      <ref url="http://secunia.com/advisories/18614" source="SECUNIA" adv="1">18614</ref>
      <ref url="http://www.debian.org/security/2006/dsa-975" source="DEBIAN">DSA-975</ref>
      <ref url="http://secunia.com/advisories/18889" source="SECUNIA">18889</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":professional" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":personal" />
        <vers num="9.1" edition=":professional" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":professional" />
        <vers num="9.2" edition=":personal" />
        <vers num="9.2" edition=":x86_64" />
        <vers num="9.3" edition="" />
        <vers num="9.3" edition=":x86_64" />
        <vers num="9.3" edition=":personal" />
        <vers num="9.3" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0044" published="2006-01-17" name="CVE-2006-0044" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the "handling of submitted form fields".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-942" source="DEBIAN" patch="1" adv="1">DSA-942</ref>
      <ref url="http://secunia.com/advisories/18457" source="SECUNIA" patch="1" adv="1">18457</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0196" source="VUPEN">ADV-2006-0196</ref>
      <ref url="http://www.securityfocus.com/bid/16252" source="BID">16252</ref>
      <ref url="http://www.object-craft.com.au/projects/albatross/news.html" source="CONFIRM">http://www.object-craft.com.au/projects/albatross/news.html</ref>
      <ref url="http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz" source="MISC">http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24130" source="XF">albatross-context-command-execution(24130)</ref>
      <ref url="http://www.osvdb.org/22451" source="OSVDB">22451</ref>
      <ref url="http://secunia.com/advisories/18496" source="SECUNIA">18496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="albatross" name="albatross">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.10" />
        <vers num="1.20" />
        <vers num="1.30" />
        <vers num="1.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0045" published="2006-01-20" name="CVE-2006-0045" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-949" source="DEBIAN" patch="1" adv="1">DSA-949</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0303" source="VUPEN">ADV-2006-0303</ref>
      <ref url="http://www.securityfocus.com/bid/16337" source="BID">16337</ref>
      <ref url="http://secunia.com/advisories/18545" source="SECUNIA" adv="1">18545</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24262" source="XF">crawl-insecure-command-execution(24262)</ref>
      <ref url="http://www.osvdb.org/22690" source="OSVDB">22690</ref>
      <ref url="http://secunia.com/advisories/18573" source="SECUNIA">18573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linley_henzell" name="dungeon_crawl">
        <vers num="4.0.0_b23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0046" published="2006-02-13" name="CVE-2006-0046" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-966" source="DEBIAN" patch="1" adv="1">DSA-966</ref>
      <ref url="http://secunia.com/advisories/18777" source="SECUNIA" patch="1" adv="1">18777</ref>
      <ref url="http://secunia.com/advisories/18771" source="SECUNIA" patch="1" adv="1">18771</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0491" source="VUPEN">ADV-2006-0491</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1</ref>
      <ref url="http://adzapper.sourceforge.net/cvslog.html" source="CONFIRM">http://adzapper.sourceforge.net/cvslog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24640" source="XF">adzapper-squid-redirect-dos(24640)</ref>
      <ref url="http://www.securityfocus.com/bid/16558" source="BID">16558</ref>
      <ref url="http://www.osvdb.org/22900" source="OSVDB">22900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cameron_simpson" name="adzapper">
        <vers num="2006-01-01" />
        <vers num="2006-01-05" />
        <vers num="2006-01-07" />
        <vers num="2006-01-14" />
        <vers num="2006-01-15" />
        <vers num="2006-01-23" />
        <vers num="2006-01-24" />
        <vers num="2006-01-25" />
        <vers num="2006-01-28" />
        <vers num="2006-01-29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0047" published="2006-03-07" name="CVE-2006-0047" modified="2011-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16975" source="BID" patch="1">16975</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426866/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060306 Out of memory crash in Freeciv 2.0.7</ref>
      <ref url="http://secunia.com/advisories/19120" source="SECUNIA" patch="1" adv="1">19120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25166" source="XF">freeciv-packets-dos(25166)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0838" source="VUPEN" adv="1">ADV-2006-0838</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:053" source="MANDRIVA">MDKSA-2006:053</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-11.xml" source="GENTOO">GLSA-200603-11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-994" source="DEBIAN">DSA-994</ref>
      <ref url="http://secunia.com/advisories/19253" source="SECUNIA" adv="1">19253</ref>
      <ref url="http://secunia.com/advisories/19227" source="SECUNIA" adv="1">19227</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeciv" name="freeciv">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0048" published="2006-04-25" name="CVE-2006-0048" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Francesco Stablum tcpick 0.2.1 allows remote attackers to cause a denial of service (segmentation fault) via certain fragmented packets, possibly involving invalid headers and an attacker-controlled payload length.  NOTE: this issue might be a buffer overflow or overread.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1466" source="VUPEN">ADV-2006-1466</ref>
      <ref url="http://www.securityfocus.com/bid/17665" source="BID">17665</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151" source="MISC">http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26090" source="XF">tcpick-writec-dos(26090)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francesco_stablum" name="tcpick">
        <vers num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0049" published="2006-03-13" name="CVE-2006-0049" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17058" source="BID" patch="1">17058</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427324/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060309 GnuPG does not detect injection of unsigned data</ref>
      <ref url="http://www.osvdb.org/23790" source="OSVDB" patch="1">23790</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-08</ref>
      <ref url="http://www.debian.org/security/2006/dsa-993" source="DEBIAN" patch="1" adv="1">DSA-993</ref>
      <ref url="http://securitytracker.com/id?1015749" source="SECTRACK" patch="1">1015749</ref>
      <ref url="http://secunia.com/advisories/19173" source="SECUNIA" patch="1" adv="1">19173</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html" source="MLIST" patch="1" adv="1">[gnupg-announce] 20060309 [Announce] GnuPG does not detect injection of unsigned data</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0915" source="VUPEN">ADV-2006-0915</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-264-1" source="UBUNTU">USN-264-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10063" source="OVAL">oval:org.mitre.oval:def:10063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25184" source="XF">gnupg-nondetached-sig-verification(25184)</ref>
      <ref url="http://www.trustix.org/errata/2006/0014" source="TRUSTIX">2006-0014</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477" source="SLACKWARE">SSA:2006-072-02</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded" source="FEDORA">FLSA-2006:185355</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0266.html" source="REDHAT">RHSA-2006:0266</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html" source="FEDORA">FEDORA-2006-147</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:055" source="MANDRIVA">MDKSA-2006:055</ref>
      <ref url="http://securityreason.com/securityalert/568" source="SREASON">568</ref>
      <ref url="http://securityreason.com/securityalert/450" source="SREASON">450</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="http://secunia.com/advisories/19287" source="SECUNIA">19287</ref>
      <ref url="http://secunia.com/advisories/19249" source="SECUNIA">19249</ref>
      <ref url="http://secunia.com/advisories/19244" source="SECUNIA">19244</ref>
      <ref url="http://secunia.com/advisories/19234" source="SECUNIA">19234</ref>
      <ref url="http://secunia.com/advisories/19232" source="SECUNIA">19232</ref>
      <ref url="http://secunia.com/advisories/19231" source="SECUNIA">19231</ref>
      <ref url="http://secunia.com/advisories/19203" source="SECUNIA">19203</ref>
      <ref url="http://secunia.com/advisories/19197" source="SECUNIA">19197</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html" source="SUSE">SUSE-SA:2006:014</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3b" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0050" published="2006-03-23" name="CVE-2006-0050" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1013" source="DEBIAN" patch="1" adv="1">DSA-1013</ref>
      <ref url="http://secunia.com/advisories/19318" source="SECUNIA" patch="1" adv="1">19318</ref>
      <ref url="http://www.securityfocus.com/bid/17182" source="BID">17182</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25442" source="XF">snmptrapfmt-log-temprary-file(25442)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0051" published="2006-04-05" name="CVE-2006-0051" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is "fetching remote playlists", which triggers the overflow in the http_peek function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20060404-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20060404-1.txt</ref>
      <ref url="http://secunia.com/advisories/19525" source="SECUNIA" patch="1" adv="1">19525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25631" source="XF">kaffeine-http-peek-bo(25631)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1229" source="VUPEN">ADV-2006-1229</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-268-1" source="UBUNTU">USN-268-1</ref>
      <ref url="http://www.securityfocus.com/bid/17372" source="BID">17372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430319/100/0/threaded" source="BUGTRAQ">20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_sr.html" source="SUSE">SUSE-SR:2006:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-04.xml" source="GENTOO">GLSA-200604-04</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1023" source="DEBIAN">DSA-1023</ref>
      <ref url="http://securitytracker.com/id?1015863" source="SECTRACK">1015863</ref>
      <ref url="http://secunia.com/advisories/19571" source="SECUNIA">19571</ref>
      <ref url="http://secunia.com/advisories/19557" source="SECUNIA">19557</ref>
      <ref url="http://secunia.com/advisories/19549" source="SECUNIA">19549</ref>
      <ref url="http://secunia.com/advisories/19542" source="SECUNIA">19542</ref>
      <ref url="http://secunia.com/advisories/19540" source="SECUNIA">19540</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:065" source="MANDRIVA">MDKSA-2006:065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaffeine" name="kaffeine_player">
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.3b" />
        <vers num="0.5_rc1" />
        <vers num="0.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0052" published="2006-03-31" name="CVE-2006-0052" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17311" source="BID" patch="1">17311</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9475" source="OVAL">oval:org.mitre.oval:def:9475</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-267-1" source="UBUNTU">USN-267-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0486.html" source="REDHAT">RHSA-2006:0486</ref>
      <ref url="http://www.osvdb.org/24367" source="OSVDB">24367</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_sr.html" source="SUSE">SUSE-SR:2006:008</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:061" source="MANDRIVA">MDKSA-2006:061</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1027" source="DEBIAN">DSA-1027</ref>
      <ref url="http://securitytracker.com/id?1015851" source="SECTRACK">1015851</ref>
      <ref url="http://secunia.com/advisories/20782" source="SECUNIA">20782</ref>
      <ref url="http://secunia.com/advisories/20624" source="SECUNIA">20624</ref>
      <ref url="http://secunia.com/advisories/19571" source="SECUNIA">19571</ref>
      <ref url="http://secunia.com/advisories/19545" source="SECUNIA">19545</ref>
      <ref url="http://secunia.com/advisories/19522" source="SECUNIA">19522</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" source="SGI">20060602-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" edition="beta3" />
        <vers num="2.0" edition="beta4" />
        <vers num="2.0" edition="beta5" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0053" published="2006-04-10" name="CVE-2006-0053" modified="2011-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17415" source="BID" patch="1">17415</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1028" source="DEBIAN" patch="1" adv="1">DSA-1028</ref>
      <ref url="http://secunia.com/advisories/19577" source="SECUNIA" patch="1" adv="1">19577</ref>
      <ref url="http://secunia.com/advisories/19575" source="SECUNIA" patch="1" adv="1">19575</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25717" source="XF">imager-jpeg-tga-dos(25717)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1294" source="VUPEN" adv="1">ADV-2006-1294</ref>
      <ref url="http://rt.cpan.org/Public/Bug/Display.html?id=18397" source="MISC">http://rt.cpan.org/Public/Bug/Display.html?id=18397</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tony_cook" name="imager">
        <vers num="0.41" />
        <vers num="0.42" />
        <vers num="0.43" />
        <vers num="0.44_1" />
        <vers num="0.45" />
        <vers num="0.45_2" />
        <vers num="0.47" />
        <vers num="0.48" />
        <vers num="0.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0054" published="2006-01-11" name="CVE-2006-0054" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16209" source="BID" patch="1">16209</ref>
      <ref url="http://secunia.com/advisories/18378" source="SECUNIA" patch="1" adv="1">18378</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc" source="FREEBSD">FreeBSD-SA-06:04</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24073" source="XF">ipfw-icmp-fragment-dos(24073)</ref>
      <ref url="http://www.osvdb.org/22319" source="OSVDB">22319</ref>
      <ref url="http://securitytracker.com/id?1015477" source="SECTRACK">1015477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.0" edition="release" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0055" published="2006-01-11" name="CVE-2006-0055" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16207" source="BID" patch="1">16207</ref>
      <ref url="http://secunia.com/advisories/18404" source="SECUNIA" patch="1" adv="1">18404</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc" source="FREEBSD">FreeBSD-SA-06:02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24074" source="XF">ee-ispell-op-symlink(24074)</ref>
      <ref url="http://www.osvdb.org/22320" source="OSVDB">22320</ref>
      <ref url="http://securitytracker.com/id?1015469" source="SECTRACK">1015469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
        <vers num="6.0" edition="release" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0056" published="2006-02-13" name="CVE-2006-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function.  NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/693909" source="CERT-VN" patch="1" adv="1">VU#693909</ref>
      <ref url="http://www.securityfocus.com/bid/16564" source="BID" patch="1">16564</ref>
      <ref url="http://securitytracker.com/id?1015603" source="SECTRACK" patch="1">1015603</ref>
      <ref url="http://secunia.com/advisories/18598" source="SECUNIA" patch="1" adv="1">18598</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0490" source="VUPEN">ADV-2006-0490</ref>
      <ref url="http://www.osvdb.org/22995" source="OSVDB">22995</ref>
      <ref url="http://www.osvdb.org/22994" source="OSVDB">22994</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml" source="GENTOO">GLSA-200606-18</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=499394" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=499394</ref>
      <ref url="http://secunia.com/advisories/20690" source="SECUNIA" adv="1">20690</ref>
      <ref url="http://jvn.jp/cert/JVNVU%23693909/index.html" source="MISC">http://jvn.jp/cert/JVNVU%23693909/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pam-mysql" name="pam-mysql">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.7" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7_pre1" />
        <vers num="0.7_pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0057" published="2006-01-27" name="CVE-2006-0057" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/998297" source="CERT-VN" adv="1">VU#998297</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx" source="MISC" patch="1" adv="1">http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24379" source="XF">ie-activex-killbit-bypass(24379)</ref>
      <ref url="http://www.securityfocus.com/bid/16409" source="BID">16409</ref>
      <ref url="http://www.osvdb.org/23657" source="OSVDB">23657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="5.5" edition="sp2" />
        <vers num="6" edition="sp1" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0058" published="2006-03-22" name="CVE-2006-0058" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-081A.html" source="CERT">TA06-081A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/834865" source="CERT-VN">VU#834865</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0265.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0265</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0264.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0264</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2490" source="VUPEN">ADV-2006-2490</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2189" source="VUPEN">ADV-2006-2189</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1529" source="VUPEN">ADV-2006-1529</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1157" source="VUPEN">ADV-2006-1157</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1139" source="VUPEN">ADV-2006-1139</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1072" source="VUPEN">ADV-2006-1072</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1068" source="VUPEN">ADV-2006-1068</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1051" source="VUPEN">ADV-2006-1051</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1049" source="VUPEN">ADV-2006-1049</ref>
      <ref url="http://www.sendmail.com/company/advisory/index.shtml" source="CONFIRM">http://www.sendmail.com/company/advisory/index.shtml</ref>
      <ref url="http://www.securityfocus.com/archive/1/428536/100/0/threaded" source="BUGTRAQ">20060322 sendmail vuln advisories (CVE-2006-0058)</ref>
      <ref url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html" source="OPENPKG">OpenPKG-SA-2006.007</ref>
      <ref url="http://www.iss.net/threats/216.html" source="ISS">20060322 Sendmail Remote Signal Handling Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml" source="GENTOO">GLSA-200603-21</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1015" source="DEBIAN">DSA-1015</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1" source="SUNALERT">200494</ref>
      <ref url="http://secunia.com/advisories/19367" source="SECUNIA">19367</ref>
      <ref url="http://secunia.com/advisories/19363" source="SECUNIA">19363</ref>
      <ref url="http://secunia.com/advisories/19342" source="SECUNIA">19342</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11074" source="OVAL">oval:org.mitre.oval:def:11074</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" source="HP">HPSBTU02116</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555" source="HP">HPSBUX02108</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24584" source="XF">smtp-timeout-bo(24584)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688</ref>
      <ref url="http://www.securityfocus.com/bid/17192" source="BID">17192</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428656/100/0/threaded" source="FEDORA">FLSA:186277</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html" source="FEDORA">FEDORA-2006-193</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html" source="FEDORA">FEDORA-2006-194</ref>
      <ref url="http://www.osvdb.org/24037" source="OSVDB">24037</ref>
      <ref url="http://www.openbsd.org/errata38.html#sendmail" source="OPENBSD">[3.8] 006: SECURITY FIX: March 25, 2006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_17_sendmail.html" source="SUSE">SUSE-SA:2006:017</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:058" source="MANDRIVA">MDKSA-2006:058</ref>
      <ref url="http://www.f-secure.com/security/fsc-2006-2.shtml" source="CONFIRM">http://www.f-secure.com/security/fsc-2006-2.shtml</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-151.shtml" source="CIAC">Q-151</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82994&amp;apar=only" source="AIXAPAR">IY82994</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82993&amp;apar=only" source="AIXAPAR">IY82993</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82992&amp;apar=only" source="AIXAPAR">IY82992</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1" source="SUNALERT">102324</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1" source="SUNALERT">102262</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.619600" source="SLACKWARE">SSA:2006-081-01</ref>
      <ref url="http://securitytracker.com/id?1015801" source="SECTRACK">1015801</ref>
      <ref url="http://securityreason.com/securityalert/743" source="SREASON">743</ref>
      <ref url="http://securityreason.com/securityalert/612" source="SREASON">612</ref>
      <ref url="http://secunia.com/advisories/20723" source="SECUNIA">20723</ref>
      <ref url="http://secunia.com/advisories/20243" source="SECUNIA">20243</ref>
      <ref url="http://secunia.com/advisories/19774" source="SECUNIA">19774</ref>
      <ref url="http://secunia.com/advisories/19676" source="SECUNIA">19676</ref>
      <ref url="http://secunia.com/advisories/19533" source="SECUNIA">19533</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="http://secunia.com/advisories/19466" source="SECUNIA">19466</ref>
      <ref url="http://secunia.com/advisories/19450" source="SECUNIA">19450</ref>
      <ref url="http://secunia.com/advisories/19407" source="SECUNIA">19407</ref>
      <ref url="http://secunia.com/advisories/19404" source="SECUNIA">19404</ref>
      <ref url="http://secunia.com/advisories/19394" source="SECUNIA">19394</ref>
      <ref url="http://secunia.com/advisories/19368" source="SECUNIA">19368</ref>
      <ref url="http://secunia.com/advisories/19361" source="SECUNIA">19361</ref>
      <ref url="http://secunia.com/advisories/19360" source="SECUNIA">19360</ref>
      <ref url="http://secunia.com/advisories/19356" source="SECUNIA">19356</ref>
      <ref url="http://secunia.com/advisories/19349" source="SECUNIA">19349</ref>
      <ref url="http://secunia.com/advisories/19346" source="SECUNIA">19346</ref>
      <ref url="http://secunia.com/advisories/19345" source="SECUNIA">19345</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" source="HP">HPSBTU02116</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555" source="HP">HPSBUX02108</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P" source="SGI">20060302-01-P</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt" source="SCO">SCOSA-2006.24</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc" source="NETBSD">NetBSD-SA2006-010</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc" source="FREEBSD">FreeBSD-SA-06:13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1689" source="OVAL" sig="1">oval:org.mitre.oval:def:1689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.13.0" />
        <vers num="8.13.1" />
        <vers num="8.13.2" />
        <vers num="8.13.3" />
        <vers num="8.13.4" />
        <vers num="8.13.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0059" published="2006-05-19" name="CVE-2006-0059" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
LiveData, ICCP Server, 5.00.035</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/190617" source="CERT-VN" patch="1">VU#190617</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1830" source="VUPEN">ADV-2006-1830</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6MMS9T" source="MISC">http://www.kb.cert.org/vuls/id/JGEI-6MMS9T</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26490" source="XF">livedata-iccp-rfc1006-bo(26490)</ref>
      <ref url="http://www.securityfocus.com/bid/18010" source="BID">18010</ref>
      <ref url="http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html" source="MISC">http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html</ref>
      <ref url="http://securitytracker.com/id?1016113" source="SECTRACK">1016113</ref>
      <ref url="http://secunia.com/advisories/20146" source="SECUNIA">20146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="livedata" name="iccp_server">
        <vers num="5.00.045" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0063" published="2006-01-05" name="CVE-2006-0063" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0051" source="VUPEN">ADV-2006-0051</ref>
      <ref url="http://securityreason.com/securityalert/313" source="SREASON">313</ref>
      <ref url="http://securityreason.com/securityalert/313" source="MISC" adv="1">http://securityreason.com/securityalert/313</ref>
      <ref url="http://securityreason.com/achievement_securityalert/30" source="SREASONRES" adv="1">20060105 phpBB 2.0.19 XSS</ref>
      <ref url="http://www.osvdb.org/22672" source="OSVDB">22672</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0064" published="2006-01-03" name="CVE-2006-0064" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0016" source="VUPEN" adv="1">ADV-2006-0016</ref>
      <ref url="http://milw0rm.com/exploits/1398" source="MILW0RM">1398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0065" published="2006-01-03" name="CVE-2006-0065" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0003" source="VUPEN">ADV-2006-0003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18273" source="SECUNIA" adv="1">18273</ref>
      <ref url="http://evuln.com/vulns/1/summary.html" source="MISC" adv="1">http://evuln.com/vulns/1/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16107" source="BID">16107</ref>
      <ref url="http://www.osvdb.org/22140" source="OSVDB">22140</ref>
      <ref url="http://securityreason.com/securityalert/315" source="SREASON">315</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vego" name="vego_web_forum">
        <vers prev="1" num="1.26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0066" published="2006-01-03" name="CVE-2006-0066" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0006" source="VUPEN">ADV-2006-0006</ref>
      <ref url="http://www.securityfocus.com/bid/16111" source="BID">16111</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22149" source="OSVDB">22149</ref>
      <ref url="http://secunia.com/advisories/18265" source="SECUNIA" adv="1">18265</ref>
      <ref url="http://evuln.com/vulns/9/summary.html" source="MISC" adv="1">http://evuln.com/vulns/9/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpjournaler" name="phpjournaler">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0067" published="2006-01-03" name="CVE-2006-0067" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0004" source="VUPEN">ADV-2006-0004</ref>
      <ref url="http://secunia.com/advisories/18272" source="SECUNIA" adv="1">18272</ref>
      <ref url="http://evuln.com/vulns/2/summary.html" source="MISC" adv="1">http://evuln.com/vulns/2/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16108" source="BID">16108</ref>
      <ref url="http://www.osvdb.org/22139" source="OSVDB">22139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vego" name="vego_links_builder">
        <vers prev="1" num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0068" published="2006-01-03" name="CVE-2006-0068" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0008" source="VUPEN">ADV-2006-0008</ref>
      <ref url="http://secunia.com/advisories/18264" source="SECUNIA" adv="1">18264</ref>
      <ref url="http://www.securityfocus.com/bid/16125" source="BID">16125</ref>
      <ref url="http://www.osvdb.org/22147" source="OSVDB">22147</ref>
      <ref url="http://www.osvdb.org/22146" source="OSVDB">22146</ref>
      <ref url="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html" source="MISC">http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="primo_place" name="primo_cart">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0069" published="2006-01-03" name="CVE-2006-0069" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/19087" source="BID">19087</ref>
      <ref url="http://www.securityfocus.com/bid/16112" source="BID">16112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18270" source="SECUNIA">18270</ref>
      <ref url="http://evuln.com/vulns/4/summary.html" source="MISC" adv="1">http://evuln.com/vulns/4/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="chipmunk_guestbook">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0070" published="2006-01-03" name="CVE-2006-0070" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded" source="BUGTRAQ">20060103 Re: Drupal all versiyon xss cehennem.org</ref>
      <ref url="http://www.securityfocus.com/archive/1/420671/100/0/threaded" source="BUGTRAQ" adv="1">20060102 Drupal all versiyon xss cehennem.org</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.6" />
        <vers num="4.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0071" published="2006-01-03" name="CVE-2006-0071" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16120" source="BID" patch="1">16120</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200601-01</ref>
      <ref url="http://www.osvdb.org/22211" source="OSVDB">22211</ref>
      <ref url="http://secunia.com/advisories/18284" source="SECUNIA">18284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="app-crypt_pinentry">
        <vers num="0.7.2" edition="r1" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0072" published="2006-01-03" name="CVE-2006-0072" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16122" source="BID">16122</ref>
      <ref url="http://www.securityfocus.com/archive/1/420677" source="BUGTRAQ">20060102 SCO Openserver 5.0.x exploit</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.6a" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0073" published="2006-01-03" name="CVE-2006-0073" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16119" source="BID">16119</ref>
      <ref url="http://www.osvdb.org/22153" source="OSVDB">22153</ref>
      <ref url="http://secunia.com/advisories/18283" source="SECUNIA" adv="1">18283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="discusware" name="discus_freeware">
        <vers num="3.10.5" />
      </prod>
      <prod vendor="discusware" name="discus_professional">
        <vers num="3.10.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0074" published="2006-01-03" name="CVE-2006-0074" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.  NOTE: it was later reported that 1.1 and earlier are affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0005" source="VUPEN" adv="1">ADV-2006-0005</ref>
      <ref url="http://www.securityfocus.com/bid/16109" source="BID">16109</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded" source="BUGTRAQ">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</ref>
      <ref url="http://www.osvdb.org/22150" source="OSVDB">22150</ref>
      <ref url="http://www.milw0rm.com/exploits/8706" source="MILW0RM">8706</ref>
      <ref url="http://secunia.com/advisories/18269" source="SECUNIA" adv="1">18269</ref>
      <ref url="http://evuln.com/vulns/5/summary.html" source="MISC">http://evuln.com/vulns/5/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jevontech" name="phpenpals">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0075" published="2006-01-03" name="CVE-2006-0075" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16106" source="BID" patch="1" adv="1">16106</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded" source="BUGTRAQ" patch="1">20060101 [eVuln] phpBook PHP Code Execution</ref>
      <ref url="http://evuln.com/vulns/6/summary.html" source="MISC" patch="1">http://evuln.com/vulns/6/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0002" source="VUPEN">ADV-2006-0002</ref>
      <ref url="http://secunia.com/advisories/18268" source="SECUNIA" adv="1">18268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="phpbook">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers prev="1" num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0076" published="2006-01-03" name="CVE-2006-0076" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16105" source="BID">16105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded" source="BUGTRAQ">20060531 Re: OaBoard 1.0 Remote File inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded" source="BUGTRAQ">20060530 OaBoard 1.0 Remote File inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] oaBoard PHP Code Execution</ref>
      <ref url="http://securitytracker.com/id?1016211" source="SECTRACK">1016211</ref>
      <ref url="http://evuln.com/vulns/3/summary.html" source="MISC">http://evuln.com/vulns/3/summary.html</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0077" published="2006-01-03" name="CVE-2006-0077" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16118" source="BID" patch="1">16118</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116</ref>
      <ref url="http://secunia.com/advisories/18253" source="SECUNIA" patch="1" adv="1">18253</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0013" source="VUPEN">ADV-2006-0013</ref>
      <ref url="http://www.osvdb.org/22160" source="OSVDB">22160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="richard_dawe" name="file_extattr">
        <vers num="0.1" />
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0078" published="2006-01-04" name="CVE-2006-0078" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0018" source="VUPEN">ADV-2006-0018</ref>
      <ref url="http://www.securityfocus.com/bid/16114" source="BID">16114</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded" source="BUGTRAQ" adv="1">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18271" source="SECUNIA" adv="1">18271</ref>
      <ref url="http://evuln.com/vulns/10/summary.html" source="MISC" adv="1">http://evuln.com/vulns/10/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded" source="BUGTRAQ">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22191" source="OSVDB">22191</ref>
      <ref url="http://www.osvdb.org/22190" source="OSVDB">22190</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067</ref>
      <ref url="http://securityreason.com/securityalert/316" source="SREASON">316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="haddad_said" name="b-net_software">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0079" published="2006-01-04" name="CVE-2006-0079" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0027" source="VUPEN">ADV-2006-0027</ref>
      <ref url="http://www.securityfocus.com/bid/16115" source="BID">16115</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded" source="BUGTRAQ" adv="1">20060102 [eVuln] ScozBook "adminname" Authentication Bypass</ref>
      <ref url="http://evuln.com/vulns/11/summary.html" source="MISC">http://evuln.com/vulns/11/summary.html</ref>
      <ref url="http://www.osvdb.org/22221" source="OSVDB">22221</ref>
      <ref url="http://securityreason.com/securityalert/318" source="SREASON">318</ref>
      <ref url="http://secunia.com/advisories/8476" source="SECUNIA">8476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scoznet" name="scozbook">
        <vers num="1.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0080" published="2006-01-04" name="CVE-2006-0080" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0033" source="VUPEN">ADV-2006-0033</ref>
      <ref url="http://www.securityfocus.com/bid/16116" source="BID">16116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded" source="BUGTRAQ">20060108 Html_Injection in vBulletin 3.5.2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</ref>
      <ref url="http://www.osvdb.org/22220" source="OSVDB">22220</ref>
      <ref url="http://www.osvdb.org/22210" source="OSVDB">22210</ref>
      <ref url="http://secunia.com/advisories/18299" source="SECUNIA">18299</ref>
      <ref url="http://kapda.ir/advisory-177.html" source="MISC" adv="1">http://kapda.ir/advisory-177.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0081" published="2006-01-04" name="CVE-2006-0081" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0017" source="VUPEN" adv="1">ADV-2006-0017</ref>
      <ref url="http://www.securityfocus.com/bid/16127" source="BID">16127</ref>
      <ref url="http://www.osvdb.org/22196" source="OSVDB">22196</ref>
      <ref url="http://secunia.com/advisories/18286" source="SECUNIA" adv="1">18286</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html" source="FULLDISC">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html" source="FULLDISC">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html" source="FULLDISC">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="graphics_accelerator_driver">
        <vers num="6.14.10.4308" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0082" published="2006-01-04" name="CVE-2006-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12717" source="BID" patch="1">12717</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-13.xml</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-06</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682" source="SLACKWARE" patch="1">SSA:2006-045-03</ref>
      <ref url="http://secunia.com/advisories/19183" source="SECUNIA" patch="1" adv="1">19183</ref>
      <ref url="http://secunia.com/advisories/19030" source="SECUNIA" patch="1" adv="1">19030</ref>
      <ref url="http://secunia.com/advisories/18851" source="SECUNIA" patch="1" adv="1">18851</ref>
      <ref url="http://secunia.com/advisories/18607" source="SECUNIA" patch="1" adv="1">18607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" source="SGI" patch="1">20060301-01-U</ref>
      <ref url="https://issues.rpath.com/browse/RPL-389" source="CONFIRM">https://issues.rpath.com/browse/RPL-389</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0412" source="VUPEN" adv="1">ADV-2008-0412</ref>
      <ref url="http://www.ubuntu.com/usn/usn-246-1" source="UBUNTU">USN-246-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded" source="BUGTRAQ">20061127 rPSA-2006-0218-1 ImageMagick</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_06_sr.html" source="SUSE">SUSE-SR:2006:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024" source="MANDRIVA">MDKSA-2006:024</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1213" source="DEBIAN">DSA-1213</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1" source="SUNALERT">231321</ref>
      <ref url="http://securitytracker.com/id?1015623" source="SECTRACK">1015623</ref>
      <ref url="http://securityreason.com/securityalert/500" source="SREASON">500</ref>
      <ref url="http://secunia.com/advisories/28800" source="SECUNIA" adv="1">28800</ref>
      <ref url="http://secunia.com/advisories/23090" source="SECUNIA" adv="1">23090</ref>
      <ref url="http://secunia.com/advisories/22998" source="SECUNIA" adv="1">22998</ref>
      <ref url="http://secunia.com/advisories/19408" source="SECUNIA" adv="1">19408</ref>
      <ref url="http://secunia.com/advisories/18871" source="SECUNIA" adv="1">18871</ref>
      <ref url="http://secunia.com/advisories/18261" source="SECUNIA" adv="1">18261</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0178.html" source="REDHAT">RHSA-2006:0178</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10717" source="OVAL">oval:org.mitre.oval:def:10717</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="6.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0083" published="2006-01-09" name="CVE-2006-0083" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18357" source="SECUNIA" patch="1" adv="1">18357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24034" source="XF">smstools-logging-format-string(24034)</ref>
      <ref url="http://www.securityfocus.com/bid/16188" source="BID">16188</ref>
      <ref url="http://www.osvdb.org/22287" source="OSVDB">22287</ref>
      <ref url="http://www.debian.org/security/2005/dsa-930" source="DEBIAN">DSA-930</ref>
      <ref url="http://secunia.com/advisories/18343" source="SECUNIA" adv="1">18343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_frings" name="sms_server_tools">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0084" published="2006-01-05" name="CVE-2006-0084" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0030" source="VUPEN">ADV-2006-0030</ref>
      <ref url="http://www.securityfocus.com/bid/16138" source="BID">16138</ref>
      <ref url="http://www.osvdb.org/22198" source="OSVDB">22198</ref>
      <ref url="http://secunia.com/advisories/18292" source="SECUNIA" adv="1">18292</ref>
      <ref url="http://evuln.com/vulns/13/summary.html" source="MISC" adv="1">http://evuln.com/vulns/13/summary.html</ref>
      <ref url="http://securitytracker.com/id?1015432" source="SECTRACK">1015432</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000486.html" source="VIM">20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rasmp" name="rasmp">
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0085" published="2006-01-05" name="CVE-2006-0085" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0040" source="VUPEN">ADV-2006-0040</ref>
      <ref url="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt" source="MISC" adv="1">http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt</ref>
      <ref url="http://secunia.com/advisories/18302" source="SECUNIA" adv="1">18302</ref>
      <ref url="http://www.osvdb.org/22206" source="OSVDB">22206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nkads" name="nkads">
        <vers num="1.0alfa2" />
        <vers num="1.0alfa3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0086" published="2006-01-05" name="CVE-2006-0086" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0037" source="VUPEN">ADV-2006-0037</ref>
      <ref url="http://secunia.com/advisories/18309" source="SECUNIA" adv="1">18309</ref>
      <ref url="http://www.osvdb.org/22202" source="OSVDB">22202</ref>
      <ref url="http://osvdb.org/ref/22/22202-nextgen.txt" source="MISC">http://osvdb.org/ref/22/22202-nextgen.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next_generation_image_gallery" name="next_generation_image_gallery">
        <vers num="0.0.1_lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0087" published="2006-01-05" name="CVE-2006-0087" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0029" source="VUPEN">ADV-2006-0029</ref>
      <ref url="http://www.securityfocus.com/bid/16140" source="BID">16140</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded" source="BUGTRAQ" adv="1">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18297" source="SECUNIA" adv="1">18297</ref>
      <ref url="http://www.osvdb.org/22200" source="OSVDB">22200</ref>
      <ref url="http://www.osvdb.org/22199" source="OSVDB">22199</ref>
      <ref url="http://www.evuln.com/vulns/12/summary.html" source="MISC">http://www.evuln.com/vulns/12/summary.html</ref>
      <ref url="http://securitytracker.com/id?1015435" source="SECTRACK">1015435</ref>
      <ref url="http://securityreason.com/securityalert/314" source="SREASON">314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lizard_cart" name="lizard_cart_cms">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0088" published="2006-01-05" name="CVE-2006-0088" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0026" source="VUPEN">ADV-2006-0026</ref>
      <ref url="http://www.securityfocus.com/bid/16110" source="BID">16110</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] inTouch Authentication Bypass</ref>
      <ref url="http://evuln.com/vulns/8/summary.html" source="MISC" adv="1">http://evuln.com/vulns/8/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23954" source="XF">intouch-intouch-sql-injection(23954)</ref>
      <ref url="http://www.osvdb.org/22382" source="OSVDB">22382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intouch" name="intouch">
        <vers num="0.5.1_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0089" published="2006-01-05" name="CVE-2006-0089" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0032" source="VUPEN">ADV-2006-0032</ref>
      <ref url="http://www.securityfocus.com/bid/16136" source="BID">16136</ref>
      <ref url="http://users.pandora.be/bratax/advisories/b007.html" source="MISC" adv="1">http://users.pandora.be/bratax/advisories/b007.html</ref>
      <ref url="http://secunia.com/advisories/18294" source="SECUNIA" adv="1">18294</ref>
      <ref url="http://www.osvdb.org/22208" source="OSVDB">22208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esri" name="arcpad">
        <vers prev="1" num="7.0.0.156" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0090" published="2006-01-05" name="CVE-2006-0090" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0031" source="VUPEN">ADV-2006-0031</ref>
      <ref url="http://secunia.com/advisories/18298" source="SECUNIA" adv="1">18298</ref>
      <ref url="http://www.securityfocus.com/bid/16137" source="BID">16137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idv_directory_viewer" name="idv_directory_viewer">
        <vers num="2005.1_b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0091" published="2006-01-05" name="CVE-2006-0091" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0034" source="VUPEN">ADV-2006-0034</ref>
      <ref url="http://secunia.com/advisories/18285" source="SECUNIA" adv="1">18285</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2" source="FULLDISC" adv="1">20060103 Open Xchange XSS</ref>
      <ref url="http://securitytracker.com/id?1015431" source="SECTRACK">1015431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open-xchange" name="open-xchange">
        <vers prev="1" num="0.8.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0092" reject="1" published="2006-01-05" name="CVE-2006-0092" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0093" published="2006-01-05" name="CVE-2006-0093" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0039" source="VUPEN">ADV-2006-0039</ref>
      <ref url="http://www.osvdb.org/22203" source="OSVDB">22203</ref>
      <ref url="http://secunia.com/advisories/18306" source="SECUNIA" adv="1">18306</ref>
      <ref url="http://osvdb.org/ref/22/22203-ecardmax.txt" source="MISC">http://osvdb.org/ref/22/22203-ecardmax.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecardmax.com" name="atcard_me_php">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0094" published="2006-01-05" name="CVE-2006-0094" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0028" source="VUPEN" adv="1">ADV-2006-0028</ref>
      <ref url="http://secunia.com/advisories/17373" source="SECUNIA" adv="1">17373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oaboard" name="oaboard">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0095" published="2006-01-06" name="CVE-2006-0095" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2" source="MLIST" patch="1" adv="1">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0235" source="VUPEN">ADV-2006-0235</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11192" source="OVAL">oval:org.mitre.oval:def:11192</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2" source="MLIST">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24189" source="XF">kernel-dmcrypt-information-disclosure(24189)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1" source="UBUNTU">USN-244-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16301" source="BID">16301</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded" source="FEDORA">FLSA:157459-4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0132.html" source="REDHAT">RHSA-2006:0132</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html" source="FEDORA">FEDORA-2006-102</ref>
      <ref url="http://www.osvdb.org/22418" source="OSVDB">22418</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040" source="MANDRIVA">MDKSA-2006:040</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://securitytracker.com/id?1015740" source="SECTRACK">1015740</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
      <ref url="http://secunia.com/advisories/19160" source="SECUNIA">19160</ref>
      <ref url="http://secunia.com/advisories/18774" source="SECUNIA">18774</ref>
      <ref url="http://secunia.com/advisories/18527" source="SECUNIA">18527</ref>
      <ref url="http://secunia.com/advisories/18487" source="SECUNIA">18487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.13" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0096" published="2006-01-06" name="CVE-2006-0096" modified="2008-11-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044" source="MANDRIVA">MDKSA-2006:044</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1" source="UBUNTU">USN-244-1</ref>
      <ref url="http://www.securityfocus.com/bid/16304" source="BID">16304</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA" adv="1">19374</ref>
      <ref url="http://secunia.com/advisories/18977" source="SECUNIA" adv="1">18977</ref>
      <ref url="http://secunia.com/advisories/18527" source="SECUNIA" adv="1">18527</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.13" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0097" published="2006-01-06" name="CVE-2006-0097" modified="2011-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0046" source="VUPEN" adv="1">ADV-2006-0046</ref>
      <ref url="http://www.securityfocus.com/bid/16145" source="BID">16145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded" source="BUGTRAQ">20060105 Windows PHP 4.x </ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.4.3" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.4.3</ref>
      <ref url="http://www.osvdb.org/22232" source="OSVDB">22232</ref>
      <ref url="http://secunia.com/advisories/18275" source="SECUNIA" adv="1">18275</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html" source="FULLDISC" adv="1">20060105 Windows PHP 4.x </ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html" source="FULLDISC">20060108 RE: Windows PHP 4.x </ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3.10" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0098" published="2006-01-06" name="CVE-2006-0098" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16144" source="BID" patch="1">16144</ref>
      <ref url="http://www.openbsd.org/errata37.html#fd" source="OPENBSD" patch="1">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</ref>
      <ref url="http://secunia.com/advisories/18296" source="SECUNIA" patch="1" adv="1">18296</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch" source="MISC" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch</ref>
      <ref url="http://www.osvdb.org/22231" source="OSVDB">22231</ref>
      <ref url="http://securitytracker.com/id?1015437" source="SECTRACK">1015437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.7" />
        <vers num="3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0099" published="2006-01-06" name="CVE-2006-0099" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16126" source="BID">16126</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl</ref>
      <ref url="http://milw0rm.com/exploits/1401" source="MILW0RM">1401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valdersoft" name="valdersoft_shopping_cart">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0100" published="2006-01-06" name="CVE-2006-0100" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the "Name of site" field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded" source="BUGTRAQ">20060102 NicoFTP Stack Overflow</ref>
      <ref url="http://securityreason.com/securityalert/317" source="SREASON">317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicosw" name="nicoftp">
        <vers prev="1" num="3.0.1.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0101" published="2006-01-06" name="CVE-2006-0101" modified="2011-09-13" discovered="2006-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/23979" source="XF">sblog-multiple-scripts-xss(23979)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0041" source="VUPEN" adv="1">ADV-2006-0041</ref>
      <ref url="http://www.osvdb.org/22374" source="OSVDB">22374</ref>
      <ref url="http://www.osvdb.org/22373" source="OSVDB">22373</ref>
      <ref url="http://osvdb.org/ref/22/22373-sblog.txt" source="MISC">http://osvdb.org/ref/22/22373-sblog.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sblog" name="sblog">
        <vers prev="1" num="0.7.1_build2005-12-02_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0102" published="2006-01-06" name="CVE-2006-0102" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0054" source="VUPEN">ADV-2006-0054</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" source="BUGTRAQ">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22256" source="OSVDB">22256</ref>
      <ref url="http://securitytracker.com/id?1015436" source="SECTRACK">1015436</ref>
      <ref url="http://secunia.com/advisories/18293" source="SECUNIA" adv="1">18293</ref>
      <ref url="http://evuln.com/vulns/14/summary.html" source="MISC" adv="1">http://evuln.com/vulns/14/summary.html</ref>
      <ref url="http://securityreason.com/securityalert/320" source="SREASON">320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralph_capper" name="tinyphpforum">
        <vers num="3.46" />
        <vers num="3.47" />
        <vers num="3.48" />
        <vers num="3.49" />
        <vers num="3.499" />
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0103" published="2006-01-06" name="CVE-2006-0103" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24016" source="XF">tinyphpforum-users-information-disclosure(24016)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0054" source="VUPEN" adv="1">ADV-2006-0054</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded" source="BUGTRAQ">20060417 Tiny PHP forum - vulns</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22257" source="OSVDB">22257</ref>
      <ref url="http://securitytracker.com/id?1015436" source="SECTRACK">1015436</ref>
      <ref url="http://securityreason.com/securityalert/320" source="SREASON">320</ref>
      <ref url="http://secunia.com/advisories/18293" source="SECUNIA" adv="1">18293</ref>
      <ref url="http://evuln.com/vulns/14/summary.html" source="MISC" adv="1">http://evuln.com/vulns/14/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralph_capper" name="tinyphpforum">
        <vers num="3.46" />
        <vers num="3.47" />
        <vers num="3.48" />
        <vers num="3.49" />
        <vers num="3.499" />
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0104" published="2006-01-06" name="CVE-2006-0104" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0054" source="VUPEN">ADV-2006-0054</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18293" source="SECUNIA" adv="1">18293</ref>
      <ref url="http://evuln.com/vulns/14/summary.html" source="MISC" adv="1">http://evuln.com/vulns/14/summary.html</ref>
      <ref url="http://evuln.com/vulns/14/exploit.html" source="MISC">http://evuln.com/vulns/14/exploit.html</ref>
      <ref url="http://www.securityfocus.com/bid/16163" source="BID">16163</ref>
      <ref url="http://www.osvdb.org/22258" source="OSVDB">22258</ref>
      <ref url="http://securitytracker.com/id?1015436" source="SECTRACK">1015436</ref>
      <ref url="http://securityreason.com/securityalert/320" source="SREASON">320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralph_capper" name="tinyphpforum">
        <vers num="3.46" />
        <vers num="3.47" />
        <vers num="3.48" />
        <vers num="3.49" />
        <vers num="3.499" />
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0105" published="2006-01-10" name="CVE-2006-0105" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php" source="MLIST" patch="1">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0114" source="VUPEN">ADV-2006-0114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24049" source="XF">postgresql-connection-request-dos(24049)</ref>
      <ref url="http://www.securityfocus.com/bid/16201" source="BID">16201</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded" source="BUGTRAQ">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</ref>
      <ref url="http://www.postgresql.org/about/news.456" source="CONFIRM">http://www.postgresql.org/about/news.456</ref>
      <ref url="http://securitytracker.com/id?1015482" source="SECTRACK">1015482</ref>
      <ref url="http://securityreason.com/securityalert/327" source="SREASON">327</ref>
      <ref url="http://secunia.com/advisories/18419" source="SECUNIA">18419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.1.0" />
        <vers num="8.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0106" published="2006-01-06" name="CVE-2006-0106" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18323" source="SECUNIA" patch="1" adv="1">18323</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197" source="MISC" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0098" source="VUPEN">ADV-2006-0098</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html" source="MLIST">[Dailydave] 20060105 WMF goes away :&lt;</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23846" source="XF">win-wmf-execute-code(23846)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded" source="BUGTRAQ">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_02_sr.html" source="SUSE">SUSE-SR:2006:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014" source="MANDRIVA">MDKSA-2006:014</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml" source="GENTOO">GLSA-200601-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-954" source="DEBIAN">DSA-954</ref>
      <ref url="http://secunia.com/advisories/18578" source="SECUNIA">18578</ref>
      <ref url="http://secunia.com/advisories/18549" source="SECUNIA">18549</ref>
      <ref url="http://secunia.com/advisories/18451" source="SECUNIA">18451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wine" name="wine">
        <vers num="0.9.2" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="2005-09-30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0107" published="2006-01-06" name="CVE-2006-0107" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16159" source="BID">16159</ref>
      <ref url="http://www.osvdb.org/22252" source="OSVDB">22252</ref>
      <ref url="http://secunia.com/advisories/18324" source="SECUNIA" adv="1">18324</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24014" source="XF">timecancms-sql-injection(24014)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idea_development_id_oy" name="timecan_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0108" published="2006-01-06" name="CVE-2006-0108" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0078" source="VUPEN">ADV-2006-0078</ref>
      <ref url="http://www.osvdb.org/22253" source="OSVDB">22253</ref>
      <ref url="http://www.osvdb.org/22252" source="OSVDB">22252</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24014" source="XF">timecancms-sql-injection(24014)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idea_development_id_oy" name="timecan_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0109" published="2006-01-06" name="CVE-2006-0109" modified="2011-03-07" discovered="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18320" source="SECUNIA" patch="1" adv="1">18320</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0076" source="VUPEN">ADV-2006-0076</ref>
      <ref url="http://www.securityfocus.com/bid/16160" source="BID">16160</ref>
      <ref url="http://www.osvdb.org/22243" source="OSVDB">22243</ref>
      <ref url="http://www.modularmerchant.com/forums/viewtopic.php?t=46" source="MISC">http://www.modularmerchant.com/forums/viewtopic.php?t=46</ref>
      <ref url="http://osvdb.org/ref/22/22243-modular.txt" source="MISC">http://osvdb.org/ref/22/22243-modular.txt</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000548.html" source="VIM">20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modular_merchant" name="shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0110" published="2006-01-06" name="CVE-2006-0110" modified="2011-03-07" discovered="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0073" source="VUPEN">ADV-2006-0073</ref>
      <ref url="http://www.securityfocus.com/bid/16154" source="BID">16154</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded" source="BUGTRAQ">20060106 [eVuln] Proyecto Domus 'email' XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22263" source="OSVDB">22263</ref>
      <ref url="http://secunia.com/advisories/18327" source="SECUNIA" adv="1">18327</ref>
      <ref url="http://evuln.com/vulns/16/summary.html" source="MISC">http://evuln.com/vulns/16/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24020" source="XF">domus-escribir-xss(24020)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="javier_suarez_sanz" name="foro_domus">
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0111" published="2006-01-06" name="CVE-2006-0111" modified="2011-03-07" discovered="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24019" source="XF">boxcar-index-xss(24019)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0080" source="VUPEN">ADV-2006-0080</ref>
      <ref url="http://www.osvdb.org/22360" source="OSVDB">22360</ref>
      <ref url="http://osvdb.org/ref/22/22360-boxcar.txt" source="MISC">http://osvdb.org/ref/22/22360-boxcar.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boxcar_media" name="shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0112" published="2006-01-06" name="CVE-2006-0112" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0036" source="VUPEN">ADV-2006-0036</ref>
      <ref url="http://www.osvdb.org/22201" source="OSVDB">22201</ref>
      <ref url="http://secunia.com/advisories/18310" source="SECUNIA" adv="1">18310</ref>
      <ref url="http://osvdb.org/ref/22/22201-espg.txt" source="MISC">http://osvdb.org/ref/22/22201-espg.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enhanced_simple_php_gallery" name="enhanced_simple_php_gallery">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0113" published="2006-01-06" name="CVE-2006-0113" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18310" source="SECUNIA" adv="1">18310</ref>
      <ref url="http://osvdb.org/ref/22/22201-espg.txt" source="MISC">http://osvdb.org/ref/22/22201-espg.txt</ref>
      <ref url="http://www.osvdb.org/22417" source="OSVDB">22417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enhanced_simple_php_gallery" name="enhanced_simple_php_gallery">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0114" published="2006-01-09" name="CVE-2006-0114" modified="2011-06-06" discovered="2006-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24042" source="XF">joomla-vcard-information-disclosure(24042)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0097" source="VUPEN" adv="1">ADV-2006-0097</ref>
      <ref url="http://www.securityfocus.com/bid/16185" source="BID">16185</ref>
      <ref url="http://secunia.com/advisories/18361" source="SECUNIA" adv="1">18361</ref>
      <ref url="http://forum.joomla.org/index.php/topic,29031.0.html" source="CONFIRM" adv="1">http://forum.joomla.org/index.php/topic,29031.0.html</ref>
      <ref url="http://forge.joomla.org/sf/go/artf2950" source="CONFIRM">http://forge.joomla.org/sf/go/artf2950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0115" published="2006-01-09" name="CVE-2006-0115" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0079" source="VUPEN" adv="1">ADV-2006-0079</ref>
      <ref url="http://www.securityfocus.com/bid/16155" source="BID">16155</ref>
      <ref url="http://www.osvdb.org/22250" source="OSVDB">22250</ref>
      <ref url="http://www.osvdb.org/22249" source="OSVDB">22249</ref>
      <ref url="http://www.osvdb.org/22248" source="OSVDB">22248</ref>
      <ref url="http://secunia.com/advisories/18325" source="SECUNIA" adv="1">18325</ref>
      <ref url="http://osvdb.org/ref/22/22248-oneplug.txt" source="MISC">http://osvdb.org/ref/22/22248-oneplug.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneplug_solutions" name="oneplug_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0116" published="2006-01-09" name="CVE-2006-0116" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0075" source="VUPEN">ADV-2006-0075</ref>
      <ref url="http://www.securityfocus.com/bid/16156" source="BID">16156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded" source="BUGTRAQ">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</ref>
      <ref url="http://www.osvdb.org/22251" source="OSVDB">22251</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-January/000515.html" source="VIM">20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</ref>
      <ref url="http://secunia.com/advisories/18322" source="SECUNIA" adv="1">18322</ref>
      <ref url="http://osvdb.org/ref/22/22251-inetstore.txt" source="MISC">http://osvdb.org/ref/22/22251-inetstore.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inetstore" name="inetstore_online">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0117" published="2006-01-09" name="CVE-2006-0117" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24205" source="XF">lotus-cdtomime-dos(24205)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2" />
        <vers num="6.5.4" />
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0118" published="2006-01-09" name="CVE-2006-0118" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24206" source="XF">lotus-long-formula-bo(24206)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2" />
        <vers num="6.5.4" />
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0119" published="2006-01-09" name="CVE-2006-0119" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27413" source="XF">domino-smtp-nrouter-dos(27413)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24211" source="XF">lotus-web-unspecified-xss(24211)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24207" source="XF">lotus-multiple-unspecified(24207)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2564" source="VUPEN" adv="1">ADV-2006-2564</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN" adv="1">ADV-2006-0081</ref>
      <ref url="http://www.securityfocus.com/bid/18020" source="BID">18020</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded" source="BUGTRAQ">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://securitytracker.com/id?1016390" source="SECTRACK">1016390</ref>
      <ref url="http://secunia.com/advisories/20855" source="SECUNIA" adv="1">20855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2" />
        <vers num="6.5.4" />
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0120" published="2006-01-09" name="CVE-2006-0120" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24217" source="XF">lotus-ssl-keyring-dos(24217)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24216" source="XF">lotus-certificate-parsing-dos(24216)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24215" source="XF">lotus-delete-attachment-dos(24215)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24214" source="XF">lotus-bmp-dos(24214)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24213" source="XF">lotus-compact-dos(24213)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24212" source="XF">lotus-outofoffice-dos(24212)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2" />
        <vers num="6.5.4" />
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0121" published="2006-01-09" name="CVE-2006-0121" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24223" source="XF">lotus-ssl-handshake-dos(24223)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2" />
        <vers num="6.5.4" />
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0122" published="2006-01-09" name="CVE-2006-0122" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Vendor provided solution:

"Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability.  For more information visit www.aquifercms.com." 
</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22247" source="OSVDB" patch="1">22247</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0074" source="VUPEN">ADV-2006-0074</ref>
      <ref url="http://www.securityfocus.com/bid/16162" source="BID">16162</ref>
      <ref url="http://secunia.com/advisories/18326" source="SECUNIA" adv="1">18326</ref>
      <ref url="http://osvdb.org/ref/22/22247-aquifer.txt" source="MISC">http://osvdb.org/ref/22/22247-aquifer.txt</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000509.html" source="VIM">20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aquifer_cms" name="aquifer_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0123" published="2006-01-09" name="CVE-2006-0123" modified="2011-09-08" discovered="2006-01-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0077" source="VUPEN" adv="1">ADV-2006-0077</ref>
      <ref url="http://www.securityfocus.com/bid/16157" source="BID">16157</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22241" source="OSVDB">22241</ref>
      <ref url="http://www.osvdb.org/22240" source="OSVDB">22240</ref>
      <ref url="http://securitytracker.com/id?1015445" source="SECTRACK">1015445</ref>
      <ref url="http://secunia.com/advisories/18300" source="SECUNIA" adv="1">18300</ref>
      <ref url="http://evuln.com/vulns/15/summary.html" source="MISC" adv="1">http://evuln.com/vulns/15/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adn_forum" name="adn_forum">
        <vers num="1.0" />
        <vers num="1.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0124" published="2006-01-09" name="CVE-2006-0124" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0077" source="VUPEN">ADV-2006-0077</ref>
      <ref url="http://www.securityfocus.com/bid/16157" source="BID">16157</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18300" source="SECUNIA" adv="1">18300</ref>
      <ref url="http://evuln.com/vulns/15/summary.html" source="MISC" adv="1">http://evuln.com/vulns/15/summary.html</ref>
      <ref url="http://www.osvdb.org/22242" source="OSVDB">22242</ref>
      <ref url="http://securitytracker.com/id?1015445" source="SECTRACK">1015445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adn_forum" name="adn_forum">
        <vers num="1.0" />
        <vers num="1.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0125" published="2006-01-09" name="CVE-2006-0125" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0053" source="VUPEN">ADV-2006-0053</ref>
      <ref url="http://www.osvdb.org/22228" source="OSVDB">22228</ref>
      <ref url="http://secunia.com/advisories/18163" source="SECUNIA" adv="1">18163</ref>
      <ref url="http://www.securityfocus.com/bid/16166" source="BID">16166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="appserv_open_project" name="appserv">
        <vers num="2.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0126" published="2006-01-09" name="CVE-2006-0126" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22223" source="OSVDB" patch="1">22223</ref>
      <ref url="http://secunia.com/advisories/18301" source="SECUNIA" patch="1" adv="1">18301</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0052" source="VUPEN">ADV-2006-0052</ref>
      <ref url="http://dist.schmorp.de/rxvt-unicode/Changes" source="CONFIRM">http://dist.schmorp.de/rxvt-unicode/Changes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt-unicode" name="rxvt-unicode">
        <vers prev="1" num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0127" published="2006-01-09" name="CVE-2006-0127" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" source="MISC" patch="1" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</ref>
      <ref url="http://www.osvdb.org/22229" source="OSVDB" patch="1">22229</ref>
      <ref url="http://secunia.com/advisories/18318" source="SECUNIA" patch="1" adv="1">18318</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" source="FULLDISC" patch="1" adv="1">20060104 Rockliffe Directory Transversal Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0055" source="VUPEN">ADV-2006-0055</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html" source="FULLDISC">20060105 Re: Rockliffe Directory Transversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="6.1.22.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0128" published="2006-01-09" name="CVE-2006-0128" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" source="MISC" patch="1" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" source="FULLDISC" patch="1" adv="1">20060104 Rockliffe Directory Transversal Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39991" source="XF">rockliffe-imap-unspecified-bo(39991)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="6.1.22.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0129" published="2006-01-09" name="CVE-2006-0129" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18318" source="SECUNIA" patch="1" adv="1">18318</ref>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" source="MISC" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0055" source="VUPEN">ADV-2006-0055</ref>
      <ref url="http://www.osvdb.org/22230" source="OSVDB">22230</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" source="FULLDISC" adv="1">20060104 Rockliffe Mailsite User Enumeration Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="7.0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0130" published="2006-01-09" name="CVE-2006-0130" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" source="MISC" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" source="FULLDISC" adv="1">20060104 Rockliffe Mailsite User Enumeration Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="7.0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0131" published="2006-01-09" name="CVE-2006-0131" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</ref>
      <ref url="http://echo.or.id/adv/adv26-K-159-2006.txt" source="MISC">http://echo.or.id/adv/adv26-K-159-2006.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boastmachine" name="boastmachine">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0132" published="2006-01-09" name="CVE-2006-0132" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18355" source="SECUNIA" patch="1" adv="1">18355</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0090" source="VUPEN">ADV-2006-0090</ref>
      <ref url="http://www.securityfocus.com/bid/16175" source="BID">16175</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded" source="BUGTRAQ">20060104 SysCP WebFTP local file inclusion vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24018" source="XF">webftp-language-file-include(24018)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webftp" name="webftp">
        <vers num="1.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0133" published="2006-01-09" name="CVE-2006-0133" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16103" source="BID">16103</ref>
      <ref url="http://www.securityfocus.com/bid/16102" source="BID">16102</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015429" source="SECTRACK">1015429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3_ml03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0134" published="2006-01-09" name="CVE-2006-0134" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0093" source="VUPEN">ADV-2006-0093</ref>
      <ref url="http://www.securityfocus.com/bid/16161" source="BID">16161</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded" source="BUGTRAQ">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref>
      <ref url="http://securitytracker.com/id?1015450" source="SECTRACK">1015450</ref>
      <ref url="http://secunia.com/advisories/18392" source="SECUNIA" adv="1">18392</ref>
      <ref url="http://evuln.com/vulns/17/summary.html" source="MISC">http://evuln.com/vulns/17/summary.html</ref>
      <ref url="http://evuln.com/vulns/17/exploit.html" source="MISC">http://evuln.com/vulns/17/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24007" source="XF">thewebforum-register-xss(24007)</ref>
      <ref url="http://www.osvdb.org/22295" source="OSVDB">22295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thewebforum" name="thewebforum">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0135" published="2006-01-09" name="CVE-2006-0135" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0093" source="VUPEN">ADV-2006-0093</ref>
      <ref url="http://www.securityfocus.com/bid/16161" source="BID">16161</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded" source="BUGTRAQ">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref>
      <ref url="http://securitytracker.com/id?1015450" source="SECTRACK">1015450</ref>
      <ref url="http://secunia.com/advisories/18392" source="SECUNIA" adv="1">18392</ref>
      <ref url="http://evuln.com/vulns/17/summary.html" source="MISC">http://evuln.com/vulns/17/summary.html</ref>
      <ref url="http://evuln.com/vulns/17/exploit.html" source="MISC">http://evuln.com/vulns/17/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24027" source="XF">thewebforum-login-sql-injection(24027)</ref>
      <ref url="http://www.osvdb.org/22294" source="OSVDB">22294</ref>
      <ref url="http://securityreason.com/securityalert/321" source="SREASON">321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thewebforum" name="thewebforum">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0136" published="2006-01-09" name="CVE-2006-0136" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0025" source="VUPEN">ADV-2006-0025</ref>
      <ref url="http://www.securityfocus.com/bid/16113" source="BID">16113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded" source="BUGTRAQ">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref>
      <ref url="http://evuln.com/vulns/7/summary.html" source="MISC">http://evuln.com/vulns/7/summary.html</ref>
      <ref url="http://evuln.com/vulns/7/exploit.html" source="MISC">http://evuln.com/vulns/7/exploit.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phanatic_softwares" name="chimera_web_portal">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0137" published="2006-01-09" name="CVE-2006-0137" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0025" source="VUPEN">ADV-2006-0025</ref>
      <ref url="http://www.securityfocus.com/bid/16113" source="BID">16113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded" source="BUGTRAQ">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref>
      <ref url="http://evuln.com/vulns/7/summary.html" source="MISC">http://evuln.com/vulns/7/summary.html</ref>
      <ref url="http://evuln.com/vulns/7/exploit.html" source="MISC">http://evuln.com/vulns/7/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23963" source="XF">chimera-linkcategory-sql-injection(23963)</ref>
      <ref url="http://www.osvdb.org/22420" source="OSVDB">22420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phanatic_softwares" name="chimera_web_portal">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0138" published="2006-01-09" name="CVE-2006-0138" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/exploits/5JP090KHFQ.html" source="MISC" adv="1">http://www.securiteam.com/exploits/5JP090KHFQ.html</ref>
      <ref url="http://www.osvdb.org/22186" source="OSVDB">22186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amsn" name="amsn">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0139" published="2006-01-09" name="CVE-2006-0139" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16168" source="BID" patch="1">16168</ref>
      <ref url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924" source="CONFIRM" patch="1" adv="1">http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924</ref>
      <ref url="http://www.hamid.ir/security/megabbs.txt" source="MISC" patch="1" adv="1">http://www.hamid.ir/security/megabbs.txt</ref>
      <ref url="http://secunia.com/advisories/18342" source="SECUNIA" patch="1" adv="1">18342</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0095" source="VUPEN">ADV-2006-0095</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24050" source="XF">megabbs-sendprivatemessage-disclosure(24050)</ref>
      <ref url="http://securitytracker.com/id?1015452" source="SECTRACK">1015452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pd9_software" name="megabbs">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0140" published="2006-01-09" name="CVE-2006-0140" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24021" source="XF">navboard-post-xss(24021)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0092" source="VUPEN">ADV-2006-0092</ref>
      <ref url="http://www.securityfocus.com/bid/16165" source="BID">16165</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22277" source="OSVDB">22277</ref>
      <ref url="http://secunia.com/advisories/18345" source="SECUNIA" adv="1">18345</ref>
      <ref url="http://evuln.com/vulns/19/summary.html" source="MISC" adv="1">http://evuln.com/vulns/19/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="navboard" name="navboard">
        <vers num="16" />
        <vers num="17" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0141" published="2006-01-09" name="CVE-2006-0141" modified="2011-03-07" discovered="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.eudora.co.nz/updates.html" source="CONFIRM" patch="1">http://www.eudora.co.nz/updates.html</ref>
      <ref url="http://secunia.com/advisories/18356" source="SECUNIA" patch="1" adv="1">18356</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0099" source="VUPEN">ADV-2006-0099</ref>
      <ref url="http://www.securityfocus.com/bid/16179" source="BID">16179</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24033" source="XF">eims-corrupted-mail-dos(24033)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24032" source="XF">eims-ntlm-auth-dos(24032)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eudora" name="internet_mail_server">
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0142" published="2006-01-09" name="CVE-2006-0142" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0096" source="VUPEN">ADV-2006-0096</ref>
      <ref url="http://www.securityfocus.com/bid/16183" source="BID">16183</ref>
      <ref url="http://secunia.com/advisories/18359" source="SECUNIA" adv="1">18359</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24031" source="XF">andromeda-script-xss(24031)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andromeda_software" name="andromeda">
        <vers prev="1" num="1.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0143" published="2006-01-09" name="CVE-2006-0143" modified="2011-09-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015453" source="SECTRACK" patch="1">1015453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24044" source="XF">win-gre-wmf-dos(24044)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0115" source="VUPEN" adv="1">ADV-2006-0115</ref>
      <ref url="http://www.securityfocus.com/bid/16167" source="BID">16167</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded" source="BUGTRAQ" adv="1">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded" source="BUGTRAQ" adv="1">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</ref>
      <ref url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html" source="MISC">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="enterprise_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0144" published="2006-01-09" name="CVE-2006-0144" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18390" source="SECUNIA" patch="1" adv="1">18390</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24076" source="XF">gopear-proxy-redirection(24076)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0148" source="VUPEN" adv="1">ADV-2006-0148</ref>
      <ref url="http://www.securityfocus.com/bid/16174" source="BID">16174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded" source="BUGTRAQ">20060109 New PEAR / Apache2Triad Exploit</ref>
      <ref url="http://apache2triad.net/forums/viewtopic.php?p=14670" source="CONFIRM">http://apache2triad.net/forums/viewtopic.php?p=14670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache2triad" name="apache2triad">
        <vers num="" />
      </prod>
      <prod vendor="php" name="pear">
        <vers num="0.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0145" published="2006-01-09" name="CVE-2006-0145" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16173" source="BID" patch="1">16173</ref>
      <ref url="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html" source="MISC" adv="1">http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded" source="BUGTRAQ">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</ref>
      <ref url="http://www.osvdb.org/22293" source="OSVDB">22293</ref>
      <ref url="http://secunia.com/advisories/18712" source="SECUNIA" adv="1">18712</ref>
      <ref url="http://secunia.com/advisories/18388" source="SECUNIA" adv="1">18388</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc" source="NETBSD">NetBSD-SA2006-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24035" source="XF">netbsd-kernfs-memory-disclosure(24035)</ref>
      <ref url="http://securityreason.com/securityalert/405" source="SREASON">405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0146" published="2006-01-09" name="CVE-2006-0146" modified="2011-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xaraya.com/index.php/news/569" source="CONFIRM" patch="1">http://www.xaraya.com/index.php/news/569</ref>
      <ref url="http://www.securityfocus.com/bid/16187" source="BID" patch="1">16187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded" source="BUGTRAQ" patch="1">20060202 Bug for libs in php link directory 2.0</ref>
      <ref url="http://www.osvdb.org/22290" source="OSVDB" patch="1">22290</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200604-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN" patch="1" adv="1">DSA-1031</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN" patch="1" adv="1">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN" patch="1" adv="1">DSA-1029</ref>
      <ref url="http://secunia.com/secunia_research/2005-64/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-64/advisory/</ref>
      <ref url="http://secunia.com/advisories/19699" source="SECUNIA" patch="1" adv="1">19699</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA" patch="1" adv="1">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA" patch="1" adv="1">19590</ref>
      <ref url="http://secunia.com/advisories/19563" source="SECUNIA" patch="1" adv="1">19563</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA" patch="1" adv="1">19555</ref>
      <ref url="http://secunia.com/advisories/18720" source="SECUNIA" patch="1" adv="1">18720</ref>
      <ref url="http://secunia.com/advisories/18276" source="SECUNIA" patch="1" adv="1">18276</ref>
      <ref url="http://secunia.com/advisories/18260" source="SECUNIA" patch="1" adv="1">18260</ref>
      <ref url="http://secunia.com/advisories/18233" source="SECUNIA" patch="1" adv="1">18233</ref>
      <ref url="http://secunia.com/advisories/17418" source="SECUNIA" patch="1" adv="1">17418</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24051" source="XF">adodb-server-command-execution(24051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1419" source="VUPEN">ADV-2006-1419</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1305" source="VUPEN" adv="1">ADV-2006-1305</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1304" source="VUPEN" adv="1">ADV-2006-1304</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0447" source="VUPEN" adv="1">ADV-2006-0447</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0370" source="VUPEN" adv="1">ADV-2006-0370</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0105" source="VUPEN" adv="1">ADV-2006-0105</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0104" source="VUPEN" adv="1">ADV-2006-0104</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0103" source="VUPEN" adv="1">ADV-2006-0103</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0102" source="VUPEN">ADV-2006-0102</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0101" source="VUPEN" adv="1">ADV-2006-0101</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded" source="BUGTRAQ">20070418 MediaBeez Sql query Execution .. Wear isn't ?? :)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded" source="BUGTRAQ">20060409 PhpOpenChat 3.0.x ADODB Server.php </ref>
      <ref url="http://www.maxdev.com/Article550.phtml" source="CONFIRM">http://www.maxdev.com/Article550.phtml</ref>
      <ref url="http://securityreason.com/securityalert/713" source="SREASON">713</ref>
      <ref url="http://secunia.com/advisories/24954" source="SECUNIA" adv="1">24954</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA" adv="1">19691</ref>
      <ref url="http://secunia.com/advisories/19600" source="SECUNIA" adv="1">19600</ref>
      <ref url="http://secunia.com/advisories/18267" source="SECUNIA" adv="1">18267</ref>
      <ref url="http://secunia.com/advisories/18254" source="SECUNIA" adv="1">18254</ref>
      <ref url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html" source="MISC">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66" />
        <vers num="4.68" />
      </prod>
      <prod vendor="mantis" name="mantis">
        <vers num="0.19.4" />
        <vers num="1.0.0_rc4" />
      </prod>
      <prod vendor="mediabeez" name="mediabeez">
        <vers num="" />
      </prod>
      <prod vendor="moodle" name="moodle">
        <vers num="1.5.3" />
      </prod>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.761" />
      </prod>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8.6g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0147" published="2006-01-09" name="CVE-2006-0147" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22291" source="OSVDB" patch="1">22291</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200604-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN" patch="1" adv="1">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN" patch="1" adv="1">DSA-1029</ref>
      <ref url="http://secunia.com/secunia_research/2005-64/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-64/advisory/</ref>
      <ref url="http://secunia.com/advisories/19628" source="SECUNIA" patch="1" adv="1">19628</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA" patch="1" adv="1">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA" patch="1" adv="1">19590</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA" patch="1" adv="1">19555</ref>
      <ref url="http://secunia.com/advisories/18276" source="SECUNIA" patch="1" adv="1">18276</ref>
      <ref url="http://secunia.com/advisories/18260" source="SECUNIA" patch="1" adv="1">18260</ref>
      <ref url="http://secunia.com/advisories/18254" source="SECUNIA" patch="1" adv="1">18254</ref>
      <ref url="http://secunia.com/advisories/18233" source="SECUNIA" patch="1" adv="1">18233</ref>
      <ref url="http://secunia.com/advisories/17418" source="SECUNIA" patch="1" adv="1">17418</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1332" source="VUPEN">ADV-2006-1332</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1305" source="VUPEN">ADV-2006-1305</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0104" source="VUPEN">ADV-2006-0104</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0103" source="VUPEN">ADV-2006-0103</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0102" source="VUPEN">ADV-2006-0102</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0101" source="VUPEN">ADV-2006-0101</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" source="BUGTRAQ">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded" source="BUGTRAQ">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN">DSA-1031</ref>
      <ref url="http://secunia.com/advisories/19600" source="SECUNIA" adv="1">19600</ref>
      <ref url="http://secunia.com/advisories/18267" source="SECUNIA" adv="1">18267</ref>
      <ref url="http://retrogod.altervista.org/simplog_092_incl_xpl.html" source="MISC">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
      <ref url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html" source="MISC">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</ref>
      <ref url="http://milw0rm.com/exploits/1663" source="MILW0RM">1663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24052" source="XF">adodb-tmssql-command-execution(24052)</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA">19691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66" />
        <vers num="4.68" />
      </prod>
      <prod vendor="mantis" name="mantis">
        <vers num="0.19.4" />
        <vers num="1.0.0_rc4" />
      </prod>
      <prod vendor="moodle" name="moodle">
        <vers num="1.5.3" />
      </prod>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.761" />
      </prod>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8.6g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0148" published="2006-01-09" name="CVE-2006-0148" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16164" source="BID">16164</ref>
      <ref url="http://www.ipomonis.com/advisories/xlpd.txt" source="MISC" adv="1">http://www.ipomonis.com/advisories/xlpd.txt</ref>
      <ref url="http://securitytracker.com/id?1015444" source="SECTRACK">1015444</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24041" source="XF">xlpd-connection-dos(24041)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netsarang" name="xlpd">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0149" published="2006-01-09" name="CVE-2006-0149" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015451" source="SECTRACK" adv="1">1015451</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html" source="FULLDISC" adv="1">20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simpbook" name="simpbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0150" published="2006-01-09" name="CVE-2006-0150" modified="2011-09-09" discovered="2005-12-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017" source="MANDRIVA" patch="1" adv="1">MDKSA-2006:017</ref>
      <ref url="http://www.securityfocus.com/bid/16177" source="BID" patch="1">16177</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0179.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0179</ref>
      <ref url="http://www.debian.org/security/2006/dsa-952" source="DEBIAN" patch="1" adv="1">DSA-952</ref>
      <ref url="http://secunia.com/advisories/18568" source="SECUNIA" patch="1" adv="1">18568</ref>
      <ref url="http://secunia.com/advisories/18412" source="SECUNIA" patch="1" adv="1">18412</ref>
      <ref url="http://secunia.com/advisories/18405" source="SECUNIA" patch="1" adv="1">18405</ref>
      <ref url="http://secunia.com/advisories/18382" source="SECUNIA" patch="1" adv="1">18382</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24030" source="XF">apache-authldap-format-string(24030)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0117" source="VUPEN" adv="1">ADV-2006-0117</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded" source="BUGTRAQ" adv="1">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</ref>
      <ref url="http://www.rudedog.org/auth_ldap/Changes.html" source="CONFIRM">http://www.rudedog.org/auth_ldap/Changes.html</ref>
      <ref url="http://www.digitalarmaments.com/2006090173928420.html" source="MISC" adv="1">http://www.digitalarmaments.com/2006090173928420.html</ref>
      <ref url="http://securitytracker.com/id?1015456" source="SECTRACK">1015456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_carrigan" name="auth_ldap">
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4.0" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0151" published="2006-01-09" name="CVE-2006-0151" modified="2010-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18363" source="SECUNIA" patch="1" adv="1">18363</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2" source="UBUNTU">USN-235-2</ref>
      <ref url="http://www.securityfocus.com/bid/16184" source="BID">16184</ref>
      <ref url="http://secunia.com/advisories/18358" source="SECUNIA" adv="1">18358</ref>
      <ref url="http://www.trustix.org/errata/2006/0010" source="TRUSTIX">2006-0010</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_02_sr.html" source="SUSE">SUSE-SR:2006:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159" source="MANDRIVA">MDKSA-2006:159</ref>
      <ref url="http://www.debian.org/security/2006/dsa-946" source="DEBIAN">DSA-946</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822" source="SLACKWARE">SSA:2006-045-08</ref>
      <ref url="http://secunia.com/advisories/21692" source="SECUNIA">21692</ref>
      <ref url="http://secunia.com/advisories/19016" source="SECUNIA">19016</ref>
      <ref url="http://secunia.com/advisories/18906" source="SECUNIA">18906</ref>
      <ref url="http://secunia.com/advisories/18558" source="SECUNIA">18558</ref>
      <ref url="http://secunia.com/advisories/18549" source="SECUNIA">18549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.3_p1" />
        <vers num="1.6.3_p2" />
        <vers num="1.6.3_p3" />
        <vers num="1.6.3_p4" />
        <vers num="1.6.3_p5" />
        <vers num="1.6.3_p6" />
        <vers num="1.6.3_p7" />
        <vers num="1.6.4" />
        <vers num="1.6.4_p1" />
        <vers num="1.6.4_p2" />
        <vers num="1.6.5" />
        <vers num="1.6.5_p1" />
        <vers num="1.6.5_p2" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.7_p5" />
        <vers num="1.6.8" />
        <vers num="1.6.8_p1" />
        <vers num="1.6.8_p12" />
        <vers num="1.6.8_p2" />
        <vers num="1.6.8_p5" />
        <vers num="1.6.8_p7" />
        <vers num="1.6.8_p8" />
        <vers num="1.6.8_p9" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
        <vers num="5.04" edition="" />
        <vers num="5.04" edition=":i386" />
        <vers num="5.04" edition=":amd64" />
        <vers num="5.04" edition=":powerpc" />
        <vers num="5.10" edition="" />
        <vers num="5.10" edition=":powerpc" />
        <vers num="5.10" edition=":i386" />
        <vers num="5.10" edition=":amd64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0152" published="2006-01-10" name="CVE-2006-0152" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0094" source="VUPEN">ADV-2006-0094</ref>
      <ref url="http://www.securityfocus.com/bid/16180" source="BID">16180</ref>
      <ref url="http://secunia.com/advisories/18360" source="SECUNIA" adv="1">18360</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24029" source="XF">phpchamber-searchresult-xss(24029)</ref>
      <ref url="http://www.osvdb.org/22282" source="OSVDB">22282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpchamber" name="phpchamber">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0153" published="2006-01-10" name="CVE-2006-0153" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0091" source="VUPEN">ADV-2006-0091</ref>
      <ref url="http://www.securityfocus.com/bid/16178" source="BID">16178</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
      <ref url="http://secunia.com/advisories/18354" source="SECUNIA" adv="1">18354</ref>
      <ref url="http://evuln.com/vulns/18/summary.html" source="MISC" adv="1">http://evuln.com/vulns/18/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24038" source="XF">427bb-scripts-security-bypass(24038)</ref>
      <ref url="http://www.osvdb.org/22274" source="OSVDB">22274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0154" published="2006-01-10" name="CVE-2006-0154" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0091" source="VUPEN">ADV-2006-0091</ref>
      <ref url="http://www.securityfocus.com/bid/16169" source="BID">16169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
      <ref url="http://secunia.com/advisories/18354" source="SECUNIA" adv="1">18354</ref>
      <ref url="http://evuln.com/vulns/18/summary.html" source="MISC" adv="1">http://evuln.com/vulns/18/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24039" source="XF">427bb-showthread-sql-injection(24039)</ref>
      <ref url="http://www.osvdb.org/22275" source="OSVDB">22275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0155" published="2006-01-10" name="CVE-2006-0155" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0091" source="VUPEN">ADV-2006-0091</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
      <ref url="http://secunia.com/advisories/18354" source="SECUNIA" adv="1">18354</ref>
      <ref url="http://evuln.com/vulns/18/summary.html" source="MISC">http://evuln.com/vulns/18/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24040" source="XF">427bb-posts-xss(24040)</ref>
      <ref url="http://www.osvdb.org/22276" source="OSVDB">22276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0156" published="2006-01-10" name="CVE-2006-0156" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0121" source="VUPEN">ADV-2006-0121</ref>
      <ref url="http://www.securityfocus.com/bid/16172" source="BID">16172</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded" source="BUGTRAQ" adv="1">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</ref>
      <ref url="http://secunia.com/advisories/18386" source="SECUNIA" adv="1">18386</ref>
      <ref url="http://evuln.com/vulns/20" source="MISC" adv="1">http://evuln.com/vulns/20</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24043" source="XF">foxrum-bbcode-xss(24043)</ref>
      <ref url="http://securityreason.com/securityalert/325" source="SREASON">325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxrum" name="foxrum">
        <vers num="4.0.4f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0157" published="2006-01-10" name="CVE-2006-0157" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16182" source="BID">16182</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl</ref>
      <ref url="http://secunia.com/advisories/18601" source="SECUNIA">18601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_news_plus">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0158" published="2006-01-10" name="CVE-2006-0158" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0038" source="VUPEN">ADV-2006-0038</ref>
      <ref url="http://www.osvdb.org/22205" source="OSVDB">22205</ref>
      <ref url="http://secunia.com/advisories/18305" source="SECUNIA" adv="1">18305</ref>
      <ref url="http://osvdb.org/ref/22/22205-sitesuite.txt" source="MISC">http://osvdb.org/ref/22/22205-sitesuite.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyberdoc" name="sitesuite_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0159" published="2006-01-10" name="CVE-2006-0159" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0073" source="VUPEN">ADV-2006-0073</ref>
      <ref url="http://www.osvdb.org/22264" source="OSVDB">22264</ref>
      <ref url="http://secunia.com/advisories/18327" source="SECUNIA" adv="1">18327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24017" source="XF">domus-escribir-sql-injection(24017)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0160" published="2006-01-10" name="CVE-2006-0160" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24046" source="XF">venomboard-addpost-sql-injection(24046)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0122" source="VUPEN" adv="1">ADV-2006-0122</ref>
      <ref url="http://www.securityfocus.com/bid/16176" source="BID">16176</ref>
      <ref url="http://www.osvdb.org/22297" source="OSVDB">22297</ref>
      <ref url="http://securityreason.com/securityalert/326" source="SREASON">326</ref>
      <ref url="http://secunia.com/advisories/18383" source="SECUNIA" adv="1">18383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2" source="BUGTRAQ" adv="1">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref>
      <ref url="http://evuln.com/vulns/21/summary.html" source="MISC" adv="1">http://evuln.com/vulns/21/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="venom_board" name="venom_board">
        <vers num="1.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0161" published="2006-01-10" name="CVE-2006-0161" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1" source="SUNALERT" patch="1" adv="1">101933</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0113" source="VUPEN">ADV-2006-0113</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015455" source="SECTRACK">1015455</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://secunia.com/advisories/18371" source="SECUNIA">18371</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534" source="OVAL" sig="1">oval:org.mitre.oval:def:1534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0162" published="2006-01-10" name="CVE-2006-0162" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/385908" source="CERT-VN">VU#385908</ref>
      <ref url="http://www.securityfocus.com/bid/16191" source="BID" patch="1">16191</ref>
      <ref url="http://secunia.com/advisories/18379" source="SECUNIA" patch="1" adv="1">18379</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0116" source="VUPEN">ADV-2006-0116</ref>
      <ref url="http://www.clamav.net/doc/0.88/ChangeLog" source="CONFIRM">http://www.clamav.net/doc/0.88/ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24047" source="XF">clamav-libclamav-upx-bo(24047)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-001.html</ref>
      <ref url="http://www.trustix.org/errata/2006/0002/" source="TRUSTIX">2006-0002</ref>
      <ref url="http://www.osvdb.org/22318" source="OSVDB">22318</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016" source="MANDRIVA">MDKSA-2006:016</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml" source="GENTOO">GLSA-200601-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-947" source="DEBIAN">DSA-947</ref>
      <ref url="http://securitytracker.com/id?1015457" source="SECTRACK">1015457</ref>
      <ref url="http://securityreason.com/securityalert/342" source="SREASON">342</ref>
      <ref url="http://secunia.com/advisories/18548" source="SECUNIA">18548</ref>
      <ref url="http://secunia.com/advisories/18478" source="SECUNIA">18478</ref>
      <ref url="http://secunia.com/advisories/18463" source="SECUNIA">18463</ref>
      <ref url="http://secunia.com/advisories/18453" source="SECUNIA">18453</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html" source="FULLDISC">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="." />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" />
        <vers num="0.75.1" />
        <vers num="0.80" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.80_rc4" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0163" published="2006-01-11" name="CVE-2006-0163" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44978" source="XF">phpnukeev-search-sql-injection(44978)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0120" source="VUPEN">ADV-2006-0120</ref>
      <ref url="http://www.securityfocus.com/bid/16186" source="BID">16186</ref>
      <ref url="http://www.osvdb.org/22316" source="OSVDB">22316</ref>
      <ref url="http://secunia.com/advisories/18394" source="SECUNIA">18394</ref>
      <ref url="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html" source="MISC" adv="1">http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke_ev">
        <vers num="7.7_r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0164" published="2006-01-11" name="CVE-2006-0164" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=384232" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=384232</ref>
      <ref url="http://secunia.com/advisories/18346" source="SECUNIA" patch="1" adv="1">18346</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0123" source="VUPEN">ADV-2006-0123</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24062" source="XF">phgstats-php-file-include(24062)</ref>
      <ref url="http://www.securityfocus.com/bid/17469" source="BID">17469</ref>
      <ref url="http://www.osvdb.org/22302" source="OSVDB">22302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woah-projekt" name="phgstats">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0165" published="2006-01-11" name="CVE-2006-0165" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417</ref>
      <ref url="http://secunia.com/advisories/18372" source="SECUNIA" patch="1" adv="1">18372</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0126" source="VUPEN">ADV-2006-0126</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24053" source="XF">webgui-forms-xss(24053)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="5.5.8" />
        <vers num="6.2.10_gamma" />
        <vers num="6.2.11_gamma" />
        <vers num="6.3.0_beta" />
        <vers num="6.4.0_beta" />
        <vers num="6.5.0_beta" />
        <vers num="6.5.1_beta" />
        <vers num="6.5.2_beta" />
        <vers num="6.5.3_beta" />
        <vers num="6.5.4_gamma" />
        <vers num="6.5.5_gamma" />
        <vers num="6.5.6_gamma" />
        <vers num="6.6.0_beta" />
        <vers num="6.6.1_beta" />
        <vers num="6.6.2_gamma" />
        <vers num="6.6.3_gamma" />
        <vers num="6.6.4_gamma" />
        <vers num="6.6.5" />
        <vers num="6.7.0_beta" />
        <vers num="6.7.1_beta" />
        <vers num="6.7.2_beta" />
        <vers num="6.7.3_gamma" />
        <vers num="6.7.4_gamma" />
        <vers num="6.7.5_gamma" />
        <vers num="6.7.6_gamma" />
        <vers num="6.7.7_gamma" />
        <vers num="6.7.8_gamma" />
        <vers num="6.8.1_beta" />
        <vers num="6.8.2_beta" />
        <vers num="6.8.3_gamma" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0166" published="2006-01-11" name="CVE-2006-0166" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015462" source="SECTRACK" patch="1">1015462</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html</ref>
      <ref url="http://secunia.com/advisories/18402" source="SECUNIA" patch="1" adv="1">18402</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24061" source="XF">systemworks-nprotect-hidden(24061)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0143" source="VUPEN">ADV-2006-0143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2005" />
        <vers num="2005_premier" />
        <vers num="2006" />
        <vers num="2006_premier" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0167" published="2006-01-11" name="CVE-2006-0167" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24075" source="XF">myphpim-login-sql-injection(24075)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24066" source="XF">myphpim-calendar-sql-injection(24066)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0147" source="VUPEN">ADV-2006-0147</ref>
      <ref url="http://www.securityfocus.com/bid/16210" source="BID">16210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded" source="BUGTRAQ">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22325" source="OSVDB">22325</ref>
      <ref url="http://www.osvdb.org/22324" source="OSVDB">22324</ref>
      <ref url="http://secunia.com/advisories/18399" source="SECUNIA" adv="1">18399</ref>
      <ref url="http://evuln.com/vulns/22/summary.html" source="MISC" adv="1">http://evuln.com/vulns/22/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpim" name="myphpim">
        <vers num="01.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0168" published="2006-01-11" name="CVE-2006-0168" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the "Create New todo" page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24071" source="XF">myphpim-todo-xss(24071)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0147" source="VUPEN">ADV-2006-0147</ref>
      <ref url="http://www.securityfocus.com/bid/16210" source="BID">16210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded" source="BUGTRAQ">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22326" source="OSVDB">22326</ref>
      <ref url="http://secunia.com/advisories/18399" source="SECUNIA" adv="1">18399</ref>
      <ref url="http://evuln.com/vulns/22/summary.html" source="MISC" adv="1">http://evuln.com/vulns/22/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpim" name="myphpim">
        <vers num="01.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0169" published="2006-01-11" name="CVE-2006-0169" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24070" source="XF">myphpim-addresses-file-upload(24070)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0147" source="VUPEN">ADV-2006-0147</ref>
      <ref url="http://www.securityfocus.com/bid/16208" source="BID">16208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421626/100/0/threaded" source="BUGTRAQ" adv="1">20060111 [eVuln] MyPhPim Arbitrary File Upload</ref>
      <ref url="http://secunia.com/advisories/18399" source="SECUNIA" adv="1">18399</ref>
      <ref url="http://evuln.com/vulns/23/summary.html" source="MISC">http://evuln.com/vulns/23/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpim" name="myphpim">
        <vers num="01.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0170" reject="1" published="2006-01-11" name="CVE-2006-0170" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2006-0171" published="2006-01-11" name="CVE-2006-0171" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16199" source="BID">16199</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421312/100/0/threaded" source="BUGTRAQ">20060106 Orjinweb E-commerce</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24097" source="XF">orjinweb-url-file-include(24097)</ref>
      <ref url="http://www.osvdb.org/22387" source="OSVDB">22387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orjinweb" name="orjinweb_e-commerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0172" published="2006-01-11" name="CVE-2006-0172" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0145" source="VUPEN">ADV-2006-0145</ref>
      <ref url="http://www.securityfocus.com/bid/16195" source="BID">16195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" source="BUGTRAQ" adv="1">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
      <ref url="http://www.securenetwork.it/advisories/sn-2006-01.html" source="MISC" adv="1">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
      <ref url="http://secunia.com/advisories/18411" source="SECUNIA" adv="1">18411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24067" source="XF">hummingbird-enterprise-xss(24067)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="enterprise_collaboration">
        <vers num="5.2" />
        <vers prev="1" num="5.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0173" published="2006-01-11" name="CVE-2006-0173" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0145" source="VUPEN">ADV-2006-0145</ref>
      <ref url="http://www.securityfocus.com/bid/16195" source="BID">16195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" source="BUGTRAQ" adv="1">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
      <ref url="http://www.securenetwork.it/advisories/sn-2006-01.html" source="MISC" adv="1">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
      <ref url="http://secunia.com/advisories/18411" source="SECUNIA" adv="1">18411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24068" source="XF">hummingbird-enterprise-file-download(24068)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="enterprise_collaboration">
        <vers num="5.2" />
        <vers prev="1" num="5.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0174" published="2006-01-11" name="CVE-2006-0174" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0145" source="VUPEN">ADV-2006-0145</ref>
      <ref url="http://www.securityfocus.com/bid/16195" source="BID">16195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" source="BUGTRAQ">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
      <ref url="http://www.securenetwork.it/advisories/sn-2006-01.html" source="MISC">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
      <ref url="http://secunia.com/advisories/18411" source="SECUNIA">18411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24069" source="XF">hummingbird-enterprise-information-disclosure(24069)</ref>
      <ref url="http://securityreason.com/securityalert/328" source="SREASON">328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="collaboration">
        <vers num="5.2" />
        <vers prev="1" num="5.21" />
      </prod>
      <prod vendor="hummingbird" name="enterprise_collaboration">
        <vers num="5.2" />
        <vers prev="1" num="5.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0175" published="2006-01-11" name="CVE-2006-0175" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16196" source="BID" patch="1">16196</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421615/100/0/threaded" source="BUGTRAQ">20060111 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34(search_form.asp)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html" source="FULLDISC">20060109 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24048" source="XF">webwizforums-searchform-xss(24048)</ref>
      <ref url="http://www.osvdb.org/22398" source="OSVDB">22398</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0176" published="2006-01-11" name="CVE-2006-0176" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16203" source="BID">16203</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421849/100/0/threaded" source="BUGTRAQ">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html" source="FULLDISC">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24102" source="XF">xmame-multiple-parameters-bo(24102)</ref>
      <ref url="http://x.mame.net/changes-unix.html" source="CONFIRM">http://x.mame.net/changes-unix.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmame" name="xmame">
        <vers num="0.102" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0177" published="2006-01-11" name="CVE-2006-0177" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16205" source="BID">16205</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html" source="FULLDISC">20060110 SUID root overflows in UNICOS and partial shellcode</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24276" source="XF">unicos-command-line-bo(24276)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cray" name="unicos">
        <vers num="9.0.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0178" published="2006-01-11" name="CVE-2006-0178" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16205" source="BID">16205</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html" source="FULLDISC">20060110 SUID root overflows in UNICOS and partial shellcode</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24277" source="XF">unicos-ftp-format-string(24277)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cray" name="unicos">
        <vers num="9.0.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0179" published="2006-01-11" name="CVE-2006-0179" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015488" source="SECTRACK" patch="1">1015488</ref>
      <ref url="http://secunia.com/advisories/18479" source="SECUNIA" patch="1" adv="1">18479</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24117" source="XF">cisco-ipphone-synflood-dos(24117)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0202" source="VUPEN" adv="1">ADV-2006-0202</ref>
      <ref url="http://www.securityfocus.com/bid/16200" source="BID">16200</ref>
      <ref url="http://www.osvdb.org/22469" source="OSVDB">22469</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml" source="CISCO" adv="1">20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ip_phone_7940">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0180" published="2006-01-12" name="CVE-2006-0180" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0149" source="VUPEN">ADV-2006-0149</ref>
      <ref url="http://www.securityfocus.com/bid/16206" source="BID">16206</ref>
      <ref url="http://secunia.com/advisories/18417" source="SECUNIA" adv="1">18417</ref>
      <ref url="http://evuln.com/vulns/24/summary.html" source="MISC" adv="1">http://evuln.com/vulns/24/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24077" source="XF">calogic-newevent-xss(24077)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422163/100/0/threaded" source="BUGTRAQ">20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22322" source="OSVDB">22322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calogic" name="calogic_calendars">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0181" published="2006-01-12" name="CVE-2006-0181" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16211" source="BID" patch="1">16211</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml" source="CISCO" patch="1" adv="1">20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0154" source="VUPEN">ADV-2006-0154</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24065" source="XF">cisco-csmars-default-password(24065)</ref>
      <ref url="http://www.osvdb.org/22346" source="OSVDB">22346</ref>
      <ref url="http://securitytracker.com/id?1015471" source="SECTRACK">1015471</ref>
      <ref url="http://securityreason.com/securityalert/335" source="SREASON">335</ref>
      <ref url="http://secunia.com/advisories/18424" source="SECUNIA">18424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cs-mars">
        <vers num="4.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0182" published="2006-01-12" name="CVE-2006-0182" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0152" source="VUPEN">ADV-2006-0152</ref>
      <ref url="http://evuln.com/vulns/25/summary.html" source="MISC" adv="1">http://evuln.com/vulns/25/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24104" source="XF">acal-login-auth-bypass(24104)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref>
      <ref url="http://www.osvdb.org/22344" source="OSVDB">22344</ref>
      <ref url="http://securityreason.com/securityalert/343" source="SREASON">343</ref>
      <ref url="http://secunia.com/advisories/18432" source="SECUNIA">18432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acal" name="calendar_project">
        <vers num="2.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0183" published="2006-01-12" name="CVE-2006-0183" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0152" source="VUPEN">ADV-2006-0152</ref>
      <ref url="http://evuln.com/vulns/25/summary.html" source="MISC" adv="1">http://evuln.com/vulns/25/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24107" source="XF">acal-header-footer-code-execute(24107)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref>
      <ref url="http://www.osvdb.org/22345" source="OSVDB">22345</ref>
      <ref url="http://securityreason.com/securityalert/343" source="SREASON">343</ref>
      <ref url="http://secunia.com/advisories/18432" source="SECUNIA">18432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acal" name="calendar_project">
        <vers num="2.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0184" published="2006-01-12" name="CVE-2006-0184" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0146" source="VUPEN">ADV-2006-0146</ref>
      <ref url="http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt" source="MISC" adv="1">http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt</ref>
      <ref url="http://secunia.com/advisories/18408" source="SECUNIA" adv="1">18408</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24072" source="XF">asptopsites-goto-sql-injection(24072)</ref>
      <ref url="http://www.osvdb.org/22330" source="OSVDB">22330</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html" source="FULLDISC">20060110 AspTopSites SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mainenet_enterprises" name="asptopsites">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0185" published="2006-01-12" name="CVE-2006-0185" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0125" source="VUPEN">ADV-2006-0125</ref>
      <ref url="http://www.securityfocus.com/bid/16192" source="BID">16192</ref>
      <ref url="http://www.securityfocus.com/archive/1/421322" source="BUGTRAQ">20060107 Php-Nuke Pool and News Module IMG Tag Cross Site</ref>
      <ref url="http://secunia.com/advisories/18374" source="SECUNIA" adv="1">18374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="news_module">
        <vers num="" />
      </prod>
      <prod vendor="php-nuke" name="pool_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0186" reject="1" published="2006-01-12" name="CVE-2006-0186" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0187" published="2006-01-12" name="CVE-2006-0187" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0151" source="VUPEN">ADV-2006-0151</ref>
      <ref url="http://www.securityfocus.com/bid/16225" source="BID">16225</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421943/100/0/threaded" source="BUGTRAQ">20060113 Visual Studio Remote Code Execution</ref>
      <ref url="http://secunia.com/advisories/18409" source="SECUNIA" adv="1">18409</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24116" source="XF">visualstudio-usercontrol-code-execution(24116)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0188" published="2006-02-23" name="CVE-2006-0188" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter.  NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24847" source="XF">squirrelmail-webmail-xss(24847)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0689" source="VUPEN">ADV-2006-0689</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2006-02-01" source="CONFIRM">http://www.squirrelmail.org/security/issue/2006-02-01</ref>
      <ref url="http://www.securityfocus.com/bid/16756" source="BID">16756</ref>
      <ref url="http://securitytracker.com/id?1015662" source="SECTRACK">1015662</ref>
      <ref url="http://secunia.com/advisories/18985" source="SECUNIA" adv="1">18985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10419" source="OVAL">oval:org.mitre.oval:def:10419</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0283.html" source="REDHAT">RHSA-2006:0283</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" source="FEDORA">FEDORA-2006-133</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" source="MANDRIVA">MDKSA-2006:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" source="GENTOO">GLSA-200603-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-988" source="DEBIAN">DSA-988</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/19960" source="SECUNIA">19960</ref>
      <ref url="http://secunia.com/advisories/19205" source="SECUNIA">19205</ref>
      <ref url="http://secunia.com/advisories/19176" source="SECUNIA">19176</ref>
      <ref url="http://secunia.com/advisories/19131" source="SECUNIA">19131</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_r3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.4.4" />
        <vers num="1.4.4_rc1" />
        <vers num="1.4.5" />
        <vers num="1.4.6_rc1" />
        <vers num="1.4_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0189" published="2006-01-13" name="CVE-2006-0189" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.</descript>
    </desc>
    <sols>
      <sol source="nvd">This is the vendor provided solution:

"eStara has released Softphone version 3.0.1.47 to resolve the buffer overflow demonstrated in parsing SDP with long "a=" lines.  Licensed customers can download a new version via the email sent to them with purchase, customers testing may go back to http://www.estara.com/softphone/ to obtain a new free trial.   Version information can be gathered by going to Help->About.  eStara highly recommends all customers upgrade to avoid this issue.  If there's further questions please email us: softphone@estara.com.
 
eStara would like to thank ZwelL for bringing the issue to our attention."</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24090" source="XF">estara-sip-sdp-bo(24090)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0167" source="VUPEN">ADV-2006-0167</ref>
      <ref url="http://www.securityfocus.com/bid/16213" source="BID">16213</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421596/100/0/threaded" source="BUGTRAQ" adv="1">20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015481" source="SECTRACK">1015481</ref>
      <ref url="http://secunia.com/advisories/18410" source="SECUNIA">18410</ref>
      <ref url="http://www.osvdb.org/22348" source="OSVDB">22348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estara" name="softphone">
        <vers num="3.0.1.14" />
        <vers num="3.0.1.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0190" published="2006-01-13" name="CVE-2006-0190" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1" source="SUNALERT" patch="1" adv="1">102066</ref>
      <ref url="http://secunia.com/advisories/18421" source="SECUNIA" patch="1" adv="1">18421</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0165" source="VUPEN">ADV-2006-0165</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24084" source="XF">solaris-unspecified-root-access(24084)</ref>
      <ref url="http://www.securityfocus.com/bid/16224" source="BID">16224</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015478" source="SECTRACK">1015478</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:702" source="OVAL" sig="1">oval:org.mitre.oval:def:702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0191" published="2006-01-13" name="CVE-2006-0191" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1" source="SUNALERT" patch="1" adv="1">102108</ref>
      <ref url="http://secunia.com/advisories/18420" source="SECUNIA" patch="1" adv="1">18420</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0166" source="VUPEN">ADV-2006-0166</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24085" source="XF">solaris-find-proc-dos(24085)</ref>
      <ref url="http://www.securityfocus.com/bid/16222" source="BID">16222</ref>
      <ref url="http://www.osvdb.org/22347" source="OSVDB">22347</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015479" source="SECTRACK">1015479</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1608" source="OVAL" sig="1">oval:org.mitre.oval:def:1608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0192" published="2006-01-13" name="CVE-2006-0192" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24087" source="XF">aspsurvey-loginvalidate-sql-injection(24087)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0164" source="VUPEN" adv="1">ADV-2006-0164</ref>
      <ref url="http://www.securityfocus.com/bid/16496" source="BID">16496</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423949/100/0/threaded" source="BUGTRAQ">20060204 sql injection in ASP Survey</ref>
      <ref url="http://www.osvdb.org/22342" source="OSVDB">22342</ref>
      <ref url="http://securityreason.com/securityalert/414" source="SREASON">414</ref>
      <ref url="http://secunia.com/advisories/18422" source="SECUNIA" adv="1">18422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philip_loftin" name="aspsurvey">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0193" published="2006-01-13" name="CVE-2006-0193" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421704/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060112 H-Sphere Security Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0172" source="VUPEN">ADV-2006-0172</ref>
      <ref url="http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r" source="CONFIRM">http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24096" source="XF">hsphere-login-xss(24096)</ref>
      <ref url="http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r" source="CONFIRM">http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r</ref>
      <ref url="http://www.osvdb.org/22372" source="OSVDB">22372</ref>
      <ref url="http://secunia.com/advisories/18447" source="SECUNIA">18447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="positive_software" name="h-sphere">
        <vers num="2.4.1" />
        <vers num="2.4.1_patch_1" />
        <vers num="2.4.1_patch_2" />
        <vers num="2.4.1_patch_3" />
        <vers num="2.4.1_patch_4" />
        <vers num="2.4.1_patch_5" />
        <vers num="2.4.1_patch_6" />
        <vers num="2.4.1_patch_7" />
        <vers num="2.4.2" />
        <vers num="2.4.2_beta_1" />
        <vers num="2.4.2_beta_2" />
        <vers num="2.4.2_beta_3" />
        <vers num="2.4.2_patch_1" />
        <vers num="2.4.2_patch_2" />
        <vers num="2.4.2_patch_3" />
        <vers num="2.4.2_patch_4" />
        <vers num="2.4.2_patch_5" />
        <vers num="2.4.2_rc1" />
        <vers num="2.4.2_rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.3_beta_1" />
        <vers num="2.4.3_beta_2" />
        <vers num="2.4.3_patch_1" />
        <vers num="2.4.3_patch_2" />
        <vers num="2.4.3_patch_3" />
        <vers num="2.4.3_patch_4" />
        <vers num="2.4.3_patch_5" />
        <vers num="2.4.3_patch_6" />
        <vers num="2.4.3_patch_7" />
        <vers num="2.4.3_patch_8" />
        <vers num="2.4.3_rc1" />
        <vers num="2.4.3_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0194" published="2006-01-13" name="CVE-2006-0194" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16216" source="BID" patch="1">16216</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0174" source="VUPEN">ADV-2006-0174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421729/100/0/threaded" source="BUGTRAQ" adv="1">20060112 FogBugz Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html" source="CONFIRM">http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24103" source="XF">fogbugz-login-xss(24103)</ref>
      <ref url="http://www.osvdb.org/22370" source="OSVDB">22370</ref>
      <ref url="http://secunia.com/advisories/18443" source="SECUNIA">18443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fog_creek_software" name="fogbugz">
        <vers prev="1" num="4.029" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0195" published="2006-02-23" name="CVE-2006-0195" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24848" source="XF">squirrelmail-magichtml-xss(24848)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0689" source="VUPEN">ADV-2006-0689</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2006-02-10" source="CONFIRM">http://www.squirrelmail.org/security/issue/2006-02-10</ref>
      <ref url="http://www.securityfocus.com/bid/16756" source="BID">16756</ref>
      <ref url="http://securitytracker.com/id?1015662" source="SECTRACK">1015662</ref>
      <ref url="http://secunia.com/advisories/18985" source="SECUNIA" adv="1">18985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9548" source="OVAL">oval:org.mitre.oval:def:9548</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0283.html" source="REDHAT">RHSA-2006:0283</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" source="FEDORA">FEDORA-2006-133</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" source="MANDRIVA">MDKSA-2006:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" source="GENTOO">GLSA-200603-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-988" source="DEBIAN">DSA-988</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/19960" source="SECUNIA">19960</ref>
      <ref url="http://secunia.com/advisories/19205" source="SECUNIA">19205</ref>
      <ref url="http://secunia.com/advisories/19176" source="SECUNIA">19176</ref>
      <ref url="http://secunia.com/advisories/19131" source="SECUNIA">19131</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_r3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.4.4" />
        <vers num="1.4.4_rc1" />
        <vers num="1.4.5" />
        <vers num="1.4.6_rc1" />
        <vers num="1.4_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0196" published="2006-01-13" name="CVE-2006-0196" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24082" source="XF">slsnif-home-bo(24082)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0212" source="VUPEN">ADV-2006-0212</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421583/100/0/threaded" source="BUGTRAQ">20060111 Serial Line Sniffer 0.4.4 Buffer Overflow</ref>
      <ref url="http://shellcoders.com/sintigan/slsnif-ploit.pl" source="MISC">http://shellcoders.com/sintigan/slsnif-ploit.pl</ref>
      <ref url="http://secunia.com/advisories/18497" source="SECUNIA">18497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serial_line_sniffer" name="serial_line_sniffer">
        <vers num="0.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0197" published="2006-01-13" name="CVE-2006-0197" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded" source="BUGTRAQ" adv="1">20060108 xorg server 6.8.2 and below on 64bit arch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x.org">
        <vers prev="1" num="6.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0198" published="2006-01-13" name="CVE-2006-0198" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481" source="MISC" adv="1">http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481</ref>
      <ref url="http://www.securityfocus.com/bid/16189" source="BID">16189</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded" source="BUGTRAQ">20060107 Xoops Pool Module IMG Tag Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24091" source="XF">xoops-pool-imagetag-xss(24091)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops_pool_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0199" published="2006-01-13" name="CVE-2006-0199" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24098" source="XF">mininuke-news-sql-injection(24098)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0173" source="VUPEN" adv="1">ADV-2006-0173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421727/100/0/threaded" source="BUGTRAQ" adv="1">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injectionvulnerability</ref>
      <ref url="http://www.osvdb.org/22384" source="OSVDB">22384</ref>
      <ref url="http://www.nukedx.com/?viewdoc=7" source="MISC">http://www.nukedx.com/?viewdoc=7</ref>
      <ref url="http://securityreason.com/securityalert/340" source="SREASON">340</ref>
      <ref url="http://secunia.com/advisories/18439" source="SECUNIA" adv="1">18439</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" source="FULLDISC" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-nuke" name="cms_system">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0200" published="2006-01-13" name="CVE-2006-0200" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24095" source="XF" patch="1">php-extmysqli-format-string(24095)</ref>
      <ref url="http://www.securityfocus.com/bid/16219" source="BID" patch="1">16219</ref>
      <ref url="http://www.php.net/release_5_1_2.php" source="CONFIRM" patch="1">http://www.php.net/release_5_1_2.php</ref>
      <ref url="http://secunia.com/advisories/18431" source="SECUNIA" patch="1" adv="1">18431</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0369" source="VUPEN">ADV-2006-0369</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0177" source="VUPEN">ADV-2006-0177</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421705/100/0/threaded" source="BUGTRAQ" adv="1">20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability</ref>
      <ref url="http://www.hardened-php.net/advisory_022006.113.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_022006.113.html</ref>
      <ref url="http://securitytracker.com/id?1015485" source="SECTRACK">1015485</ref>
      <ref url="http://securityreason.com/securityalert/337" source="SREASON">337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.1" />
        <vers num="5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0201" published="2006-01-13" name="CVE-2006-0201" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0183" source="VUPEN">ADV-2006-0183</ref>
      <ref url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" source="MISC" adv="1">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</ref>
      <ref url="http://www.securityfocus.com/bid/16218" source="BID">16218</ref>
      <ref url="http://www.securityfocus.com/archive/1/421739" source="BUGTRAQ" adv="1">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18444" source="SECUNIA" adv="1">18444</ref>
      <ref url="http://www.osvdb.org/22378" source="OSVDB">22378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paypal" name="php_toolkit">
        <vers prev="1" num="0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0202" published="2006-01-13" name="CVE-2006-0202" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0183" source="VUPEN">ADV-2006-0183</ref>
      <ref url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" source="MISC" adv="1">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</ref>
      <ref url="http://www.securityfocus.com/bid/16218" source="BID">16218</ref>
      <ref url="http://www.securityfocus.com/archive/1/421739" source="BUGTRAQ" adv="1">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18444" source="SECUNIA" adv="1">18444</ref>
      <ref url="http://www.osvdb.org/22379" source="OSVDB">22379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paypal" name="php_toolkit">
        <vers prev="1" num="0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0203" published="2006-01-13" name="CVE-2006-0203" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24101" source="XF">mininuke-membership-change-password(24101)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0173" source="VUPEN" adv="1">ADV-2006-0173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421748/100/0/threaded" source="BUGTRAQ" adv="1">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remoteuser password change exploit</ref>
      <ref url="http://www.osvdb.org/22385" source="OSVDB">22385</ref>
      <ref url="http://securityreason.com/securityalert/344" source="SREASON">344</ref>
      <ref url="http://secunia.com/advisories/18439" source="SECUNIA" adv="1">18439</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" source="FULLDISC" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html" source="FULLDISC" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remote user password change exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html" source="BUGTRAQ" adv="1">20060129 [xpl#2] MiniNuke 1.8.2 - change member's passwrod &lt; Perl ></ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-nuke" name="cms_system">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0204" published="2006-01-13" name="CVE-2006-0204" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24106" source="XF">wordcircle-index-xss(24106)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0185" source="VUPEN">ADV-2006-0185</ref>
      <ref url="http://www.securityfocus.com/bid/16227" source="BID">16227</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" source="BUGTRAQ" adv="1">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22359" source="OSVDB">22359</ref>
      <ref url="http://secunia.com/advisories/18440" source="SECUNIA" adv="1">18440</ref>
      <ref url="http://evuln.com/vulns/28/summary.html" source="MISC" adv="1">http://evuln.com/vulns/28/summary.html</ref>
      <ref url="http://securityreason.com/securityalert/345" source="SREASON">345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordcircle" name="wordcircle">
        <vers num="2.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0205" published="2006-01-13" name="CVE-2006-0205" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24108" source="XF">wordcircle-login-security-bypass(24108)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24105" source="XF">wordcircle-sql-injection(24105)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0185" source="VUPEN" adv="1">ADV-2006-0185</ref>
      <ref url="http://www.securityfocus.com/bid/16227" source="BID">16227</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421745/100/0/threaded" source="BUGTRAQ" adv="1">20060112 [eVuln] Wordcircle Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22358" source="OSVDB">22358</ref>
      <ref url="http://securityreason.com/securityalert/346" source="SREASON">346</ref>
      <ref url="http://securityreason.com/securityalert/345" source="SREASON">345</ref>
      <ref url="http://secunia.com/advisories/18440" source="SECUNIA" adv="1">18440</ref>
      <ref url="http://evuln.com/vulns/28/summary.html" source="MISC">http://evuln.com/vulns/28/summary.html</ref>
      <ref url="http://evuln.com/vulns/27/summary.html" source="MISC">http://evuln.com/vulns/27/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordcircle" name="wordcircle">
        <vers num="2.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0206" published="2006-01-13" name="CVE-2006-0206" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16229" source="BID">16229</ref>
      <ref url="http://secunia.com/advisories/18450" source="SECUNIA" adv="1">18450</ref>
      <ref url="http://evuln.com/vulns/29/summary.html" source="MISC" adv="1">http://evuln.com/vulns/29/summary.html</ref>
      <ref url="http://evuln.com/vulns/29/exploit.html" source="MISC">http://evuln.com/vulns/29/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24110" source="XF">lwc-cal-execute-code(24110)</ref>
      <ref url="http://www.osvdb.org/22376" source="OSVDB">22376</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000612.html" source="VIM">20060318 Source VERIFY - Light Weight Calendar issue is eval injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="light_weight_calendar" name="light_weight_calendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0207" published="2006-01-13" name="CVE-2006-0207" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24094" source="XF" patch="1">php-session-response-splitting(24094)</ref>
      <ref url="http://www.securityfocus.com/bid/16220" source="BID" patch="1">16220</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-22</ref>
      <ref url="http://securitytracker.com/id?1015484" source="SECTRACK" patch="1" adv="1">1015484</ref>
      <ref url="http://secunia.com/advisories/19355" source="SECUNIA" patch="1" adv="1">19355</ref>
      <ref url="http://secunia.com/advisories/19179" source="SECUNIA" patch="1" adv="1">19179</ref>
      <ref url="http://secunia.com/advisories/18697" source="SECUNIA" patch="1" adv="1">18697</ref>
      <ref url="http://secunia.com/advisories/18431" source="SECUNIA" patch="1" adv="1">18431</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0369" source="VUPEN" adv="1">ADV-2006-0369</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0177" source="VUPEN" adv="1">ADV-2006-0177</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1" source="UBUNTU">USN-261-1</ref>
      <ref url="http://www.php.net/release_5_1_2.php" source="CONFIRM">http://www.php.net/release_5_1_2.php</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028" source="MANDRIVA">MDKSA-2006:028</ref>
      <ref url="http://www.hardened-php.net/advisory_012006.112.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_012006.112.html</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1331" source="DEBIAN">DSA-1331</ref>
      <ref url="http://secunia.com/advisories/25945" source="SECUNIA">25945</ref>
      <ref url="http://secunia.com/advisories/19012" source="SECUNIA" adv="1">19012</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html" source="SUSE">SUSE-SR:2006:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0208" published="2006-01-13" name="CVE-2006-0208" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16803" source="BID" patch="1">16803</ref>
      <ref url="http://www.php.net/release_5_1_2.php" source="CONFIRM" patch="1">http://www.php.net/release_5_1_2.php</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-22</ref>
      <ref url="http://secunia.com/advisories/19355" source="SECUNIA" patch="1" adv="1">19355</ref>
      <ref url="http://secunia.com/advisories/19179" source="SECUNIA" patch="1" adv="1">19179</ref>
      <ref url="http://secunia.com/advisories/18697" source="SECUNIA" patch="1" adv="1">18697</ref>
      <ref url="http://secunia.com/advisories/18431" source="SECUNIA" patch="1" adv="1">18431</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2685" source="VUPEN" adv="1">ADV-2006-2685</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0369" source="VUPEN" adv="1">ADV-2006-0369</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0177" source="VUPEN" adv="1">ADV-2006-0177</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1" source="UBUNTU">USN-261-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0501.html" source="REDHAT" adv="1">RHSA-2006:0501</ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.4.2" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.4.2</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028" source="MANDRIVA">MDKSA-2006:028</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm</ref>
      <ref url="http://secunia.com/advisories/21564" source="SECUNIA" adv="1">21564</ref>
      <ref url="http://secunia.com/advisories/21252" source="SECUNIA" adv="1">21252</ref>
      <ref url="http://secunia.com/advisories/20951" source="SECUNIA" adv="1">20951</ref>
      <ref url="http://secunia.com/advisories/20222" source="SECUNIA" adv="1">20222</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA" adv="1">20210</ref>
      <ref url="http://secunia.com/advisories/19832" source="SECUNIA" adv="1">19832</ref>
      <ref url="http://secunia.com/advisories/19012" source="SECUNIA" adv="1">19012</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0549.html" source="REDHAT" adv="1">RHSA-2006:0549</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0276.html" source="REDHAT">RHSA-2006:0276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10064" source="OVAL">oval:org.mitre.oval:def:10064</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html" source="SUSE">SUSE-SR:2006:004</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0209" published="2006-01-13" name="CVE-2006-0209" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0153" source="VUPEN">ADV-2006-0153</ref>
      <ref url="http://evuln.com/vulns/26/summary.html" source="MISC">http://evuln.com/vulns/26/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24080" source="XF">tanklogger-generalfunctions-sql-injection(24080)</ref>
      <ref url="http://www.securityfocus.com/bid/16228" source="BID">16228</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421743/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] TankLogger SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22369" source="OSVDB">22369</ref>
      <ref url="http://www.osvdb.org/22368" source="OSVDB">22368</ref>
      <ref url="http://securityreason.com/securityalert/341" source="SREASON">341</ref>
      <ref url="http://secunia.com/advisories/18441" source="SECUNIA">18441</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000480.html" source="VIM">20060113 Verified TankLogger SQl inject by source inspection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tanklogger" name="tanklogger">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0210" published="2006-01-13" name="CVE-2006-0210" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0175" source="VUPEN">ADV-2006-0175</ref>
      <ref url="http://www.securityfocus.com/bid/16214" source="BID">16214</ref>
      <ref url="http://www.interspire.com/forum/showthread.php?p=29606" source="CONFIRM">http://www.interspire.com/forum/showthread.php?p=29606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24112" source="XF">trackpointnx-login-xss(24112)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421740/100/0/threaded" source="BUGTRAQ">20060112 Interspire TrackPoint NX XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22377" source="OSVDB">22377</ref>
      <ref url="http://secunia.com/advisories/18445" source="SECUNIA">18445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="trackpoint_nx">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0211" published="2006-01-13" name="CVE-2006-0211" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0203" source="VUPEN">ADV-2006-0203</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421791/100/0/threaded" source="BUGTRAQ">20060112 Helm XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24139" source="XF">helm-forgotpassword-xss(24139)</ref>
      <ref url="http://www.webhostautomation.com/webhost-301" source="CONFIRM">http://www.webhostautomation.com/webhost-301</ref>
      <ref url="http://www.securityfocus.com/bid/16234" source="BID">16234</ref>
      <ref url="http://www.osvdb.org/22454" source="OSVDB">22454</ref>
      <ref url="http://secunia.com/advisories/18492" source="SECUNIA">18492</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helm_hosting" name="helm_hosting_control_panel">
        <vers num="3.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0212" published="2006-01-13" name="CVE-2006-0212" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0184" source="VUPEN">ADV-2006-0184</ref>
      <ref url="http://www.securityfocus.com/bid/16236" source="BID">16236</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt" source="MISC" adv="1">http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/18437" source="SECUNIA" adv="1">18437</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2" source="FULLDISC" adv="1">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421993/100/0/threaded" source="BUGTRAQ">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
      <ref url="http://www.osvdb.org/22380" source="OSVDB">22380</ref>
      <ref url="http://securitytracker.com/id?1015486" source="SECTRACK">1015486</ref>
      <ref url="http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2" source="MISC">http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toshiba" name="bluetooth_stack">
        <vers num="3.00.11" />
        <vers num="3.00.12" />
        <vers num="3.00.31a" />
        <vers num="3.00.32" />
        <vers num="3.01.03" />
        <vers num="3.10.00" />
        <vers num="3.20.00" />
        <vers num="3.20.01" />
        <vers num="3.20.02" />
        <vers num="3.20.04" />
        <vers num="4.00.01t" />
        <vers num="4.00.11" />
        <vers prev="1" num="4.00.23t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0213" published="2006-01-13" name="CVE-2006-0213" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18438" source="SECUNIA" patch="1" adv="1">18438</ref>
      <ref url="http://kolab.org/security/kolab-vendor-notice-08.txt" source="CONFIRM" patch="1" adv="1">http://kolab.org/security/kolab-vendor-notice-08.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0186" source="VUPEN">ADV-2006-0186</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24123" source="XF">kolab-smtp-logging(24123)</ref>
      <ref url="http://www.osvdb.org/22381" source="OSVDB">22381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kolab" name="kolab_groupware_server">
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2005-12-15_pre2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0214" published="2006-01-15" name="CVE-2006-0214" modified="2008-09-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24136" source="XF">ezdatabase-visitorupload-file-include(24136)</ref>
      <ref url="http://www.securityfocus.com/bid/16237" source="BID">16237</ref>
      <ref url="http://securityreason.com/securityalert/351" source="SREASON">351</ref>
      <ref url="http://secunia.com/advisories/18043" source="SECUNIA">18043</ref>
      <ref url="http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html" source="MISC">http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indexcor" name="ezdatabase">
        <vers num="2.0" />
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0215" published="2006-01-16" name="CVE-2006-0215" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.  NOTE: this issue might be resultant from CVE-2006-0216.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22352" source="OSVDB">22352</ref>
      <ref url="http://osvdb.org/ref/22/22352-qualityppc.txt" source="MISC" adv="1">http://osvdb.org/ref/22/22352-qualityppc.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualityebiz" name="quality_ppc">
        <vers num="1.0_build_1644" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0216" published="2006-01-16" name="CVE-2006-0216" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to obtain sensitive information, possibly the installation path of the application, via unspecified "meta characters" to the cpage parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22353" source="OSVDB">22353</ref>
      <ref url="http://osvdb.org/ref/22/22353-qualityppc.txt" source="MISC">http://osvdb.org/ref/22/22353-qualityppc.txt</ref>
      <ref url="http://osvdb.org/ref/22/22352-qualityppc.txt" source="MISC">http://osvdb.org/ref/22/22352-qualityppc.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualityebiz" name="quality_ppc">
        <vers num="1.0_build_1644" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0217" published="2006-01-16" name="CVE-2006-0217" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0187" source="VUPEN">ADV-2006-0187</ref>
      <ref url="http://www.securityfocus.com/bid/16239" source="BID">16239</ref>
      <ref url="http://www.osvdb.org/22444" source="OSVDB">22444</ref>
      <ref url="http://www.osvdb.org/22443" source="OSVDB">22443</ref>
      <ref url="http://secunia.com/advisories/18477" source="SECUNIA" adv="1">18477</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0517.html" source="FULLDISC">20060115 Ultimate Auction &lt;=3.67</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24138" source="XF">ultimate-auction-item-xss(24138)</ref>
      <ref url="http://www.securityfocus.com/bid/16254" source="BID">16254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_auction" name="ultimate_auction">
        <vers num="3.67" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0218" published="2006-01-16" name="CVE-2006-0218" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection.  NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603.  However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://community.mybboard.net/showthread.php?tid=5852" source="CONFIRM" patch="1" adv="1">http://community.mybboard.net/showthread.php?tid=5852</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0219" published="2006-01-16" name="CVE-2006-0219" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://community.mybboard.net/showthread.php?tid=5960" source="CONFIRM" patch="1">http://community.mybboard.net/showthread.php?tid=5960</ref>
      <ref url="http://www.securityfocus.com/bid/16230" source="BID">16230</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151" source="MISC">http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088" source="MISC">http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24115" source="XF">mybb-usercp-script-sql-injection(24115)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2" />
        <vers num="1.01" />
        <vers num="1.0_final" />
        <vers num="1.0_preview_release_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0220" published="2006-01-16" name="CVE-2006-0220" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16232" source="BID">16232</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421914/100/0/threaded" source="BUGTRAQ">20060113 DCP Portal Cross-Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24153" source="XF">dcpportal-calendar-search-xss(24153)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codeworx_technologies" name="dcp-portal">
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0221" published="2006-01-16" name="CVE-2006-0221" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24266" source="XF">cm3-login-sql-injection(24266)</ref>
      <ref url="http://www.securityfocus.com/bid/16231" source="BID">16231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421941/100/0/threaded" source="BUGTRAQ">20060113 DDSN CMS Admin Panel SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22696" source="OSVDB">22696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ddsn" name="cm3cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0222" published="2006-01-16" name="CVE-2006-0222" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24235" source="XF">template-seller-fullview-xss(24235)</ref>
      <ref url="http://www.securityfocus.com/bid/16233" source="BID">16233</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421916/100/0/threaded" source="BUGTRAQ">20060113 AlstraSoft Template Seller Pro Cross-Site Scripting Vulnerability</ref>
      <ref url="http://www.osvdb.org/22746" source="OSVDB">22746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="template_seller">
        <vers num="" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0223" published="2006-01-16" name="CVE-2006-0223" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16235" source="BID" patch="1">16235</ref>
      <ref url="http://www.123flashchat.com/flash-chat-server-v512.html" source="MISC" patch="1">http://www.123flashchat.com/flash-chat-server-v512.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24137" source="XF">123flashchat-user-directory-traversal(24137)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0198" source="VUPEN" adv="1">ADV-2006-0198</ref>
      <ref url="http://www.osvdb.org/22440" source="OSVDB">22440</ref>
      <ref url="http://secunia.com/advisories/18455" source="SECUNIA" adv="1">18455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="topcmm_computing" name="123_flash_chat_server">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0224" published="2006-01-24" name="CVE-2006-0224" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423207/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060123 [ Rosiello Security ] Eterm-LibAST Advisory</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423088/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060125 Rosiello Security - Eterm-LibAST Advisory</ref>
      <ref url="http://www.rosiello.org/en/read_bugs.php?id=25" source="MISC" patch="1" adv="1">http://www.rosiello.org/en/read_bugs.php?id=25</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0314" source="VUPEN">ADV-2006-0314</ref>
      <ref url="http://www.securityfocus.com/bid/16350" source="BID">16350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423366/100/0/threaded" source="BUGTRAQ">20060123 LibAST 0.7 Release Fixes Security Vulnerability</ref>
      <ref url="http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840" source="CONFIRM">http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24303" source="XF">eterm-libast-filename-bo(24303)</ref>
      <ref url="http://www.osvdb.org/22735" source="OSVDB">22735</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:029" source="MANDRIVA">MDKSA-2006:029</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml" source="GENTOO">GLSA-200601-14</ref>
      <ref url="http://www.debian.org/security/2006/dsa-976" source="DEBIAN">DSA-976</ref>
      <ref url="http://securityreason.com/securityalert/373" source="SREASON">373</ref>
      <ref url="http://secunia.com/advisories/18916" source="SECUNIA">18916</ref>
      <ref url="http://secunia.com/advisories/18632" source="SECUNIA">18632</ref>
      <ref url="http://secunia.com/advisories/18586" source="SECUNIA">18586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libast" name="libast">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0225" published="2006-01-25" name="CVE-2006-0225" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://secunia.com/advisories/18595" source="SECUNIA" patch="1" adv="1">18595</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24305" source="XF">openssh-scp-command-execution(24305)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2120" source="VUPEN">ADV-2007-2120</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4869" source="VUPEN">ADV-2006-4869</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2490" source="VUPEN">ADV-2006-2490</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0306" source="VUPEN">ADV-2006-0306</ref>
      <ref url="http://www.ubuntu.com/usn/usn-255-1" source="UBUNTU">USN-255-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16369" source="BID">16369</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425397/100/0/threaded" source="FEDORA">FLSA-2006:168935</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0044.html" source="REDHAT">RHSA-2006:0044</ref>
      <ref url="http://www.osvdb.org/22692" source="OSVDB">22692</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.003-openssh.html" source="OPENPKG">OpenPKG-SA-2006.003</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_openssh.html" source="SUSE">SUSE-SA:2006:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-11.xml" source="GENTOO">GLSA-200602-11</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.425802" source="SLACKWARE">SSA:2006-045-06</ref>
      <ref url="http://securitytracker.com/id?1015540" source="SECTRACK">1015540</ref>
      <ref url="http://secunia.com/advisories/19159" source="SECUNIA">19159</ref>
      <ref url="http://secunia.com/advisories/18970" source="SECUNIA">18970</ref>
      <ref url="http://secunia.com/advisories/18969" source="SECUNIA">18969</ref>
      <ref url="http://secunia.com/advisories/18964" source="SECUNIA">18964</ref>
      <ref url="http://secunia.com/advisories/18910" source="SECUNIA">18910</ref>
      <ref url="http://secunia.com/advisories/18850" source="SECUNIA">18850</ref>
      <ref url="http://secunia.com/advisories/18798" source="SECUNIA">18798</ref>
      <ref url="http://secunia.com/advisories/18736" source="SECUNIA">18736</ref>
      <ref url="http://secunia.com/advisories/18650" source="SECUNIA">18650</ref>
      <ref url="http://secunia.com/advisories/18579" source="SECUNIA">18579</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9962" source="OVAL">oval:org.mitre.oval:def:9962</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112" source="HP">HPSBUX02178</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/005_ssh.patch" source="OPENBSD">20060212 [3.8] 005: SECURITY FIX: February 12, 2006</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0698.html" source="REDHAT">RHSA-2006:0698</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0298.html" source="REDHAT">RHSA-2006:0298</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:034" source="MANDRIVA">MDKSA-2006:034</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102961-1" source="SUNALERT">102961</ref>
      <ref url="http://securityreason.com/securityalert/462" source="SREASON">462</ref>
      <ref url="http://secunia.com/advisories/25936" source="SECUNIA">25936</ref>
      <ref url="http://secunia.com/advisories/25607" source="SECUNIA">25607</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/23680" source="SECUNIA">23680</ref>
      <ref url="http://secunia.com/advisories/23340" source="SECUNIA">23340</ref>
      <ref url="http://secunia.com/advisories/23241" source="SECUNIA">23241</ref>
      <ref url="http://secunia.com/advisories/22196" source="SECUNIA">22196</ref>
      <ref url="http://secunia.com/advisories/21724" source="SECUNIA">21724</ref>
      <ref url="http://secunia.com/advisories/21492" source="SECUNIA">21492</ref>
      <ref url="http://secunia.com/advisories/21262" source="SECUNIA">21262</ref>
      <ref url="http://secunia.com/advisories/21129" source="SECUNIA">21129</ref>
      <ref url="http://secunia.com/advisories/20723" source="SECUNIA">20723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112" source="HP">HPSBUX02178</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability" source="CONFIRM">http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" source="SGI">20060703-01-P</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1138" source="OVAL" sig="1">oval:org.mitre.oval:def:1138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1p1" />
        <vers num="3.0.2" />
        <vers num="3.0.2p1" />
        <vers num="3.0p1" />
        <vers num="3.1" />
        <vers num="3.1p1" />
        <vers num="3.2" />
        <vers num="3.2.2p1" />
        <vers num="3.2.3p1" />
        <vers num="3.3" />
        <vers num="3.3p1" />
        <vers num="3.4" />
        <vers num="3.4p1" />
        <vers num="3.5" />
        <vers num="3.5p1" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.1p1" />
        <vers num="3.6.1p2" />
        <vers num="3.7" />
        <vers num="3.7.1" />
        <vers num="3.7.1p2" />
        <vers num="3.8" />
        <vers num="3.8.1" />
        <vers num="3.8.1p1" />
        <vers num="3.9" />
        <vers num="3.9.1" />
        <vers num="3.9.1p1" />
        <vers num="4.0p1" />
        <vers num="4.1p1" />
        <vers num="4.2p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0226" published="2006-01-18" name="CVE-2006-0226" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16296" source="BID" patch="1">16296</ref>
      <ref url="http://secunia.com/advisories/18353" source="SECUNIA" patch="1" adv="1">18353</ref>
      <ref url="http://www.signedness.org/advisories/sps-0x1.txt" source="MISC" adv="1">http://www.signedness.org/advisories/sps-0x1.txt</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc" source="FREEBSD">FreeBSD-SA-06:05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24192" source="XF">bsd-ieee80211-bo(24192)</ref>
      <ref url="http://www.osvdb.org/22537" source="OSVDB">22537</ref>
      <ref url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson" source="MISC">http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson</ref>
      <ref url="http://securitytracker.com/id?1015518" source="SECTRACK">1015518</ref>
      <ref url="http://kernelwars.blogspot.com/2007/01/alive.html" source="MISC">http://kernelwars.blogspot.com/2007/01/alive.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.0" edition="release" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0227" published="2006-01-17" name="CVE-2006-0227" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1" source="SUNALERT" patch="1">102033</ref>
      <ref url="http://securitytracker.com/id?1015492" source="SECTRACK" patch="1">1015492</ref>
      <ref url="http://secunia.com/advisories/18498" source="SECUNIA" patch="1" adv="1">18498</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0200" source="VUPEN">ADV-2006-0200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24127" source="XF">solaris-lpsched-dos(24127)</ref>
      <ref url="http://www.securityfocus.com/bid/16245" source="BID">16245</ref>
      <ref url="http://www.osvdb.org/22442" source="OSVDB">22442</ref>
      <ref url="http://www.osvdb.org/22441" source="OSVDB">22441</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:662" source="OVAL" sig="1">oval:org.mitre.oval:def:662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="10.0" edition=":x86" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0228" published="2006-01-17" name="CVE-2006-0228" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16261" source="BID" patch="1">16261</ref>
      <ref url="http://secunia.com/advisories/18458" source="SECUNIA" patch="1" adv="1">18458</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0199" source="VUPEN">ADV-2006-0199</ref>
      <ref url="http://www.grsecurity.org/news.php#grsec218" source="CONFIRM">http://www.grsecurity.org/news.php#grsec218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24156" source="XF">grsecurity-rbac-admin-privileges(24156)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grsecurity" name="grsecurity_kernel_patch">
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0229" published="2006-01-17" name="CVE-2006-0229" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when Wehntrust creates the autostart key.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/422046/100/0/threaded" source="BUGTRAQ" patch="1">20060116 Re: [Full-disclosure] WehnTrust - When you have to trust Wehntrust</ref>
      <ref url="http://www.securityfocus.com/bid/16268" source="BID">16268</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422020/100/0/threaded" source="BUGTRAQ">20060116 WehnTrust - When you have to trust Wehntrust</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24315" source="XF">wehntrust-service-start-file-execution(24315)</ref>
      <ref url="http://www.wehnus.com/downloads.pl" source="MISC">http://www.wehnus.com/downloads.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wehnus" name="wehntrust">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0230" published="2006-04-24" name="CVE-2006-0230" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/118388" source="CERT-VN">VU#118388</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0010.html" source="VULNWATCH" patch="1" adv="1">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1464" source="VUPEN">ADV-2006-1464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25972" source="XF">sse-unauth-admin-access(25972)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.04.21.html</ref>
      <ref url="http://www.securityfocus.com/bid/17637" source="BID">17637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded" source="BUGTRAQ">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431724/100/0/threaded" source="BUGTRAQ">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref>
      <ref url="http://secunia.com/advisories/19734" source="SECUNIA">19734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="5.0.0.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0231" published="2006-04-24" name="CVE-2006-0231" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0011.html" source="VULNWATCH" patch="1" adv="1">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1464" source="VUPEN">ADV-2006-1464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25973" source="XF">sse-insecure-private-key(25973)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.04.21.html</ref>
      <ref url="http://www.securityfocus.com/bid/17637" source="BID">17637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded" source="BUGTRAQ">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431725/100/0/threaded" source="BUGTRAQ">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref>
      <ref url="http://securitytracker.com/id?1015974" source="SECTRACK">1015974</ref>
      <ref url="http://secunia.com/advisories/19734" source="SECUNIA">19734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="5.0.0.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0232" published="2006-04-24" name="CVE-2006-0232" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0012.html" source="VULNWATCH" patch="1" adv="1">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1464" source="VUPEN">ADV-2006-1464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25974" source="XF">sse-unauth-file-access(25974)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.04.21.html</ref>
      <ref url="http://www.securityfocus.com/bid/17637" source="BID">17637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded" source="BUGTRAQ">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431728/100/0/threaded" source="BUGTRAQ">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015974" source="SECTRACK">1015974</ref>
      <ref url="http://securityreason.com/securityalert/759" source="SREASON">759</ref>
      <ref url="http://securityreason.com/securityalert/758" source="SREASON">758</ref>
      <ref url="http://secunia.com/advisories/19734" source="SECUNIA">19734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="5.0.0.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0233" published="2006-01-17" name="CVE-2006-0233" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24140" source="XF">microblog-functions-xss(24140)</ref>
      <ref url="http://www.securityfocus.com/bid/16272" source="BID">16272</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422145/100/0/threaded" source="BUGTRAQ" adv="1">20060117 [eVuln] microBlog BBCode XSS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015496" source="SECTRACK">1015496</ref>
      <ref url="http://evuln.com/vulns/36/summary.html" source="MISC">http://evuln.com/vulns/36/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microblog" name="microblog">
        <vers num="2.0_rc10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0234" published="2006-01-17" name="CVE-2006-0234" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0239" source="VUPEN">ADV-2006-0239</ref>
      <ref url="http://www.securityfocus.com/bid/16270" source="BID">16270</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422141/100/0/threaded" source="BUGTRAQ" adv="1">20060117 [eVuln] microBlog SQL Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24132" source="XF">microblog-index-sql-injection(24132)</ref>
      <ref url="http://www.osvdb.org/22512" source="OSVDB">22512</ref>
      <ref url="http://securitytracker.com/id?1015496" source="SECTRACK">1015496</ref>
      <ref url="http://secunia.com/advisories/18442" source="SECUNIA">18442</ref>
      <ref url="http://evuln.com/vulns/35/summary.html" source="MISC">http://evuln.com/vulns/35/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microblog" name="microblog">
        <vers num="2.0_rc10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0235" published="2006-01-17" name="CVE-2006-0235" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0241" source="VUPEN">ADV-2006-0241</ref>
      <ref url="http://www.securityfocus.com/bid/16247" source="BID">16247</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422105/100/0/threaded" source="BUGTRAQ" adv="1">20060116 White Album Sql &amp;#304;njection biyosecurity.be</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24271" source="XF">whitealbum-pictures-sql-injection(24271)</ref>
      <ref url="http://www.osvdb.org/22520" source="OSVDB">22520</ref>
      <ref url="http://www.biyosecurity.be/bugs/whitealbum.txt" source="MISC">http://www.biyosecurity.be/bugs/whitealbum.txt</ref>
      <ref url="http://secunia.com/advisories/18460" source="SECUNIA">18460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="white_angle" name="white_album">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0236" published="2006-01-17" name="CVE-2006-0236" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16271" source="BID" patch="1">16271</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422148/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060117 Secunia Research: Mozilla Thunderbird Attachment SpoofingVulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2005-22/advisory" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-22/advisory</ref>
      <ref url="http://secunia.com/advisories/15907" source="SECUNIA" patch="1" adv="1">15907</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=300246" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=300246</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24164" source="XF">thunderbird-attachment-ext-spoofing(24164)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0230" source="VUPEN" adv="1">ADV-2006-0230</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:021" source="MANDRIVA">MDKSA-2006:021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0237" published="2006-01-17" name="CVE-2006-0237" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0214" source="VUPEN">ADV-2006-0214</ref>
      <ref url="http://www.securityfocus.com/bid/16255" source="BID">16255</ref>
      <ref url="http://secunia.com/advisories/18470" source="SECUNIA" adv="1">18470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24150" source="XF">gtpicommerce-index-xss(24150)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtp" name="icommerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0238" published="2006-01-17" name="CVE-2006-0238" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lesterchan.net/blogs/" source="CONFIRM" patch="1">http://www.lesterchan.net/blogs/</ref>
      <ref url="http://secunia.com/advisories/18471" source="SECUNIA" patch="1" adv="1">18471</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0192" source="VUPEN">ADV-2006-0192</ref>
      <ref url="http://www.securityfocus.com/bid/16241" source="BID">16241</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24163" source="XF">wpstats-script-sql-injection(24163)</ref>
      <ref url="http://www.osvdb.org/22450" source="OSVDB">22450</ref>
      <ref url="http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability" source="CONFIRM">http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability</ref>
      <ref url="http://osvdb.org/ref/22/22450-wpstats.txt" source="MISC">http://osvdb.org/ref/22/22450-wpstats.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamerz" name="wp-stats">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0239" published="2006-01-17" name="CVE-2006-0239" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0194" source="VUPEN">ADV-2006-0194</ref>
      <ref url="http://www.securityfocus.com/bid/16243" source="BID">16243</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422102/100/0/threaded" source="BUGTRAQ">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref>
      <ref url="http://secunia.com/advisories/18488" source="SECUNIA" adv="1">18488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24154" source="XF">simpleblog-comment-xss(24154)</ref>
      <ref url="http://www.osvdb.org/22448" source="OSVDB">22448</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=21926" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=21926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="8pixel.net" name="simple_blog">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0240" published="2006-01-17" name="CVE-2006-0240" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24155" source="XF">simpleblog-month-sql-injection(24155)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0194" source="VUPEN" adv="1">ADV-2006-0194</ref>
      <ref url="http://www.securityfocus.com/bid/16243" source="BID">16243</ref>
      <ref url="http://www.securityfocus.com/archive/1/422102/100/0/threaded" source="BUGTRAQ" adv="1">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref>
      <ref url="http://www.osvdb.org/22447" source="OSVDB">22447</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=21926" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=21926</ref>
      <ref url="http://secunia.com/advisories/18488" source="SECUNIA" adv="1">18488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="8pixel.net" name="simple_blog">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0241" published="2006-01-17" name="CVE-2006-0241" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0237" source="VUPEN">ADV-2006-0237</ref>
      <ref url="http://www.securityfocus.com/bid/16277" source="BID">16277</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422133/100/0/threaded" source="BUGTRAQ">20060117 XSS in WBNews &lt; = v1.1.0</ref>
      <ref url="http://secunia.com/advisories/18499" source="SECUNIA">18499</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmobo" name="wbnews">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0242" published="2006-01-17" name="CVE-2006-0242" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422124/100/0/threaded" source="BUGTRAQ" patch="1">20060117 IndonesiaHack Advisory HTML injection in PHP Fusebox</ref>
      <ref url="http://www.securityfocus.com/bid/16274" source="BID">16274</ref>
      <ref url="http://securityreason.com/securityalert/355" source="SREASON">355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusebox" name="php_fusebox">
        <vers num="4.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0243" published="2006-01-17" name="CVE-2006-0243" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0229" source="VUPEN">ADV-2006-0229</ref>
      <ref url="http://www.securityfocus.com/bid/16281" source="BID">16281</ref>
      <ref url="http://secunia.com/advisories/18454" source="SECUNIA" adv="1">18454</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24187" source="XF">smbcms-sitesearch-xss(24187)</ref>
      <ref url="http://www.osvdb.org/22494" source="OSVDB">22494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smbcms" name="smbcms">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0244" published="2006-01-17" name="CVE-2006-0244" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0232" source="VUPEN">ADV-2006-0232</ref>
      <ref url="http://www.securityfocus.com/bid/16263" source="BID">16263</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422158/100/0/threaded" source="BUGTRAQ">20060116 Re: Directory traversal in phpXplorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421997/100/0/threaded" source="BUGTRAQ" adv="1">20060116 Directory traversal in phpXplorer</ref>
      <ref url="http://www.arrelnet.com/advisories/adv20060116.html" source="MISC" adv="1">http://www.arrelnet.com/advisories/adv20060116.html</ref>
      <ref url="http://secunia.com/advisories/18518" source="SECUNIA" adv="1">18518</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39982" source="XF">phpxplorer-sshare-directory-traversal(39982)</ref>
      <ref url="http://securityreason.com/securityalert/353" source="SREASON">353</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpxplorer" name="phpxplorer">
        <vers num="0.9.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0245" published="2006-01-17" name="CVE-2006-0245" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php.  NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0227" source="VUPEN">ADV-2006-0227</ref>
      <ref url="http://www.securityfocus.com/bid/16259" source="BID">16259</ref>
      <ref url="http://www.osvdb.org/22471" source="OSVDB">22471</ref>
      <ref url="http://secunia.com/advisories/18519" source="SECUNIA" adv="1">18519</ref>
      <ref url="http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html" source="MISC" adv="1">http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html</ref>
      <ref url="http://bugs.cubecart.com/?do=details&amp;id=459" source="MISC" adv="1">http://bugs.cubecart.com/?do=details&amp;id=459</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24177" source="XF">cubecart-index-script-xss(24177)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="3.0.7-pl1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0246" published="2006-01-17" name="CVE-2006-0246" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0213" source="VUPEN">ADV-2006-0213</ref>
      <ref url="http://www.securityfocus.com/bid/16265" source="BID">16265</ref>
      <ref url="http://www.osvdb.org/22462" source="OSVDB">22462</ref>
      <ref url="http://secunia.com/advisories/18472" source="SECUNIA" adv="1">18472</ref>
      <ref url="http://osvdb.org/ref/22/22462-widexl.txt" source="MISC">http://osvdb.org/ref/22/22462-widexl.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24161" source="XF">downloadtracker-down-xss(24161)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="widexl" name="download_tracker">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0247" published="2006-01-17" name="CVE-2006-0247" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0188" source="VUPEN">ADV-2006-0188</ref>
      <ref url="http://www.securityfocus.com/bid/16264" source="BID">16264</ref>
      <ref url="http://www.osvdb.org/22461" source="OSVDB">22461</ref>
      <ref url="http://secunia.com/advisories/18469" source="SECUNIA" adv="1">18469</ref>
      <ref url="http://osvdb.org/ref/22/22461-anyboard.txt" source="MISC">http://osvdb.org/ref/22/22461-anyboard.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24167" source="XF">netbula-anyboard-script-xss(24167)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbula" name="anyboard">
        <vers prev="1" num="9.9.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0248" published="2006-01-17" name="CVE-2006-0248" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0218" source="VUPEN">ADV-2006-0218</ref>
      <ref url="http://secunia.com/advisories/18483" source="SECUNIA" adv="1">18483</ref>
      <ref url="http://blog.globalnetworks.gr/?p=4" source="MISC">http://blog.globalnetworks.gr/?p=4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24304" source="XF">virata-emweb-unauth-access(24304)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intracom" name="jetspeed">
        <vers num="500" />
        <vers num="520" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0249" published="2006-01-17" name="CVE-2006-0249" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24146" source="XF">geoBlog-viewcat-sql-injection(24146)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0191" source="VUPEN" adv="1">ADV-2006-0191</ref>
      <ref url="http://www.securityfocus.com/bid/16249" source="BID">16249</ref>
      <ref url="http://www.osvdb.org/22463" source="OSVDB">22463</ref>
      <ref url="http://securitytracker.com/id?1015493" source="SECTRACK">1015493</ref>
      <ref url="http://secunia.com/advisories/18504" source="SECUNIA" adv="1">18504</ref>
      <ref url="http://evuln.com/vulns/33/summary.html" source="MISC">http://evuln.com/vulns/33/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitdamaged" name="geoblog">
        <vers num="mod_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0250" published="2006-01-17" name="CVE-2006-0250" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0234" source="VUPEN">ADV-2006-0234</ref>
      <ref url="http://www.securityfocus.com/bid/16267" source="BID">16267</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422086/100/0/threaded" source="BUGTRAQ">20060116 Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad Format String Vulnerability</ref>
      <ref url="http://www.digitalarmaments.com/2006040164883273.html" source="MISC">http://www.digitalarmaments.com/2006040164883273.html</ref>
      <ref url="http://secunia.com/advisories/18525" source="SECUNIA" adv="1">18525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24178" source="XF">cmusnmp-snmpinput-format-string(24178)</ref>
      <ref url="http://www.osvdb.org/22493" source="OSVDB">22493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="snmptrapd">
        <vers num="3.6" />
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0251" published="2006-01-17" name="CVE-2006-0251" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0189" source="VUPEN">ADV-2006-0189</ref>
      <ref url="http://www.securityfocus.com/bid/16251" source="BID">16251</ref>
      <ref url="http://www.osvdb.org/22439" source="OSVDB">22439</ref>
      <ref url="http://secunia.com/advisories/18468" source="SECUNIA" adv="1">18468</ref>
      <ref url="http://osvdb.org/ref/22/22439-faqomatic.txt" source="MISC">http://osvdb.org/ref/22/22439-faqomatic.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24165" source="XF">faqomatic-fom-xss(24165)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faq-o-matic" name="faq-o-matic">
        <vers prev="1" num="2.711" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0252" published="2006-01-17" name="CVE-2006-0252" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0190" source="VUPEN">ADV-2006-0190</ref>
      <ref url="http://www.securityfocus.com/bid/16242" source="BID" adv="1">16242</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422052/100/0/threaded" source="BUGTRAQ" adv="1">20060115 [eVuln] Benders Calendar SQL Injection</ref>
      <ref url="http://www.osvdb.org/22449" source="OSVDB">22449</ref>
      <ref url="http://securitytracker.com/id?1015491" source="SECTRACK" adv="1">1015491</ref>
      <ref url="http://secunia.com/advisories/18462" source="SECUNIA" adv="1">18462</ref>
      <ref url="http://evuln.com/vulns/30/summary.html" source="MISC" adv="1">http://evuln.com/vulns/30/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24120" source="XF">benderscalendar-sql-injection(24120)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="benders_calendar" name="benders_calendar">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0253" published="2006-01-17" name="CVE-2006-0253" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the Bluetooth OBEX Object Push service in "Blue Neighbors.EXE" in AmbiCom Blue Neighbors 2.50 Build 2500 and earlier allows remote attackers to execute arbitrary code via a long file name, as demonstrated via a long RFILE argument to ussp-push.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0219" source="VUPEN">ADV-2006-0219</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422481/100/0/threaded" source="BUGTRAQ">20060120 DMA[2006-0115a] - 'AmbiCom Bluetooth Object Push Overflow'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/18466" source="SECUNIA" adv="1">18466</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24179" source="XF">ambicom-bluetooth-objectpush-bo(24179)</ref>
      <ref url="http://www.securityfocus.com/bid/16258" source="BID">16258</ref>
      <ref url="http://securityreason.com/securityalert/366" source="SREASON">366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ambicom" name="blue_neighbors">
        <vers num="2.50_build_2500" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0254" published="2006-01-17" name="CVE-2006-0254" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create" source="CONFIRM">https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0217" source="VUPEN">ADV-2006-0217</ref>
      <ref url="http://www.securityfocus.com/bid/16260" source="BID">16260</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421996/100/0/threaded" source="BUGTRAQ" adv="1">20060115 Apache Geronimo 1.0 - CSS and persistent HTML-Injectionvulnerabilities</ref>
      <ref url="http://www.oliverkarow.de/research/geronimo_css.txt" source="MISC" adv="1">http://www.oliverkarow.de/research/geronimo_css.txt</ref>
      <ref url="http://secunia.com/advisories/18485" source="SECUNIA" adv="1">18485</ref>
      <ref url="http://issues.apache.org/jira/browse/GERONIMO-1474" source="MISC" adv="1">http://issues.apache.org/jira/browse/GERONIMO-1474</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24159" source="XF">geronimo-webaccesslog-viewer-xss(24159)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24158" source="XF">geronimo-jspexamples-xss(24158)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA">31493</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="geronimo">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0255" published="2006-01-17" name="CVE-2006-0255" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0258" source="VUPEN">ADV-2006-0258</ref>
      <ref url="http://www.securityfocus.com/bid/16290" source="BID">16290</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422263/100/0/threaded" source="BUGTRAQ">20060117 [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()</ref>
      <ref url="http://secdev.zoller.lu/research/checkpoint.txt" source="MISC">http://secdev.zoller.lu/research/checkpoint.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="" edition=":fp1" />
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
        <vers num="4.1" edition="sp5" />
        <vers num="4.1" edition="sp5a" />
        <vers num="4.1" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0256" published="2006-01-18" name="CVE-2006-0256" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.3" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0257" published="2006-01-18" name="CVE-2006-0257" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1" adv="1">1015499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22540" source="OSVDB">22540</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.1" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0258" published="2006-01-18" name="CVE-2006-0258" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0259" published="2006-01-18" name="CVE-2006-0259" modified="2011-09-02" discovered="2006-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" patch="1">VU#545804</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID" patch="1">16287</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" patch="1" adv="1">18493</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.osvdb.org/22544" source="OSVDB">22544</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0260" published="2006-01-18" name="CVE-2006-0260" modified="2011-09-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMS_METADATA_UTIL package; (g) MAKE_FILTER, FETCH_VIEWS_ERROR, FETCH_FILTERS, FETCH_VIEWS, SET_FILTER_COMMON, DO_FILTER_SCRIPT, SET_TABLE_FILTERS, and MAKE_FILTER_TEXT functions in the DBMS_METADATA_INT package; and (h) GET_PREPOST_TABLE_ACT function in the DBMS_METADATA package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22643" source="OSVDB">22643</ref>
      <ref url="http://www.osvdb.org/22637" source="OSVDB">22637</ref>
      <ref url="http://www.osvdb.org/22543" source="OSVDB">22543</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0261" published="2006-01-18" name="CVE-2006-0261" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component.  NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24168" source="XF">oracle-masterkey-plaintext(24168)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422255/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html" source="MISC">http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0262" published="2006-01-18" name="CVE-2006-0262" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.4" />
        <vers num="personal_10.1.0.4" />
        <vers num="standard_10.1.0.4" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7.4" />
        <vers num="standard_8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.0.1.5_fips" />
        <vers num="standard_9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0263" published="2006-01-18" name="CVE-2006-0263" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/870172" source="CERT-VN">VU#870172</ref>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22551" source="OSVDB">22551</ref>
      <ref url="http://www.osvdb.org/22550" source="OSVDB">22550</ref>
      <ref url="http://www.osvdb.org/22547" source="OSVDB">22547</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.1" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0264" reject="1" published="2006-01-18" name="CVE-2006-0264" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0259.  Reason: This candidate is subsumed by CVE-2006-0259.  An error during initial CVE analysis used the wrong set of affected versions for "DB10". Notes: All CVE users should reference CVE-2006-0259 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2006-0265" published="2006-01-18" name="CVE-2006-0265" modified="2011-09-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22642" source="OSVDB">22642</ref>
      <ref url="http://www.osvdb.org/22641" source="OSVDB">22641</ref>
      <ref url="http://www.osvdb.org/22640" source="OSVDB">22640</ref>
      <ref url="http://www.osvdb.org/22639" source="OSVDB">22639</ref>
      <ref url="http://www.osvdb.org/22555" source="OSVDB">22555</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.1" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0266" published="2006-01-18" name="CVE-2006-0266" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0267" published="2006-01-18" name="CVE-2006-0267" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.2.0.6 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB20.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0268" published="2006-01-18" name="CVE-2006-0268" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
        <vers num="9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0269" published="2006-01-18" name="CVE-2006-0269" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22563" source="OSVDB">22563</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle10g">
        <vers num="standard_10.1.0.5" />
        <vers num="standard_10.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0270" published="2006-01-18" name="CVE-2006-0270" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27.  NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24186" source="XF">oracle-sga-masterkey-plaintext(24186)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422262/30/7400/threaded" source="BUGTRAQ">20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html" source="MISC">http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0271" published="2006-01-18" name="CVE-2006-0271" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Upgrade &amp; Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22566" source="OSVDB">22566</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.4" />
        <vers num="personal_10.1.0.4" />
        <vers num="standard_10.1.0.4" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7.4" />
        <vers num="standard_8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1.5" />
        <vers num="standard_9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0272" published="2006-01-18" name="CVE-2006-0272" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29.  NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/891644" source="CERT-VN">VU#891644</ref>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24376" source="XF">oracle-xdbdbmx-xmlschema-bo(24376)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://www.argeniss.com/research/ARGENISS-ADV-010601.txt" source="MISC">http://www.argeniss.com/research/ARGENISS-ADV-010601.txt</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html" source="FULLDISC">20060126 [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT}</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.4" />
        <vers num="personal_10.1.0.4" />
        <vers num="standard_10.1.0.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="standard_9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0273" published="2006-01-18" name="CVE-2006-0273" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0" />
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0274" published="2006-01-18" name="CVE-2006-0274" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0275" published="2006-01-18" name="CVE-2006-0275" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04.  NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422261/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Read parts of files via customize(fixed after 875 days)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html" source="MISC">http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0276" published="2006-01-18" name="CVE-2006-0276" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless &amp; Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0277" published="2006-01-18" name="CVE-2006-0277" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0278" published="2006-01-18" name="CVE-2006-0278" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0279" published="2006-01-18" name="CVE-2006-0279" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0280" published="2006-01-18" name="CVE-2006-0280" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_enterprise_portal">
        <vers num="8.4" edition="bundle15" />
        <vers num="8.8" edition="bundle10" />
        <vers num="8.9" edition="bundle2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0281" published="2006-01-18" name="CVE-2006-0281" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.95.f1" />
        <vers num="sp23_l1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0282" published="2006-01-18" name="CVE-2006-0282" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2" edition="r1" />
        <vers num="10.1.2.0.2" edition="r2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0283" published="2006-01-18" name="CVE-2006-0283" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects &amp; Convert Tablespace component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0284" published="2006-01-18" name="CVE-2006-0284" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" edition="r2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0285" published="2006-01-18" name="CVE-2006-0285" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2" />
        <vers num="10.1.2.0.2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0286" published="2006-01-18" name="CVE-2006-0286" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2" />
        <vers num="10.1.2.0.2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.0.1.5" edition="" />
        <vers num="9.0.1.5" edition=":fips" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0287" published="2006-01-18" name="CVE-2006-0287" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0288" published="2006-01-18" name="CVE-2006-0288" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0289" published="2006-01-18" name="CVE-2006-0289" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005-2378 and REP06 is the same as CVE-2005-2371, both of which involve directory traversal.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422257/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html" source="MISC">http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html" source="MISC">http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="6.0.8.26_ps17" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0290" published="2006-01-18" name="CVE-2006-0290" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.1" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="9.2.0.7" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0291" published="2006-01-18" name="CVE-2006-0291" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.1.0" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0292" published="2006-02-02" name="CVE-2006-0292" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=316885" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=316885</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0200.html" source="REDHAT" adv="1">RHSA-2006:0200</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0199.html" source="REDHAT" adv="1">RHSA-2006:0199</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10016" source="OVAL">oval:org.mitre.oval:def:10016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24430" source="XF">mozilla-javascript-memory-corruption(24430)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded" source="FEDORA">FLSA-2006:180036-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded" source="FEDORA">FLSA:180036-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html" source="FEDORA">FEDORA-2006-076</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html" source="FEDORA">FEDORA-2006-075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037" source="MANDRIVA">MDKSA-2006:037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036" source="MANDRIVA">MDKSA-2006:036</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19230" source="SECUNIA">19230</ref>
      <ref url="http://secunia.com/advisories/18709" source="SECUNIA">18709</ref>
      <ref url="http://secunia.com/advisories/18708" source="SECUNIA">18708</ref>
      <ref url="http://secunia.com/advisories/18706" source="SECUNIA">18706</ref>
      <ref url="http://secunia.com/advisories/18705" source="SECUNIA">18705</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18703" source="SECUNIA">18703</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U" source="SGI">20060201-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:670" source="OVAL" sig="1">oval:org.mitre.oval:def:670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0293" published="2006-02-02" name="CVE-2006-0293" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=322045" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=322045</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42654" source="XF">firefox-function-allocation-code-execution(42654)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24430" source="XF">mozilla-javascript-memory-corruption(24430)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-01.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1494" source="OVAL" sig="1">oval:org.mitre.oval:def:1494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0294" published="2006-02-02" name="CVE-2006-0294" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=317934" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=317934</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24431" source="XF">mozilla-element-change-memory-corruption(24431)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-02.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-02.html</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1514" source="OVAL" sig="1">oval:org.mitre.oval:def:1514</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0295" published="2006-02-02" name="CVE-2006-0295" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-038A.html" source="CERT">TA06-038A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/759273" source="CERT-VN">VU#759273</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=319296" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=319296</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24433" source="XF">mozilla-queryinterface-memory-corruption(24433)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-04.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-04.html</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1562" source="OVAL" sig="1">oval:org.mitre.oval:def:1562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0296" published="2006-02-02" name="CVE-2006-0296" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-038A.html" source="CERT">TA06-038A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/592425" source="CERT-VN">VU#592425</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=319847" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=319847</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0200.html" source="REDHAT" adv="1">RHSA-2006:0200</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0199.html" source="REDHAT" adv="1">RHSA-2006:0199</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11803" source="OVAL">oval:org.mitre.oval:def:11803</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24434" source="XF">mozilla-xuldocument-command-execution(24434)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded" source="FEDORA">FLSA-2006:180036-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded" source="FEDORA">FLSA:180036-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html" source="FEDORA">FEDORA-2006-076</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html" source="FEDORA">FEDORA-2006-075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-05.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037" source="MANDRIVA">MDKSA-2006:037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036" source="MANDRIVA">MDKSA-2006:036</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19230" source="SECUNIA">19230</ref>
      <ref url="http://secunia.com/advisories/18709" source="SECUNIA">18709</ref>
      <ref url="http://secunia.com/advisories/18708" source="SECUNIA">18708</ref>
      <ref url="http://secunia.com/advisories/18706" source="SECUNIA">18706</ref>
      <ref url="http://secunia.com/advisories/18705" source="SECUNIA">18705</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18703" source="SECUNIA">18703</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U" source="SGI">20060201-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1493" source="OVAL" sig="1">oval:org.mitre.oval:def:1493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0297" published="2006-02-02" name="CVE-2006-0297" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=322215" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=322215</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=319872" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=319872</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24435" source="XF">mozilla-component-integer-overflow(24435)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-06.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-06.html</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1339" source="OVAL" sig="1">oval:org.mitre.oval:def:1339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0298" published="2006-02-02" name="CVE-2006-0298" modified="2011-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24436" source="XF" patch="1">mozilla-xml-parser-dos(24436)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID" patch="1">16476</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK" patch="1">1015570</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA" patch="1" adv="1">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA" patch="1" adv="1">18700</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN" adv="1">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN" adv="1">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-07.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-07.html</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA" adv="1">22065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:677" source="OVAL" sig="1">oval:org.mitre.oval:def:677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0299" published="2006-02-02" name="CVE-2006-0299" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=322312" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=322312</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24437" source="XF">mozilla-e4x-security-bypass(24437)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-08.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-08.html</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1625" source="OVAL" sig="1">oval:org.mitre.oval:def:1625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0300" published="2006-02-23" name="CVE-2006-0300" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:046" source="MANDRIVA" patch="1" adv="1">MDKSA-2006:046</ref>
      <ref url="http://www.osvdb.org/23371" source="OSVDB" patch="1">23371</ref>
      <ref url="http://secunia.com/advisories/18999" source="SECUNIA" patch="1" adv="1">18999</ref>
      <ref url="http://secunia.com/advisories/18976" source="SECUNIA" patch="1" adv="1">18976</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24855" source="XF">gnu-tar-pax-headers-bo(24855)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2518" source="VUPEN">ADV-2008-2518</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0684" source="VUPEN">ADV-2006-0684</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-257-1" source="UBUNTU" adv="1">USN-257-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0010" source="TRUSTIX" adv="1">2006-0010</ref>
      <ref url="http://www.securityfocus.com/bid/16764" source="BID">16764</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430299/100/0/threaded" source="FEDORA">FLSA:183571-2</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0232.html" source="REDHAT">RHSA-2006:0232</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.006-tar.html" source="OPENPKG">OpenPKG-SA-2006.006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-06.xml" source="GENTOO">GLSA-200603-06</ref>
      <ref url="http://www.debian.org/security/2006/dsa-987" source="DEBIAN">DSA-987</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-241646-1" source="SUNALERT">241646</ref>
      <ref url="http://securitytracker.com/id?1015705" source="SECTRACK">1015705</ref>
      <ref url="http://secunia.com/advisories/19236" source="SECUNIA">19236</ref>
      <ref url="http://secunia.com/advisories/19152" source="SECUNIA">19152</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="http://secunia.com/advisories/19093" source="SECUNIA">19093</ref>
      <ref url="http://secunia.com/advisories/19016" source="SECUNIA">19016</ref>
      <ref url="http://secunia.com/advisories/18973" source="SECUNIA" adv="1">18973</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9295" source="OVAL">oval:org.mitre.oval:def:9295</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6094" source="OVAL">oval:org.mitre.oval:def:6094</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5993" source="OVAL">oval:org.mitre.oval:def:5993</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5978" source="OVAL">oval:org.mitre.oval:def:5978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5252" source="OVAL">oval:org.mitre.oval:def:5252</ref>
      <ref url="http://lists.gnu.org/archive/html/bug-tar/2006-02/msg00051.html" source="MLIST">[Bug-tar] 20060220 tar 1.15.90 released</ref>
      <ref url="http://securityreason.com/securityalert/543" source="SREASON">543</ref>
      <ref url="http://securityreason.com/securityalert/480" source="SREASON">480</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/20042" source="SECUNIA">20042</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="tar">
        <vers num="1.14" />
        <vers num="1.14.1" />
        <vers num="1.15" />
        <vers num="1.15.1" />
        <vers num="1.15.90" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0301" published="2006-01-30" name="CVE-2006-0301" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24391" source="XF" patch="1">xpdf-splash-bo(24391)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-249-1" source="UBUNTU" patch="1">USN-249-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427990/100/0/threaded" source="FEDORA" patch="1" adv="1">FLSA:175404</ref>
      <ref url="http://www.securityfocus.com/archive/1/423899/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060202 [KDE Security Advisory] kpdf/xpdf heap based buffer overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0201.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0201</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00039.html" source="FEDORA" patch="1" adv="1">FEDORA-2006-103</ref>
      <ref url="http://www.kde.org/info/security/advisory-20060202-1.txt" source="MISC" patch="1" adv="1">http://www.kde.org/info/security/advisory-20060202-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-12</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-05</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-04</ref>
      <ref url="http://www.debian.org/security/2006/dsa-974" source="DEBIAN" patch="1" adv="1">DSA-974</ref>
      <ref url="http://www.debian.org/security/2006/dsa-972" source="DEBIAN" patch="1" adv="1">DSA-972</ref>
      <ref url="http://www.debian.org/security/2006/dsa-971" source="DEBIAN" patch="1" adv="1">DSA-971</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.474747" source="SLACKWARE" patch="1">SSA:2006-045-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.472683" source="SLACKWARE" patch="1">SSA:2006-045-09</ref>
      <ref url="http://securitytracker.com/id?1015576" source="SECTRACK" patch="1">1015576</ref>
      <ref url="http://secunia.com/advisories/19377" source="SECUNIA" patch="1" adv="1">19377</ref>
      <ref url="http://secunia.com/advisories/18983" source="SECUNIA" patch="1" adv="1">18983</ref>
      <ref url="http://secunia.com/advisories/18913" source="SECUNIA" patch="1" adv="1">18913</ref>
      <ref url="http://secunia.com/advisories/18908" source="SECUNIA" patch="1" adv="1">18908</ref>
      <ref url="http://secunia.com/advisories/18882" source="SECUNIA" patch="1" adv="1">18882</ref>
      <ref url="http://secunia.com/advisories/18864" source="SECUNIA" patch="1" adv="1">18864</ref>
      <ref url="http://secunia.com/advisories/18862" source="SECUNIA" patch="1" adv="1">18862</ref>
      <ref url="http://secunia.com/advisories/18860" source="SECUNIA" patch="1" adv="1">18860</ref>
      <ref url="http://secunia.com/advisories/18839" source="SECUNIA" patch="1" adv="1">18839</ref>
      <ref url="http://secunia.com/advisories/18838" source="SECUNIA" patch="1" adv="1">18838</ref>
      <ref url="http://secunia.com/advisories/18837" source="SECUNIA" patch="1" adv="1">18837</ref>
      <ref url="http://secunia.com/advisories/18834" source="SECUNIA" patch="1" adv="1">18834</ref>
      <ref url="http://secunia.com/advisories/18826" source="SECUNIA" patch="1" adv="1">18826</ref>
      <ref url="http://secunia.com/advisories/18825" source="SECUNIA" patch="1" adv="1">18825</ref>
      <ref url="http://secunia.com/advisories/18707" source="SECUNIA" patch="1" adv="1">18707</ref>
      <ref url="http://secunia.com/advisories/18677" source="SECUNIA" patch="1" adv="1">18677</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0206.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0206</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt" source="SCO" patch="1" adv="1">SCOSA-2006.15</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=141242" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=141242</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0422" source="VUPEN" adv="1">ADV-2006-0422</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0389" source="VUPEN" adv="1">ADV-2006-0389</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:032" source="MANDRIVA">MDKSA-2006:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:031" source="MANDRIVA">MDKSA-2006:031</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:030" source="MANDRIVA">MDKSA-2006:030</ref>
      <ref url="http://securityreason.com/securityalert/470" source="SREASON">470</ref>
      <ref url="http://secunia.com/advisories/18875" source="SECUNIA" adv="1">18875</ref>
      <ref url="http://secunia.com/advisories/18274" source="SECUNIA" adv="1">18274</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10850" source="OVAL">oval:org.mitre.oval:def:10850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0302" published="2006-01-18" name="CVE-2006-0302" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16285" source="BID">16285</ref>
      <ref url="http://secunia.com/advisories/18511" source="SECUNIA" adv="1">18511</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041438.html" source="FULLDISC" adv="1">20060116 ZyXel P2000W (Version 2) VoIP wireless phone undocumented port UDP/9090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24145" source="XF">zyxel-p2000w-default-port(24145)</ref>
      <ref url="http://www.osvdb.org/22516" source="OSVDB">22516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="p2000w_version_2_voip_wifi_phone">
        <vers num="wv.00.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0303" published="2006-01-18" name="CVE-2006-0303" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18513" source="SECUNIA" patch="1" adv="1">18513</ref>
      <ref url="http://www.joomla.org/content/view/738/66/" source="CONFIRM">http://www.joomla.org/content/view/738/66/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0304" published="2006-01-18" name="CVE-2006-0304" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18486" source="SECUNIA" patch="1" adv="1">18486</ref>
      <ref url="http://aluigi.altervista.org/adv/dualsbof-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/dualsbof-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0245" source="VUPEN">ADV-2006-0245</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24191" source="XF">dualdhcpdns-options-field-bo(24191)</ref>
      <ref url="http://www.securityfocus.com/bid/16298" source="BID">16298</ref>
      <ref url="http://securitytracker.com/id?1015495" source="SECTRACK">1015495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="achal_dhir" name="dual_dhcp_dns_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0305" published="2006-01-18" name="CVE-2006-0305" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clipcomm CPW-100E VoIP 802.11b Wireless Handset Phone running firmware 1.1.12 (051129) and CP-100E VoIP 802.11b Wireless Phone running firmware 1.1.60 allows remote attackers to gain unauthorized access via the debug service on TCP port 60023.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16289" source="BID">16289</ref>
      <ref url="http://secunia.com/advisories/18505" source="SECUNIA" adv="1">18505</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041439.html" source="FULLDISC" adv="1">20060116 Clipcomm CP-100E VoIP wireless desktop phone open debug service TCP/60023</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041436.html" source="FULLDISC" adv="1">20060116 Clipcomm CPW-100E VoIP wireless handset phone open debug service TCP/60023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24144" source="XF">clipcomm-cp100e-default-port(24144)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clipcomm" name="cp-100e_voip_wifi_phone">
        <vers num="1.1.60" />
      </prod>
      <prod vendor="clipcomm" name="cpw-100e_voip_wifi_phone">
        <vers num="1.1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0306" published="2006-01-18" name="CVE-2006-0306" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756" source="CONFIRM" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0236" source="VUPEN" adv="1">ADV-2006-0236</ref>
      <ref url="http://www.securityfocus.com/bid/16276" source="BID">16276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded" source="BUGTRAQ">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22529" source="OSVDB">22529</ref>
      <ref url="http://www.designfolks.com.au/karma/DMPrimer/" source="MISC" adv="1">http://www.designfolks.com.au/karma/DMPrimer/</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp" source="CONFIRM" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp</ref>
      <ref url="http://securitytracker.com/id?1015504" source="SECTRACK">1015504</ref>
      <ref url="http://secunia.com/advisories/18531" source="SECUNIA" adv="1">18531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0" />
        <vers num="11.1" edition="sp1" />
      </prod>
      <prod vendor="ca" name="brightstor_mobile_backup">
        <vers num="r4.0" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" />
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0" />
      </prod>
      <prod vendor="ca" name="server_protection_suite">
        <vers num="2" />
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="5.2" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:" />
        <vers num="6.0" edition="sp1::fr" />
        <vers num="6.0" edition="sp1::en" />
        <vers num="6.0_build_6.0.56.3" edition="" />
        <vers num="6.0_build_6.0.56.3" edition=":" />
        <vers num="6.0_build_6.0.56.3" edition="::en" />
        <vers num="6.0_build_6.0.74" edition="" />
        <vers num="6.0_build_6.0.74" edition=":" />
        <vers num="6.0_build_6.0.74" edition="::fr" />
        <vers num="6.0_build_6.0.74" edition="::en" />
        <vers num="6.0_build_6.0.74" edition="::de" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0307" published="2006-01-18" name="CVE-2006-0307" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption and log file consumption) via unspecified "unrecognized network messages" that are not properly handled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015504" source="SECTRACK" patch="1">1015504</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756" source="CONFIRM" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0236" source="VUPEN" adv="1">ADV-2006-0236</ref>
      <ref url="http://www.securityfocus.com/bid/16276" source="BID">16276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded" source="BUGTRAQ">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22529" source="OSVDB">22529</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp" source="CONFIRM" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp</ref>
      <ref url="http://secunia.com/advisories/18531" source="SECUNIA" adv="1">18531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0" />
        <vers num="11.1" edition="sp1" />
      </prod>
      <prod vendor="ca" name="brightstor_mobile_backup">
        <vers num="r4.0" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" />
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0" />
      </prod>
      <prod vendor="ca" name="server_protection_suite">
        <vers num="2" />
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="5.2" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:" />
        <vers num="6.0" edition="sp1::fr" />
        <vers num="6.0" edition="sp1::en" />
        <vers num="6.0_build_6.0.56.3" edition="" />
        <vers num="6.0_build_6.0.56.3" edition=":" />
        <vers num="6.0_build_6.0.56.3" edition="::en" />
        <vers num="6.0_build_6.0.74" edition="" />
        <vers num="6.0_build_6.0.74" edition=":" />
        <vers num="6.0_build_6.0.74" edition="::fr" />
        <vers num="6.0_build_6.0.74" edition="::en" />
        <vers num="6.0_build_6.0.74" edition="::de" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0308" published="2006-01-18" name="CVE-2006-0308" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33092" source="XF">htmltonuke-htmltonuke-file-include(33092)</ref>
      <ref url="http://www.securityfocus.com/bid/16282" source="BID">16282</ref>
      <ref url="http://www.milw0rm.com/exploits/3524" source="MILW0RM">3524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htmltonuke" name="htmltonuke">
        <vers num="2.0_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0309" published="2006-01-18" name="CVE-2006-0309" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0238" source="VUPEN">ADV-2006-0238</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422064/100/0/threaded" source="BUGTRAQ">20060116 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421929/100/0/threaded" source="BUGTRAQ">20060113 Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015490" source="SECTRACK">1015490</ref>
      <ref url="http://secunia.com/advisories/18461" source="SECUNIA" adv="1">18461</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24125" source="XF">linksys-null-length-dos(24125)</ref>
      <ref url="http://www.securityfocus.com/bid/16307" source="BID">16307</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422266/100/0/threaded" source="BUGTRAQ">20060117 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="befvp41">
        <vers num="1.01.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0310" published="2006-01-18" name="CVE-2006-0310" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0240" source="VUPEN">ADV-2006-0240</ref>
      <ref url="http://www.securityfocus.com/bid/16286" source="BID">16286</ref>
      <ref url="http://secunia.com/advisories/16889" source="SECUNIA" adv="1">16889</ref>
      <ref url="http://evuln.com/vulns/37/summary.html" source="MISC" adv="1">http://evuln.com/vulns/37/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24141" source="XF">aoblogger-url-xss(24141)</ref>
      <ref url="http://www.osvdb.org/22526" source="OSVDB">22526</ref>
      <ref url="http://mikeheltonisawesome.com/viewcomments.php?idd=46" source="CONFIRM">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html" source="BUGTRAQ">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_helton" name="aoblogger">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0311" published="2006-01-18" name="CVE-2006-0311" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0240" source="VUPEN">ADV-2006-0240</ref>
      <ref url="http://www.securityfocus.com/bid/16286" source="BID">16286</ref>
      <ref url="http://secunia.com/advisories/16889" source="SECUNIA" adv="1">16889</ref>
      <ref url="http://evuln.com/vulns/37/summary.html" source="MISC" adv="1">http://evuln.com/vulns/37/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24142" source="XF">aoblogger-login-sql-injection(24142)</ref>
      <ref url="http://www.osvdb.org/22527" source="OSVDB">22527</ref>
      <ref url="http://mikeheltonisawesome.com/viewcomments.php?idd=46" source="CONFIRM">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html" source="BUGTRAQ">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_helton" name="aoblogger">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0312" published="2006-01-18" name="CVE-2006-0312" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0240" source="VUPEN">ADV-2006-0240</ref>
      <ref url="http://www.securityfocus.com/bid/16286" source="BID">16286</ref>
      <ref url="http://secunia.com/advisories/16889" source="SECUNIA" adv="1">16889</ref>
      <ref url="http://evuln.com/vulns/37/summary.html" source="MISC" adv="1">http://evuln.com/vulns/37/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24143" source="XF">aoblogger-create-security-bypass(24143)</ref>
      <ref url="http://mikeheltonisawesome.com/viewcomments.php?idd=46" source="CONFIRM">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html" source="BUGTRAQ">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_helton" name="aoblogger">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0313" published="2006-01-18" name="CVE-2006-0313" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php, (11) index.php, (12) group.php, or (13) anniv.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16273" source="BID" patch="1">16273</ref>
      <ref url="http://www.osvdb.org/22415" source="OSVDB" patch="1">22415</ref>
      <ref url="http://www.osvdb.org/22414" source="OSVDB" patch="1">22414</ref>
      <ref url="http://www.osvdb.org/22413" source="OSVDB" patch="1">22413</ref>
      <ref url="http://www.osvdb.org/22412" source="OSVDB" patch="1">22412</ref>
      <ref url="http://www.osvdb.org/22411" source="OSVDB" patch="1">22411</ref>
      <ref url="http://www.osvdb.org/22410" source="OSVDB" patch="1">22410</ref>
      <ref url="http://www.osvdb.org/22409" source="OSVDB" patch="1">22409</ref>
      <ref url="http://www.osvdb.org/22408" source="OSVDB" patch="1">22408</ref>
      <ref url="http://www.osvdb.org/22407" source="OSVDB" patch="1">22407</ref>
      <ref url="http://www.osvdb.org/22406" source="OSVDB" patch="1">22406</ref>
      <ref url="http://www.osvdb.org/22405" source="OSVDB" patch="1">22405</ref>
      <ref url="http://www.osvdb.org/22404" source="OSVDB" patch="1">22404</ref>
      <ref url="http://www.osvdb.org/22403" source="OSVDB" patch="1">22403</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682</ref>
      <ref url="http://secunia.com/advisories/18459" source="SECUNIA" patch="1" adv="1">18459</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0231" source="VUPEN">ADV-2006-0231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pdfdirectory" name="pdfdirectory">
        <vers num="0.2.10" />
        <vers num="0.2.11" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0314" published="2006-01-18" name="CVE-2006-0314" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22402" source="OSVDB">22402</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pdfdirectory" name="pdfdirectory">
        <vers num="0.2.10" />
        <vers num="0.2.11" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0315" published="2006-01-18" name="CVE-2006-0315" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt" source="MISC">http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16257" source="BID">16257</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422071/100/0/threaded" source="BUGTRAQ" adv="1">20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18043" source="SECUNIA" adv="1">18043</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html" source="FULLDISC" adv="1">20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24135" source="XF">ezdatabase-index-p-path-disclosure(24135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24134" source="XF">ezdatabase-index-p-xss(24134)</ref>
      <ref url="http://www.osvdb.org/22684" source="OSVDB">22684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indexcor" name="ezdatabase">
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0316" published="2006-01-18" name="CVE-2006-0316" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/715730" source="CERT-VN" patch="1" adv="1">VU#715730</ref>
      <ref url="http://www.securityfocus.com/bid/16262" source="BID" patch="1">16262</ref>
      <ref url="http://secunia.com/advisories/18521" source="SECUNIA" patch="1" adv="1">18521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24160" source="XF">aol-youvegotpictures-activex-bo(24160)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0221" source="VUPEN">ADV-2006-0221</ref>
      <ref url="http://www.osvdb.org/22486" source="OSVDB">22486</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MIMG-6KRSQP" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/MIMG-6KRSQP</ref>
      <ref url="http://securitytracker.com/id?1015494" source="SECTRACK">1015494</ref>
      <ref url="http://news.com.com/2061-10789_3-6027865.html?part=rss&amp;tag=6027865&amp;subj=news" source="MISC">http://news.com.com/2061-10789_3-6027865.html?part=rss&amp;tag=6027865&amp;subj=news</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol_client_software">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":plus" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":classic" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0317" published="2006-01-18" name="CVE-2006-0317" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0197" source="VUPEN">ADV-2006-0197</ref>
      <ref url="http://www.securityfocus.com/bid/16266" source="BID">16266</ref>
      <ref url="http://secunia.com/advisories/18473" source="SECUNIA" adv="1">18473</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24151" source="XF">referertracker-rkrtstats-xss(24151)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redkernel" name="referrer_tracker">
        <vers num="1.1.0_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0318" published="2006-01-18" name="CVE-2006-0318" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24131" source="XF">blogphp-index-bypass-security(24131)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0204" source="VUPEN" adv="1">ADV-2006-0204</ref>
      <ref url="http://www.securityfocus.com/bid/16269" source="BID">16269</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422137/100/0/threaded" source="BUGTRAQ" adv="1">20060117 [eVuln] BlogPHP Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22495" source="OSVDB">22495</ref>
      <ref url="http://secunia.com/advisories/18467" source="SECUNIA" adv="1">18467</ref>
      <ref url="http://evuln.com/vulns/34/summary" source="MISC" adv="1">http://evuln.com/vulns/34/summary</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insane_visions" name="blogphp">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0319" published="2006-01-18" name="CVE-2006-0319" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22496" source="OSVDB">22496</ref>
      <ref url="http://www.lort.dk/DSR-farmerswife44sp1.pl" source="MISC">http://www.lort.dk/DSR-farmerswife44sp1.pl</ref>
      <ref url="http://secunia.com/advisories/18508" source="SECUNIA" adv="1">18508</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113717162320654&amp;w=2" source="FULLDISC">20060113 Farmers wife 4.4 sp1 remote SYSTEM access</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24190" source="XF">farmerswife-ftp-directory-traversal(24190)</ref>
      <ref url="http://www.securityfocus.com/bid/16321" source="BID">16321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="farmers_wife" name="farmers_wife">
        <vers num="4.4_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0320" published="2006-01-18" name="CVE-2006-0320" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0195" source="VUPEN">ADV-2006-0195</ref>
      <ref url="http://www.securityfocus.com/bid/16244" source="BID">16244</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422068/100/0/threaded" source="BUGTRAQ" adv="1">20060115 [eVuln] Bit 5 Blog SQL Injection &amp; Authentication Bypass Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18464" source="SECUNIA" adv="1">18464</ref>
      <ref url="http://evuln.com/vulns/31/summary" source="MISC" adv="1">http://evuln.com/vulns/31/summary</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24124" source="XF">bit5blog-processlogin-sql-injection(24124)</ref>
      <ref url="http://www.osvdb.org/22445" source="OSVDB">22445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bit_5_blog" name="bit_5_blog">
        <vers prev="1" num="8.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0321" published="2006-01-23" name="CVE-2006-0321" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt" source="CONFIRM" patch="1" adv="1">http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24265" source="XF">fetchmail-message-bounce-dos(24265)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0300" source="VUPEN">ADV-2006-0300</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.securityfocus.com/bid/16365" source="BID">16365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422936/100/0/threaded" source="BUGTRAQ">20060122 fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321)</ref>
      <ref url="http://www.osvdb.org/22691" source="OSVDB">22691</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.443499" source="SLACKWARE">SSA:2006-045-01</ref>
      <ref url="http://securitytracker.com/id?1015527" source="SECTRACK">1015527</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA" adv="1">21253</ref>
      <ref url="http://secunia.com/advisories/18895" source="SECUNIA" adv="1">18895</ref>
      <ref url="http://secunia.com/advisories/18571" source="SECUNIA" adv="1">18571</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=8784" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=8784</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="6.3.0" />
        <vers num="6.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0322" published="2006-01-19" name="CVE-2006-0322" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=386609" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=386609</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0392" source="VUPEN">ADV-2006-0392</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24478" source="XF">mediawiki-comment-format-dos(24478)</ref>
      <ref url="http://secunia.com/advisories/18717" source="SECUNIA">18717</ref>
      <ref url="http://secunia.com/advisories/18711" source="SECUNIA">18711</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html" source="SUSE">SUSE-SR:2006:003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
        <vers num="1.4_beta6" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5_alpha1" />
        <vers num="1.5_alpha2" />
        <vers num="1.5_beta1" />
        <vers num="1.5_beta2" />
        <vers num="1.5_beta3" />
        <vers num="1.5_beta4" />
        <vers num="1.5_rc2" />
        <vers num="1.5_rc3" />
        <vers num="1.5_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0323" published="2006-03-23" name="CVE-2006-0323" modified="2011-03-07" discovered="2005-10-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a a size value that is less than the actual size, or (2) other unspecified manipulations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/231028" source="CERT-VN" patch="1" adv="1">VU#231028</ref>
      <ref url="http://www.service.real.com/realplayer/security/03162006_player/en/" source="CONFIRM" patch="1">http://www.service.real.com/realplayer/security/03162006_player/en/</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0257.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0257</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_18_realplayer.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:018</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-24.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-24</ref>
      <ref url="http://secunia.com/advisories/19365" source="SECUNIA" patch="1" adv="1">19365</ref>
      <ref url="http://secunia.com/advisories/19362" source="SECUNIA" patch="1" adv="1">19362</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25408" source="XF">realnetworks-swf-bo(25408)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1057" source="VUPEN">ADV-2006-1057</ref>
      <ref url="http://www.securityfocus.com/bid/17202" source="BID">17202</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430621/100/0/threaded" source="BUGTRAQ">20060411 Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015806" source="SECTRACK">1015806</ref>
      <ref url="http://securityreason.com/securityalert/690" source="SREASON">690</ref>
      <ref url="http://secunia.com/advisories/19390" source="SECUNIA" adv="1">19390</ref>
      <ref url="http://secunia.com/advisories/19358" source="SECUNIA" adv="1">19358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="gold" />
        <vers num="10.0.6" />
        <vers num="10.5" />
      </prod>
      <prod vendor="realnetworks" name="rhapsody">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0324" published="2006-01-19" name="CVE-2006-0324" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0268" source="VUPEN">ADV-2006-0268</ref>
      <ref url="http://www.securityfocus.com/bid/16319" source="BID">16319</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422364/100/0/threaded" source="BUGTRAQ" adv="1">20060119 [eVuln] WebspotBlogging Authentication Bypass Vulnerability</ref>
      <ref url="http://evuln.com/vulns/41/summary.html" source="MISC" adv="1">http://evuln.com/vulns/41/summary.html</ref>
      <ref url="https://sourceforge.net/project/shownotes.php?release_id=387180&amp;group_id=156586" source="CONFIRM">https://sourceforge.net/project/shownotes.php?release_id=387180&amp;group_id=156586</ref>
      <ref url="https://sourceforge.net/forum/forum.php?forum_id=532233" source="CONFIRM">https://sourceforge.net/forum/forum.php?forum_id=532233</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24222" source="XF">webspotblogging-login-sql-injection(24222)</ref>
      <ref url="http://www.osvdb.org/22670" source="OSVDB">22670</ref>
      <ref url="http://securitytracker.com/id?1015522" source="SECTRACK">1015522</ref>
      <ref url="http://securityreason.com/securityalert/356" source="SREASON">356</ref>
      <ref url="http://secunia.com/advisories/18560" source="SECUNIA">18560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspot" name="webspotblogging">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0325" published="2006-01-20" name="CVE-2006-0325" modified="2011-12-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24254" source="XF" patch="1">etomite-default-backdoor(24254)</ref>
      <ref url="http://secunia.com/advisories/18556" source="SECUNIA" patch="1" adv="1">18556</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0283" source="VUPEN">ADV-2006-0283</ref>
      <ref url="http://www.securityfocus.com/bid/16336" source="BID">16336</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423523/100/0/threaded" source="BUGTRAQ">20060130 Etomite followup information</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423497/100/0/threaded" source="BUGTRAQ">20060127 Etomite CMS </ref>
      <ref url="http://www.osvdb.org/22693" source="OSVDB">22693</ref>
      <ref url="http://www.lucaercoli.it/advs/etomite.txt" source="MISC">http://www.lucaercoli.it/advs/etomite.txt</ref>
      <ref url="http://www.etomite.org/forums/index.php?showtopic=4291" source="CONFIRM">http://www.etomite.org/forums/index.php?showtopic=4291</ref>
      <ref url="http://www.etomite.org/forums/index.php?showtopic=4185" source="CONFIRM">http://www.etomite.org/forums/index.php?showtopic=4185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etomite" name="etomite">
        <vers prev="1" num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0327" published="2006-01-20" name="CVE-2006-0327" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422360/100/0/threaded" source="BUGTRAQ" patch="1">20060119 IRM 015: File system path disclosure on TYPO3 Web Content Manager</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0269" source="VUPEN">ADV-2006-0269</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422390/100/0/threaded" source="BUGTRAQ">20060119 Re: IRM 015: File system path disclosure on TYPO3 Web Content Manager</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422390/100/0/threaded" source="BUGTRAQ">20060119 Re: IRM 015: File system path disclosure on TYPO3 Web Content Manage</ref>
      <ref url="http://www.irmplc.com/advisory015.htm" source="MISC" adv="1">http://www.irmplc.com/advisory015.htm</ref>
      <ref url="http://secunia.com/advisories/18546" source="SECUNIA" adv="1">18546</ref>
      <ref url="http://bugs.typo3.org/view.php?id=2248" source="MISC">http://bugs.typo3.org/view.php?id=2248</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24244" source="XF">typo3-multiple-path-disclosure(24244)</ref>
      <ref url="http://www.osvdb.org/22667" source="OSVDB">22667</ref>
      <ref url="http://www.osvdb.org/22666" source="OSVDB">22666</ref>
      <ref url="http://www.osvdb.org/22665" source="OSVDB">22665</ref>
      <ref url="http://securityreason.com/securityalert/361" source="SREASON">361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="3.7.1" />
        <vers num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0328" published="2006-01-20" name="CVE-2006-0328" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/632633" source="CERT-VN">VU#632633</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0263" source="VUPEN">ADV-2006-0263</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422405/100/0/threaded" source="BUGTRAQ" adv="1">20060119 Critical security advisory #006 tftpd32 Format string</ref>
      <ref url="http://www.critical.lt/research/tftpd32_281_dos.txt" source="MISC">http://www.critical.lt/research/tftpd32_281_dos.txt</ref>
      <ref url="http://www.critical.lt/?vulnerabilities/200" source="MISC" adv="1">http://www.critical.lt/?vulnerabilities/200</ref>
      <ref url="http://secunia.com/advisories/18539" source="SECUNIA" adv="1">18539</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24250" source="XF">tftpd32-request-format-string(24250)</ref>
      <ref url="http://www.securityfocus.com/bid/16333" source="BID">16333</ref>
      <ref url="http://www.osvdb.org/22661" source="OSVDB">22661</ref>
      <ref url="http://securityreason.com/securityalert/362" source="SREASON">362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philippe_jounin" name="tftpd32">
        <vers num="2.81" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0329" published="2006-01-20" name="CVE-2006-0329" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18553" source="SECUNIA" patch="1" adv="1">18553</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0266" source="VUPEN">ADV-2006-0266</ref>
      <ref url="http://www.securityfocus.com/bid/16326" source="BID">16326</ref>
      <ref url="http://www.osvdb.org/22669" source="OSVDB">22669</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html</ref>
      <ref url="http://securitytracker.com/id?1015519" source="SECTRACK">1015519</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24240" source="XF">hitachi-hitsenser-sql-injection(24240)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="hitsenser_data_mart_server">
        <vers num="bs" />
        <vers num="bs_l" />
        <vers num="bs_m" />
        <vers num="bs_s" />
        <vers num="ex" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0330" published="2006-01-20" name="CVE-2006-0330" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24247" source="XF" patch="1">gallery-unknown-xss(24247)</ref>
      <ref url="http://www.securityfocus.com/bid/16334" source="BID" patch="1">16334</ref>
      <ref url="http://www.osvdb.org/22660" source="OSVDB" patch="1">22660</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200601-13</ref>
      <ref url="http://secunia.com/advisories/18627" source="SECUNIA" patch="1" adv="1">18627</ref>
      <ref url="http://secunia.com/advisories/18557" source="SECUNIA" patch="1" adv="1">18557</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0282" source="VUPEN">ADV-2006-0282</ref>
      <ref url="http://gallery.menalto.com/page/gallery_1_5_2_release" source="CONFIRM">http://gallery.menalto.com/page/gallery_1_5_2_release</ref>
      <ref url="http://www.us.debian.org/security/2006/dsa-1148" source="DEBIAN">DSA-1148</ref>
      <ref url="http://secunia.com/advisories/21502" source="SECUNIA">21502</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.4" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_pl1" />
        <vers num="1.4.3_pl2" />
        <vers num="1.4.4_pl2" />
        <vers num="1.4.4_pl3" />
        <vers num="1.4.4_pl4" />
        <vers num="1.4.4_pl5" />
        <vers num="1.4_pl1" />
        <vers num="1.4_pl2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1_rc2" />
        <vers num="1.5.2_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0331" published="2006-01-20" name="CVE-2006-0331" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=117" source="MISC">http://www.squirrelmail.org/plugin_view.php?id=117</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422414/100/0/threaded" source="BUGTRAQ">20060119 Change passwd 3.1 (SquirrelMail plugin )</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24258" source="XF">changepassword-changepasswd-bo(24258)</ref>
      <ref url="http://securityreason.com/securityalert/363" source="SREASON">363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thiago_melo_de_paula" name="change_passwd">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0332" published="2006-01-20" name="CVE-2006-0332" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16317" source="BID" patch="1">16317</ref>
      <ref url="http://secunia.com/advisories/18524" source="SECUNIA" patch="1" adv="1">18524</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24220" source="XF">ecartis-pantomime-bypass-security(24220)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0260" source="VUPEN" adv="1">ADV-2006-0260</ref>
      <ref url="http://marc.theaimsgroup.com/?l=listar-dev&amp;m=113770802408358&amp;w=2" source="MLIST">[listar-dev] 20060119 [EDev] Re: Potential vulnerability -- who to contact?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=listar-dev&amp;m=113732552708625&amp;w=2" source="MLIST">[listar-dev] 20060115 [EDev] Re: Potential vulnerability -- who to contact?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="1.0.0_snapshot_2005-09-09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0333" published="2006-01-20" name="CVE-2006-0333" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422386/100/0/threaded" source="BUGTRAQ" adv="1">20060118 -2- [XSS] in ar-blog v 5.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24246" source="XF">arblog-index-xss(24246)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435205/100/0/threaded" source="BUGTRAQ">20060527 Multiple Xss exploits in ar-blog v 5.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ar-blog" name="ar-blog">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0334" published="2006-01-20" name="CVE-2006-0334" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter.  NOTE: some sources claim that the affected parameter is "q", but the only public archive of the original researcher notification shows an XSS manipulation in "Keywords".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24230" source="XF">masm-search-xss(24230)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0252" source="VUPEN">ADV-2006-0252</ref>
      <ref url="http://www.securityfocus.com/bid/16312" source="BID">16312</ref>
      <ref url="http://www.osvdb.org/22626" source="OSVDB">22626</ref>
      <ref url="http://secunia.com/advisories/18535" source="SECUNIA" adv="1">18535</ref>
      <ref url="http://osvdb.org/ref/22/22626-my_amazon.txt" source="MISC">http://osvdb.org/ref/22/22626-my_amazon.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freekrai.net" name="my_amazon_store_manager">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0335" published="2006-01-20" name="CVE-2006-0335" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16314" source="BID" patch="1">16314</ref>
      <ref url="http://www.osvdb.org/22631" source="OSVDB" patch="1">22631</ref>
      <ref url="http://secunia.com/advisories/18542" source="SECUNIA" patch="1" adv="1">18542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24233" source="XF">kerio-winroute-activedirectory-dos(24233)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24232" source="XF">kerio-winroute-html-dos(24232)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0247" source="VUPEN">ADV-2006-0247</ref>
      <ref url="http://www.kerio.com/kwf_history.html" source="CONFIRM">http://www.kerio.com/kwf_history.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
        <vers num="5.10" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.3_patch1" />
        <vers num="6.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0336" published="2006-01-20" name="CVE-2006-0336" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0324" source="VUPEN">ADV-2006-0324</ref>
      <ref url="http://www.kerio.com/kwf_history.html" source="CONFIRM">http://www.kerio.com/kwf_history.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24317" source="XF">kerio-winroute-browsing-dos(24317)</ref>
      <ref url="http://www.securityfocus.com/bid/16385" source="BID">16385</ref>
      <ref url="http://www.osvdb.org/22631" source="OSVDB">22631</ref>
      <ref url="http://secunia.com/advisories/18589" source="SECUNIA">18589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
        <vers num="5.10" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.3_patch1" />
        <vers num="6.1.4" />
        <vers num="6.1.4_patch_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0337" published="2006-01-20" name="CVE-2006-0337" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.f-secure.com/security/fsc-2006-1.shtml" source="CONFIRM" patch="1" adv="1">http://www.f-secure.com/security/fsc-2006-1.shtml</ref>
      <ref url="http://secunia.com/advisories/18529" source="SECUNIA" patch="1" adv="1">18529</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0257" source="VUPEN">ADV-2006-0257</ref>
      <ref url="http://www.securityfocus.com/bid/16309" source="BID">16309</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24198" source="XF">fsecure-zip-bo(24198)</ref>
      <ref url="http://www.osvdb.org/22632" source="OSVDB">22632</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-103.shtml" source="CIAC">Q-103</ref>
      <ref url="http://securitytracker.com/id?1015510" source="SECTRACK">1015510</ref>
      <ref url="http://securitytracker.com/id?1015509" source="SECTRACK">1015509</ref>
      <ref url="http://securitytracker.com/id?1015508" source="SECTRACK">1015508</ref>
      <ref url="http://securitytracker.com/id?1015507" source="SECTRACK">1015507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2.16" edition="" />
        <vers num="2.16" edition=":linux_gateways" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="4.51" edition="" />
        <vers num="4.51" edition=":linux_workstations" />
        <vers num="4.51" edition=":linux_servers" />
        <vers num="4.51" edition=":linux_gateways" />
        <vers num="4.52" edition="" />
        <vers num="4.52" edition=":linux_workstations" />
        <vers num="4.52" edition=":linux_servers" />
        <vers num="4.52" edition=":linux_gateways" />
        <vers num="4.61" edition="" />
        <vers num="4.61" edition=":linux_gateways" />
        <vers num="4.61" edition=":linux_servers" />
        <vers num="4.62" edition="" />
        <vers num="4.62" edition=":samba_servers" />
        <vers num="4.64" edition="" />
        <vers num="4.64" edition=":linux_gateways" />
        <vers num="4.64" edition=":linux_servers" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux_server_security" />
        <vers num="5.0" edition=":linux_client_security" />
        <vers num="5.01" edition="" />
        <vers num="5.01" edition=":linux_client_security" />
        <vers num="5.01" edition=":linux_server_security" />
        <vers num="5.11" edition="" />
        <vers num="5.11" edition=":linux_client_security" />
        <vers num="5.11" edition=":linux_server_security" />
        <vers num="5.40" edition="" />
        <vers num="5.40" edition=":workstations" />
        <vers num="5.41" edition="" />
        <vers num="5.41" edition=":mimesweeper" />
        <vers num="5.41" edition=":workstations" />
        <vers num="5.41" edition=":windows_servers" />
        <vers num="5.42" edition="" />
        <vers num="5.42" edition=":mimesweeper" />
        <vers num="5.42" edition=":windows_servers" />
        <vers num="5.42" edition=":workstations" />
        <vers num="5.43" edition="" />
        <vers num="5.43" edition=":workstations" />
        <vers num="5.44" edition="" />
        <vers num="5.44" edition=":workstations" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":client_security" />
        <vers num="5.5" edition=":mimesweeper" />
        <vers num="5.5" edition=":windows_servers" />
        <vers num="5.5" edition=":citrix_servers" />
        <vers num="5.51" edition="" />
        <vers num="5.51" edition=":mimesweeper" />
        <vers num="5.52" edition="" />
        <vers num="5.52" edition=":citrix_servers" />
        <vers num="5.52" edition=":client_security" />
        <vers num="5.52" edition=":windows_servers" />
        <vers num="5.54" edition="" />
        <vers num="5.54" edition=":client_security" />
        <vers num="5.55" edition="" />
        <vers num="5.55" edition=":client_security" />
        <vers num="5.61" edition="" />
        <vers num="5.61" edition=":mimesweeper" />
        <vers num="6.01" edition="" />
        <vers num="6.01" edition=":ms_exchange" />
        <vers num="6.01" edition=":client_security" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":ms_exchange" />
        <vers num="6.2" edition=":firewalls" />
        <vers num="6.21" edition="" />
        <vers num="6.21" edition=":ms_exchange" />
        <vers num="6.30" edition="" />
        <vers num="6.30" edition=":ms_exchange" />
        <vers num="6.30_sr1" edition="" />
        <vers num="6.30_sr1" edition=":ms_exchange" />
        <vers num="6.31" edition="" />
        <vers num="6.31" edition=":ms_exchange" />
        <vers num="6.40" edition="" />
        <vers num="6.40" edition=":ms_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="2.06" edition="" />
        <vers num="2.06" edition=":linux" />
        <vers num="2.14" edition="" />
        <vers num="2.14" edition=":linux" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":linux" />
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
        <vers num="6.41" />
        <vers num="6.42" />
      </prod>
      <prod vendor="f-secure" name="solutions_based_on_f-secure_personal_express">
        <vers num="6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0338" published="2006-01-20" name="CVE-2006-0338" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16309" source="BID" patch="1">16309</ref>
      <ref url="http://www.f-secure.com/security/fsc-2006-1.shtml" source="CONFIRM" patch="1">http://www.f-secure.com/security/fsc-2006-1.shtml</ref>
      <ref url="http://secunia.com/advisories/18529" source="SECUNIA" patch="1" adv="1">18529</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0257" source="VUPEN">ADV-2006-0257</ref>
      <ref url="http://www.osvdb.org/22633" source="OSVDB">22633</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-103.shtml" source="CIAC">Q-103</ref>
      <ref url="http://securitytracker.com/id?1015510" source="SECTRACK">1015510</ref>
      <ref url="http://securitytracker.com/id?1015509" source="SECTRACK">1015509</ref>
      <ref url="http://securitytracker.com/id?1015508" source="SECTRACK">1015508</ref>
      <ref url="http://securitytracker.com/id?1015507" source="SECTRACK">1015507</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24199" source="XF">fsecure-rar-zip-scan-bypass(24199)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="4.51" edition="" />
        <vers num="4.51" edition=":linux_servers" />
        <vers num="4.51" edition=":linux_gateways" />
        <vers num="4.52" edition="" />
        <vers num="4.52" edition=":linux_workstations" />
        <vers num="4.52" edition=":linux_servers" />
        <vers num="4.52" edition=":linux_gateways" />
        <vers num="4.60" edition="" />
        <vers num="4.60" edition=":samba_servers" />
        <vers num="4.61" edition="" />
        <vers num="4.61" edition=":linux_gateways" />
        <vers num="4.61" edition=":linux_servers" />
        <vers num="4.62" edition="" />
        <vers num="4.62" edition=":samba_servers" />
        <vers num="4.64" edition="" />
        <vers num="4.64" edition=":linux_gateways" />
        <vers num="4.64" edition=":linux_servers" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux_server_security" />
        <vers num="5.0" edition=":linux_client_security" />
        <vers num="5.11" edition="" />
        <vers num="5.11" edition=":linux_client_security" />
        <vers num="5.11" edition=":linux_server_security" />
        <vers num="5.41" edition="" />
        <vers num="5.41" edition=":mimesweeper" />
        <vers num="5.41" edition=":workstations" />
        <vers num="5.42" edition="" />
        <vers num="5.42" edition=":mimesweeper" />
        <vers num="5.42" edition=":windows_servers" />
        <vers num="5.42" edition=":workstations" />
        <vers num="5.43" edition="" />
        <vers num="5.43" edition=":workstations" />
        <vers num="5.44" edition="" />
        <vers num="5.44" edition=":workstations" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":client_security" />
        <vers num="5.5" edition=":mimesweeper" />
        <vers num="5.5" edition=":windows_servers" />
        <vers num="5.52" edition="" />
        <vers num="5.52" edition=":mimesweeper" />
        <vers num="5.52" edition=":citrix_servers" />
        <vers num="5.52" edition=":client_security" />
        <vers num="5.52" edition=":windows_servers" />
        <vers num="5.55" edition="" />
        <vers num="5.55" edition=":client_security" />
        <vers num="6.01" edition="" />
        <vers num="6.01" edition=":ms_exchange" />
        <vers num="6.01" edition=":client_security" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":ms_exchange" />
        <vers num="6.2" edition=":firewalls" />
        <vers num="6.21" edition="" />
        <vers num="6.21" edition=":ms_exchange" />
        <vers num="6.30" edition="" />
        <vers num="6.30" edition=":ms_exchange" />
        <vers num="6.30_sr1" edition="" />
        <vers num="6.30_sr1" edition=":ms_exchange" />
        <vers num="6.31" edition="" />
        <vers num="6.31" edition=":ms_exchange" />
        <vers num="6.40" edition="" />
        <vers num="6.40" edition=":ms_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="5.0" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="2.06" edition="" />
        <vers num="2.06" edition=":linux" />
        <vers num="2.14" edition="" />
        <vers num="2.14" edition=":linux" />
        <vers num="6.32" />
        <vers num="6.41" />
        <vers num="6.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0339" published="2006-01-20" name="CVE-2006-0339" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16311" source="BID" patch="1">16311</ref>
      <ref url="http://secunia.com/advisories/18522" source="SECUNIA" patch="1" adv="1">18522</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0251" source="VUPEN">ADV-2006-0251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422361/100/0/threaded" source="BUGTRAQ" adv="1">20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html" source="MISC" adv="1">http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html</ref>
      <ref url="http://www.bitcomet.com/doc/changelog.htm" source="CONFIRM">http://www.bitcomet.com/doc/changelog.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24229" source="XF">bitcomet-torrent-publisher-bo(24229)</ref>
      <ref url="http://www.osvdb.org/22625" source="OSVDB">22625</ref>
      <ref url="http://securityreason.com/securityalert/357" source="SREASON">357</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0669.html" source="FULLDISC">20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0442.html" source="BUGTRAQ">20060122 BitComet URI Proof of Concept</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitcomet" name="bitcomet">
        <vers num="0.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0340" published="2006-01-20" name="CVE-2006-0340" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015501" source="SECTRACK" patch="1">1015501</ref>
      <ref url="http://secunia.com/advisories/18490" source="SECUNIA" patch="1" adv="1">18490</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24182" source="XF">cisco-ios-sgbp-dos(24182)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0248" source="VUPEN">ADV-2006-0248</ref>
      <ref url="http://www.securityfocus.com/bid/16303" source="BID">16303</ref>
      <ref url="http://www.osvdb.org/22624" source="OSVDB">22624</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-sgbp.shtml" source="CISCO" adv="1">20060118 IOS Stack Group Bidding Protocol Crafted Packet DoS</ref>
      <ref url="http://securityreason.com/securityalert/358" source="SREASON">358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0t" />
        <vers num="12.0xa" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xn" />
        <vers num="12.0xr" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1e" />
        <vers num="12.1ec" />
        <vers num="12.1ex" />
        <vers num="12.1ez" />
        <vers num="12.1ga" />
        <vers num="12.1gb" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xd" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xq" />
        <vers num="12.1xs" />
        <vers num="12.1xu" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yd" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2by" />
        <vers num="12.2cx" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2su" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xv" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yn" />
        <vers num="12.2yt" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zj" />
        <vers num="12.2zn" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3t" />
        <vers num="12.3xb" />
        <vers num="12.3xd" />
        <vers num="12.3xf" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xm" />
        <vers num="12.3xq" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0341" published="2006-01-06" name="CVE-2006-0341" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18551" source="SECUNIA" patch="1" adv="1">18551</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2" source="FULLDISC" patch="1" adv="1">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0284" source="VUPEN">ADV-2006-0284</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24256" source="XF">mailsite-wconsole-xss(24256)</ref>
      <ref url="http://www.securityfocus.com/bid/16330" source="BID">16330</ref>
      <ref url="http://www.osvdb.org/22677" source="OSVDB">22677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="6.1.22" />
        <vers prev="1" num="7.0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0342" published="2006-01-20" name="CVE-2006-0342" modified="2011-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18551" source="SECUNIA" patch="1" adv="1">18551</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2" source="FULLDISC" patch="1" adv="1">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24255" source="XF">mailsite-wconsole-dos(24255)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0284" source="VUPEN" adv="1">ADV-2006-0284</ref>
      <ref url="http://www.securityfocus.com/bid/16331" source="BID">16331</ref>
      <ref url="http://www.osvdb.org/22678" source="OSVDB">22678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers num="7.0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0343" published="2006-01-20" name="CVE-2006-0343" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18538" source="SECUNIA" patch="1" adv="1">18538</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0267" source="VUPEN">ADV-2006-0267</ref>
      <ref url="http://www.securityfocus.com/bid/16327" source="BID">16327</ref>
      <ref url="http://www.osvdb.org/22676" source="OSVDB">22676</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html</ref>
      <ref url="http://securitytracker.com/id?1015520" source="SECTRACK">1015520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24243" source="XF">hitachi-jp1netinsight-port-dos(24243)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="jpi_netsight_ii_port_discovery_advance">
        <vers num="r_15237_9154_07_50" />
      </prod>
      <prod vendor="hitachi" name="jpi_netsight_ii_port_discovery_standard">
        <vers num="r_15237_9164_07_00" />
        <vers num="r_15237_9164_07_01" />
        <vers num="r_15237_9164_07_02" />
        <vers num="r_15237_9164_07_03" />
        <vers num="r_15237_9164_07_04" />
        <vers num="r_15237_9164_07_05" />
        <vers num="r_15237_9164_07_06" />
        <vers num="r_15237_9164_07_07" />
        <vers num="r_15237_9164_07_08" />
        <vers num="r_15237_9164_07_09" />
        <vers num="r_15237_9164_07_10" />
        <vers num="r_15237_9164_07_11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0344" published="2006-01-20" name="CVE-2006-0344" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nii.co.in/vuln/filecopa.html" source="MISC" patch="1" adv="1">http://www.nii.co.in/vuln/filecopa.html</ref>
      <ref url="http://secunia.com/advisories/18550" source="SECUNIA" patch="1" adv="1">18550</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24257" source="XF">filecopa-ftp-directory-traversal(24257)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0285" source="VUPEN">ADV-2006-0285</ref>
      <ref url="http://www.securityfocus.com/bid/16335" source="BID">16335</ref>
      <ref url="http://www.osvdb.org/22694" source="OSVDB">22694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intervations" name="filecopa">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0345" published="2006-01-20" name="CVE-2006-0345" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php.  NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16306" source="BID">16306</ref>
      <ref url="http://evuln.com/vulns/40/summary.html" source="MISC" adv="1">http://evuln.com/vulns/40/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24218" source="XF">saralblog-search-sql-injection(24218)</ref>
      <ref url="http://www.osvdb.org/22740" source="OSVDB">22740</ref>
      <ref url="http://securitytracker.com/id?1015517" source="SECTRACK">1015517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html" source="BUGTRAQ">20060118 [eVuln] SaralBlog XSS &amp; Multiple SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saral_kaushik" name="saralblog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0346" published="2006-01-20" name="CVE-2006-0346" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16306" source="BID">16306</ref>
      <ref url="http://evuln.com/vulns/40/summary.html" source="MISC" adv="1">http://evuln.com/vulns/40/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24219" source="XF">saralblog-view-xss(24219)</ref>
      <ref url="http://www.osvdb.org/27907" source="OSVDB">27907</ref>
      <ref url="http://securitytracker.com/id?1015517" source="SECTRACK">1015517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html" source="BUGTRAQ">20060118 [eVuln] SaralBlog XSS &amp; Multiple SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saral_kaushik" name="saralblog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0347" published="2006-01-20" name="CVE-2006-0347" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16315" source="BID" patch="1">16315</ref>
      <ref url="http://secunia.com/advisories/18533" source="SECUNIA" patch="1" adv="1">18533</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24224" source="XF">elog-dotdot-directory-traversal(24224)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0262" source="VUPEN">ADV-2006-0262</ref>
      <ref url="http://midas.psi.ch/elog/download/ChangeLog" source="MISC">http://midas.psi.ch/elog/download/ChangeLog</ref>
      <ref url="http://www.osvdb.org/22647" source="OSVDB">22647</ref>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA">18783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0348" published="2006-01-20" name="CVE-2006-0348" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16315" source="BID" patch="1">16315</ref>
      <ref url="http://secunia.com/advisories/18533" source="SECUNIA" patch="1" adv="1">18533</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0262" source="VUPEN">ADV-2006-0262</ref>
      <ref url="http://midas.psi.ch/elog/download/ChangeLog" source="MISC">http://midas.psi.ch/elog/download/ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24221" source="XF">elog-elogd-format-string(24221)</ref>
      <ref url="http://www.osvdb.org/22646" source="OSVDB">22646</ref>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA">18783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0349" published="2006-01-20" name="CVE-2006-0349" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16305" source="BID">16305</ref>
      <ref url="http://securitytracker.com/id?1015505" source="SECTRACK" adv="1">1015505</ref>
      <ref url="http://secunia.com/advisories/18212" source="SECUNIA" adv="1">18212</ref>
      <ref url="http://evuln.com/vulns/39/summary.html" source="MISC" adv="1">http://evuln.com/vulns/39/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24210" source="XF">eggblog-blog-sql-injection(24210)</ref>
      <ref url="http://www.osvdb.org/22751" source="OSVDB">22751</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html" source="BUGTRAQ">20060118 [eVuln] eggblog Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_designs" name="eggblog">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0350" published="2006-01-20" name="CVE-2006-0350" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16305" source="BID">16305</ref>
      <ref url="http://securitytracker.com/id?1015505" source="SECTRACK" adv="1">1015505</ref>
      <ref url="http://secunia.com/advisories/18212" source="SECUNIA" adv="1">18212</ref>
      <ref url="http://evuln.com/vulns/39/summary.html" source="MISC" adv="1">http://evuln.com/vulns/39/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24209" source="XF">eggblog-topic-xss(24209)</ref>
      <ref url="http://www.osvdb.org/22752" source="OSVDB">22752</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html" source="BUGTRAQ">20060118 [eVuln] eggblog Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_designs" name="eggblog">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0351" published="2006-01-20" name="CVE-2006-0351" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22636" source="OSVDB" patch="1">22636</ref>
      <ref url="http://secunia.com/advisories/18532" source="SECUNIA" patch="1" adv="1">18532</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0256" source="VUPEN">ADV-2006-0256</ref>
      <ref url="http://mydns.bboy.net/download/changelog.html" source="CONFIRM">http://mydns.bboy.net/download/changelog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24228" source="XF">mydns-query-dos(24228)</ref>
      <ref url="http://www.securityfocus.com/bid/16431" source="BID">16431</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-16.xml" source="GENTOO">GLSA-200601-16</ref>
      <ref url="http://www.debian.org/security/2006/dsa-963" source="DEBIAN">DSA-963</ref>
      <ref url="http://securitytracker.com/id?1015521" source="SECTRACK">1015521</ref>
      <ref url="http://secunia.com/advisories/18653" source="SECUNIA">18653</ref>
      <ref url="http://secunia.com/advisories/18641" source="SECUNIA">18641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="don_moore" name="mydns">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.11.0" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0352" published="2006-01-20" name="CVE-2006-0352" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request.  NOTE: It was later reported that 1.1.2 is also affected.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456069/100/0/threaded" source="BUGTRAQ">20070105 Flog 1.1.2 Remote Admin Password Disclosure</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422268/100/0/threaded" source="BUGTRAQ">20060117 [eVuln] Flog Information Disclosure Vulnerability</ref>
      <ref url="http://evuln.com/vulns/38/summary/bt/" source="MISC">http://evuln.com/vulns/38/summary/bt/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31307" source="XF">flog-admin-info-disclosure(31307)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24193" source="XF">flog-data-directory-insecure(24193)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fluffington" name="flog">
        <vers num="1.01" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0353" published="2006-01-22" name="CVE-2006-0353" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16357" source="BID" patch="1">16357</ref>
      <ref url="http://www.debian.org/security/2006/dsa-956" source="DEBIAN" patch="1" adv="1">DSA-956</ref>
      <ref url="http://secunia.com/advisories/18623" source="SECUNIA" patch="1" adv="1">18623</ref>
      <ref url="http://secunia.com/advisories/18564" source="SECUNIA" patch="1" adv="1">18564</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24263" source="XF">lsh-file-descriptor-leak(24263)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0301" source="VUPEN" adv="1">ADV-2006-0301</ref>
      <ref url="http://www.osvdb.org/22695" source="OSVDB">22695</ref>
      <ref url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2006q1/000467.html" source="MLIST" adv="1">[lsh-bugs] SECURITY: lshd leaks fd:s to user shells</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="lsh">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0354" published="2006-01-22" name="CVE-2006-0354" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="5.5" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="5.1" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015483" source="SECTRACK" patch="1">1015483</ref>
      <ref url="http://secunia.com/advisories/18430" source="SECUNIA" patch="1" adv="1">18430</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24086" source="XF">cisco-aironet-arp-dos(24086)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0176" source="VUPEN">ADV-2006-0176</ref>
      <ref url="http://www.securityfocus.com/bid/16217" source="BID">16217</ref>
      <ref url="http://www.osvdb.org/22375" source="OSVDB">22375</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060112-wireless.shtml" source="CISCO" adv="1">20060112 Access Point Memory Exhaustion from ARP Attacks</ref>
      <ref url="http://securityreason.com/securityalert/339" source="SREASON">339</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5680" source="OVAL">oval:org.mitre.oval:def:5680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="aironet_ap1100">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1130ag">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1200">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1230ag">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1240ag">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1300">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap1400">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="aironet_ap350">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0355" published="2006-01-22" name="CVE-2006-0355" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421869/100/0/threaded" source="BUGTRAQ" adv="1">20060114 [KAPDA::#21] - HomeFtp v1.1 Denial of Service</ref>
      <ref url="http://www.kapda.ir/advisory-202.html" source="MISC" adv="1">http://www.kapda.ir/advisory-202.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24152" source="XF">homeftp-long-command-dos(24152)</ref>
      <ref url="http://www.securityfocus.com/bid/16238" source="BID">16238</ref>
      <ref url="http://securityreason.com/securityalert/350" source="SREASON">350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helmsman_research" name="homeftp">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0356" published="2006-01-22" name="CVE-2006-0356" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422033/100/0/threaded" source="BUGTRAQ" adv="1">20060115 Homeftp r1.0.7 Denial of Service</ref>
      <ref url="http://www.kapda.ir/advisory-211.html" source="MISC" adv="1">http://www.kapda.ir/advisory-211.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24227" source="XF">homeftpserver-long-command-dos(24227)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ari_pikivirta" name="home_ftp_server">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0357" published="2006-01-22" name="CVE-2006-0357" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422162/100/0/threaded" source="BUGTRAQ" adv="1">20060115 Cerberus FTP Server 2.32 Denial of Service</ref>
      <ref url="http://www.kapda.ir/advisory-210.html" source="MISC" adv="1">http://www.kapda.ir/advisory-210.html</ref>
      <ref url="http://www.cerberusftp.com/cerberus-releasenotes.htm" source="MISC">http://www.cerberusftp.com/cerberus-releasenotes.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24226" source="XF">cerberus-long-command-dos(24226)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grant_averett" name="cerberus_ftp_server">
        <vers num="2.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0358" published="2006-01-22" name="CVE-2006-0358" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16279" source="BID">16279</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422151/100/0/threaded" source="BUGTRAQ">20060117 PowerPortal Cross-Site Scripting Vulnerability</ref>
      <ref url="http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/" source="MISC">http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24196" source="XF">powerportal-search-index-xss(24196)</ref>
      <ref url="http://www.osvdb.org/27958" source="OSVDB">27958</ref>
      <ref url="http://www.osvdb.org/27957" source="OSVDB">27957</ref>
      <ref url="http://secunia.com/advisories/10172" source="SECUNIA">10172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerportal" name="powerportal">
        <vers num="1.1b" />
        <vers num="1.3" />
        <vers num="1.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0359" published="2006-01-22" name="CVE-2006-0359" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24181" source="XF">eyebeam-sip-header-bo(24181)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0259" source="VUPEN">ADV-2006-0259</ref>
      <ref url="http://www.securityfocus.com/bid/16253" source="BID">16253</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446573/100/0/threaded" source="BUGTRAQ">20060921 Re: CounterPath eyeBeam Handing SIP header Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422009/100/0/threaded" source="BUGTRAQ">20060116 CounterPath eyeBeam Handing SIP header Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/354" source="SREASON">354</ref>
      <ref url="http://secunia.com/advisories/18516" source="SECUNIA" adv="1">18516</ref>
      <ref url="http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx" source="MISC">http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="counterpath" name="eyebeam_sip_softphone">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0360" published="2006-01-22" name="CVE-2006-0360" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16285" source="BID">16285</ref>
      <ref url="http://secunia.com/advisories/18512" source="SECUNIA" adv="1">18512</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041437.html" source="FULLDISC" adv="1">20060116 MPM HP-180W VoIP wireless desktop phone undocumented port UDP/9090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24147" source="XF">mpn-hp180w-default-port(24147)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpm" name="hp-180w_voip_wifi_phone">
        <vers num="we.00.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0361" published="2006-01-22" name="CVE-2006-0361" modified="2011-03-07" discovered="2006-01-15" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an &lt;a> tag in the comment parameter, which strips most tags but not &lt;a>.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0195" source="VUPEN">ADV-2006-0195</ref>
      <ref url="http://www.securityfocus.com/bid/16246" source="BID">16246</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421994/100/0/threaded" source="BUGTRAQ" adv="1">20060115 [eVuln] Bit 5 Blog JavaScript Insertion Vulnerability</ref>
      <ref url="http://www.osvdb.org/22446" source="OSVDB">22446</ref>
      <ref url="http://secunia.com/advisories/18464" source="SECUNIA" adv="1">18464</ref>
      <ref url="http://evuln.com/vulns/32/summary/" source="MISC" adv="1">http://evuln.com/vulns/32/summary/</ref>
      <ref url="http://evuln.com/vulns/32/exploit" source="MISC">http://evuln.com/vulns/32/exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24129" source="XF">bit5blog-addcomment-xss(24129)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bit_5_blog" name="bit_5_blog">
        <vers num="8.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0362" published="2006-01-22" name="CVE-2006-0362" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a denial of service (CPU consumption) via an unknown vector, probably involving an HTTP request with a negative number in the Content-Length header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22504" source="OSVDB" patch="1">22504</ref>
      <ref url="http://www.eweek.com/article2/0,1759,1912048,00.asp" source="CONFIRM" patch="1">http://www.eweek.com/article2/0,1759,1912048,00.asp</ref>
      <ref url="http://isc.sans.org/diary.php?storyid=1042" source="MISC" patch="1">http://isc.sans.org/diary.php?storyid=1042</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24200" source="XF">tippingpoint-ips-http-traffic-dos(24200)</ref>
      <ref url="http://www.securityfocus.com/bid/16299" source="BID">16299</ref>
      <ref url="http://securitytracker.com/id?1015511" source="SECTRACK">1015511</ref>
      <ref url="http://secunia.com/advisories/18515" source="SECUNIA">18515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="tippingpoint_ips_tos">
        <vers num="2.1.3.6323" />
        <vers num="2.2.0.6504" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0363" published="2006-01-22" name="CVE-2006-0363" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the original passwords via a program that calls CryptUnprotectData, as demonstrated by the "MSN Password Recovery.exe" program.  NOTE: it could be argued that local-only password recovery is inherently insecure because the decryption methods and keys must be stored somewhere on the local system, and are thus inherently accessible with varying degrees of effort.  Perhaps this issue should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422283/100/0/threaded" source="BUGTRAQ">20060117 Re: MSN Messenger Password Decrypter for WinXP/2003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421921/100/0/threaded" source="BUGTRAQ">20060113 Re: MSN Messenger Password Decrypter for WinXP/2003</ref>
      <ref url="http://www.msn-password-recovery.com/" source="MISC">http://www.msn-password-recovery.com/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_messenger">
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0364" published="2006-01-22" name="CVE-2006-0364" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "&amp;#106&amp;#97&amp;#118&amp;#97&amp;#115&amp;#99&amp;#114&amp;#105&amp;#112&amp;#116".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18544" source="SECUNIA" patch="1" adv="1">18544</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24225" source="XF">mybb-html-signature-xss(24225)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0255" source="VUPEN">ADV-2006-0255</ref>
      <ref url="http://www.securityfocus.com/bid/16308" source="BID">16308</ref>
      <ref url="http://www.osvdb.org/22628" source="OSVDB">22628</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0332.html" source="BUGTRAQ">20060118 MyBB Signature HTML Code Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="1.0_preview_release_2" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0365" published="2006-01-22" name="CVE-2006-0365" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422277/100/0/threaded" source="BUGTRAQ">20060118 XMB Forum HTML Code Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24208" source="XF">xmbforum-imgsrc-xss(24208)</ref>
      <ref url="http://www.osvdb.org/27920" source="OSVDB">27920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_software" name="xmb_forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0366" published="2006-01-22" name="CVE-2006-0366" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.</descript>
    </desc>
    <sols>
      <sol source="nvd">A simple fix has been released on the Main PCW site available directly at &lt;a href="http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1">http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1
&lt;/a>Please download and install imediately. </sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16300" source="BID" patch="1">16300</ref>
      <ref url="http://secunia.com/advisories/18541" source="SECUNIA" patch="1" adv="1">18541</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0254" source="VUPEN">ADV-2006-0254</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422265/100/0/threaded" source="BUGTRAQ">20060117 Phpclanwebsite BBCode IMG Tag XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpclanwebsite" name="phpclanwebsite">
        <vers num="1.23.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0367" published="2006-01-22" name="CVE-2006-0367" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22621" source="OSVDB" patch="1">22621</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtml" source="CISCO" patch="1" adv="1">20060118 Cisco Call Manager Privilege Escalation</ref>
      <ref url="http://securitytracker.com/id?1015502" source="SECTRACK" patch="1">1015502</ref>
      <ref url="http://secunia.com/advisories/18501" source="SECUNIA" patch="1" adv="1">18501</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24172" source="XF">cisco-callmanager-ccmadmin-gain-priv(24172)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0250" source="VUPEN" adv="1">ADV-2006-0250</ref>
      <ref url="http://www.securityfocus.com/bid/16293" source="BID">16293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1(2)" />
        <vers num="3.1(3a)" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3(3)" />
        <vers num="3.3(3)es61" />
        <vers num="3.3(4)es25" />
        <vers num="3.3(5)" />
        <vers num="4.0" />
        <vers num="4.0(2a)es40" />
        <vers num="4.0(2a)sr2b" />
        <vers num="4.1(2)es33" />
        <vers num="4.1(3)es07" />
        <vers num="4.1(3)sr1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0368" published="2006-01-22" name="CVE-2006-0368" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18494" source="SECUNIA" patch="1" adv="1">18494</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0249" source="VUPEN">ADV-2006-0249</ref>
      <ref url="http://www.securityfocus.com/bid/16295" source="BID">16295</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtml" source="CISCO">20060118 Cisco Call Manager Denial of Service</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24180" source="XF">cisco-callmanager-port-connection-dos(24180)</ref>
      <ref url="http://www.osvdb.org/22623" source="OSVDB">22623</ref>
      <ref url="http://www.osvdb.org/22622" source="OSVDB">22622</ref>
      <ref url="http://securitytracker.com/id?1015503" source="SECTRACK">1015503</ref>
      <ref url="http://securityreason.com/securityalert/359" source="SREASON">359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1(2)" />
        <vers num="3.1(3a)" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3(3)" />
        <vers num="3.3(3)es61" />
        <vers num="3.3(4)es25" />
        <vers num="3.3(5)" />
        <vers num="3.3(5)es30" />
        <vers num="4.0" />
        <vers num="4.0(2a)es40" />
        <vers num="4.0(2a)es62" />
        <vers num="4.0(2a)sr2b" />
        <vers num="4.1(2)es33" />
        <vers num="4.1(2)es55" />
        <vers num="4.1(3)es07" />
        <vers num="4.1(3)es32" />
        <vers num="4.1(3)sr1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0369" published="2006-01-22" name="CVE-2006-0369" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">** DISPUTED **  MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW.  NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423432/100/0/threaded" source="BUGTRAQ">20060128 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423228/100/0/threaded" source="BUGTRAQ">20060123 RE: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423204/100/0/threaded" source="BUGTRAQ">20060124 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423180/30/7310/threaded" source="BUGTRAQ">20060122 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422491/100/0/threaded" source="BUGTRAQ" adv="1">20060120 MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/422698/100/0/threaded" source="BUGTRAQ">20060121 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/422592/100/0/threaded" source="BUGTRAQ">20060121 RE: MySQL 5.0 information leak?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0370" published="2006-01-22" name="CVE-2006-0370" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422499/100/0/threaded" source="BUGTRAQ" adv="1">20060120 [eVuln] RCBlog Directory Traversal &amp; Sensitive Information Disclosure</ref>
      <ref url="http://www.fluffington.com/index.php?page=rcblog" source="MISC">http://www.fluffington.com/index.php?page=rcblog</ref>
      <ref url="http://secunia.com/advisories/18547" source="SECUNIA" adv="1">18547</ref>
      <ref url="http://evuln.com/vulns/42/summary.html" source="MISC" adv="1">http://evuln.com/vulns/42/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24249" source="XF">rcblog-data-config-insecure-directories(24249)</ref>
      <ref url="http://www.osvdb.org/22679" source="OSVDB">22679</ref>
      <ref url="http://securitytracker.com/id?1015523" source="SECTRACK">1015523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noah_medling" name="rcblog">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0371" published="2006-01-22" name="CVE-2006-0371" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16342" source="BID">16342</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422499/100/0/threaded" source="BUGTRAQ" adv="1">20060120 [eVuln] RCBlog Directory Traversal &amp; Sensitive Information Disclosure</ref>
      <ref url="http://www.fluffington.com/index.php?page=rcblog" source="MISC">http://www.fluffington.com/index.php?page=rcblog</ref>
      <ref url="http://secunia.com/advisories/18547" source="SECUNIA" adv="1">18547</ref>
      <ref url="http://evuln.com/vulns/42/summary.html" source="MISC" adv="1">http://evuln.com/vulns/42/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27042" source="XF">rcblog-index-file-include(27042)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24248" source="XF">rcblog-index-directory-traversal(24248)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436784/30/4500/threaded" source="BUGTRAQ">20060611 RCblog 1.03 Directory Traversal [index.php]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425392/100/0/threaded" source="BUGTRAQ">20060218 RCblog exploit [fun]</ref>
      <ref url="http://www.osvdb.org/22680" source="OSVDB">22680</ref>
      <ref url="http://securitytracker.com/id?1015523" source="SECTRACK">1015523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noah_medling" name="rcblog">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0372" published="2006-01-22" name="CVE-2006-0372" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.</descript>
    </desc>
    <sols>
      <sol source="nvd">BlogPHP version 2.0 was released to fix the config.php exploit and is available for download at &lt;a href="http://sourceforge.net/project/showfiles.php?group_id=156043">http://sourceforge.net/project/showfiles.php?group_id=156043&lt;/a>.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16340" source="BID">16340</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422593/100/0/threaded" source="BUGTRAQ">20060121 BlogPHP config.php SQL injection login bypassed</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422484/100/0/threaded" source="BUGTRAQ" adv="1">20060120 BlogPHP config.php SQL injection login bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422483/100/0/threaded" source="BUGTRAQ" adv="1">20060120 BlogPHP config.php SQL injection login bypass</ref>
      <ref url="http://www.osvdb.org/22738" source="OSVDB">22738</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24131" source="XF">blogphp-index-bypass-security(24131)</ref>
      <ref url="http://securityreason.com/securityalert/365" source="SREASON">365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insane_visions" name="blogphp">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0373" published="2006-01-22" name="CVE-2006-0373" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16302" source="BID">16302</ref>
      <ref url="http://www.osvdb.org/27918" source="OSVDB">27918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="douran" name="followweb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0374" published="2006-01-22" name="CVE-2006-0374" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24149" source="XF">act-p202s-default-port(24149)</ref>
      <ref url="http://www.securityfocus.com/bid/16288" source="BID">16288</ref>
      <ref url="http://secunia.com/advisories/18514" source="SECUNIA" adv="1">18514</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html" source="FULLDISC" adv="1">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantage_century_telecommunication" name="p202s">
        <vers num="1.01.21_firmware_1.1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0375" published="2006-01-22" name="CVE-2006-0375" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18514" source="SECUNIA" adv="1">18514</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html" source="FULLDISC" adv="1">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24149" source="XF">act-p202s-default-port(24149)</ref>
      <ref url="http://www.securityfocus.com/bid/16288" source="BID">16288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantage_century_telecommunication" name="p202s">
        <vers num="1.01.21_firmware_1.1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0376" published="2006-01-22" name="CVE-2006-0376" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.theta44.org/karma/" source="MISC">http://www.theta44.org/karma/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421868/100/0/threaded" source="BUGTRAQ">20060114 [NMRC Advisory] Microsoft Windows Wireless Exposure on Laptops</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html" source="MISC">http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html</ref>
      <ref url="http://www.nmrc.org/pub/advise/20060114.txt" source="MISC" adv="1">http://www.nmrc.org/pub/advise/20060114.txt</ref>
      <ref url="http://securitytracker.com/id?1015489" source="SECTRACK">1015489</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24157" source="XF">windows-wireless-adhoc-unauth-access(24157)</ref>
      <ref url="http://securityreason.com/securityalert/349" source="SREASON">349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:home" />
        <vers num="" edition="gold:professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0377" published="2006-02-23" name="CVE-2006-0377" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2006-02-15" source="CONFIRM" patch="1">http://www.squirrelmail.org/security/issue/2006-02-15</ref>
      <ref url="http://securitytracker.com/id?1015662" source="SECTRACK" patch="1">1015662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24849" source="XF">squirrelmail-mailbox-imap-injection(24849)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0689" source="VUPEN">ADV-2006-0689</ref>
      <ref url="http://www.securityfocus.com/bid/16756" source="BID">16756</ref>
      <ref url="http://secunia.com/advisories/18985" source="SECUNIA" adv="1">18985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11470" source="OVAL">oval:org.mitre.oval:def:11470</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0283.html" source="REDHAT">RHSA-2006:0283</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" source="FEDORA">FEDORA-2006-133</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" source="MANDRIVA">MDKSA-2006:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" source="GENTOO">GLSA-200603-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-988" source="DEBIAN">DSA-988</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/19960" source="SECUNIA">19960</ref>
      <ref url="http://secunia.com/advisories/19205" source="SECUNIA">19205</ref>
      <ref url="http://secunia.com/advisories/19176" source="SECUNIA">19176</ref>
      <ref url="http://secunia.com/advisories/19131" source="SECUNIA">19131</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_r3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.4.4" />
        <vers num="1.4.4_rc1" />
        <vers num="1.4.5" />
        <vers num="1.4.6_rc1" />
        <vers num="1.4_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0378" published="2006-01-23" name="CVE-2006-0378" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program.  NOTE: the name of the affected program might be installation-dependent, but it has been identified as "product_details.php" by some sources.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0253" source="VUPEN">ADV-2006-0253</ref>
      <ref url="http://www.securityfocus.com/bid/16313" source="BID">16313</ref>
      <ref url="http://www.osvdb.org/22634" source="OSVDB">22634</ref>
      <ref url="http://secunia.com/advisories/18537" source="SECUNIA" adv="1">18537</ref>
      <ref url="http://osvdb.org/ref/22/22634-x-site.txt" source="MISC">http://osvdb.org/ref/22/22634-x-site.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24234" source="XF">xsitemanager-productdetails-xss(24234)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netrix" name="x-site_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0379" published="2006-01-25" name="CVE-2006-0379" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18599" source="SECUNIA" patch="1" adv="1">18599</ref>
      <ref url="http://www.securityfocus.com/bid/16373" source="BID">16373</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc" source="FREEBSD">FreeBSD-SA-06:06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24338" source="XF">bsd-buffer-initialization-disclosure(24338)</ref>
      <ref url="http://www.osvdb.org/22730" source="OSVDB">22730</ref>
      <ref url="http://securitytracker.com/id?1015541" source="SECTRACK">1015541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.4" edition="stable" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0380" published="2006-01-25" name="CVE-2006-0380" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18599" source="SECUNIA" patch="1" adv="1">18599</ref>
      <ref url="http://www.securityfocus.com/bid/16373" source="BID">16373</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc" source="FREEBSD">FreeBSD-SA-06:06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24340" source="XF">bsd-buffer-length-disclosure(24340)</ref>
      <ref url="http://www.osvdb.org/22731" source="OSVDB">22731</ref>
      <ref url="http://securitytracker.com/id?1015541" source="SECTRACK">1015541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.4" edition="stable" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0381" published="2006-01-25" name="CVE-2006-0381" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18609" source="SECUNIA" patch="1" adv="1">18609</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:07.pf.asc" source="FREEBSD" patch="1">FreeBSD-SA-06:07</ref>
      <ref url="http://www.securityfocus.com/bid/16375" source="BID">16375</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&amp;r2=1.104" source="CONFIRM">http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&amp;r2=1.104</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24337" source="XF">bsd-pf-fragment-dos(24337)</ref>
      <ref url="http://www.osvdb.org/22732" source="OSVDB">22732</ref>
      <ref url="http://securitytracker.com/id?1015542" source="SECTRACK">1015542</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-004.txt.asc" source="NETBSD">NetBSD-SA2006-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
        <vers num="6.0" edition="release" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0382" published="2006-02-14" name="CVE-2006-0382" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0597" source="VUPEN">ADV-2006-0597</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Feb/msg00000.html" source="APPLE">APPLE-SA-2006-02-14</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24682" source="XF">macosx-system-call-dos(24682)</ref>
      <ref url="http://www.securityfocus.com/bid/16654" source="BID">16654</ref>
      <ref url="http://www.osvdb.org/23190" source="OSVDB">23190</ref>
      <ref url="http://securitytracker.com/id?1015634" source="SECTRACK">1015634</ref>
      <ref url="http://secunia.com/advisories/18907" source="SECUNIA">18907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0383" published="2006-03-02" name="CVE-2006-0383" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE">APPLE-SA-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25025" source="XF">macosx-vpn-dos(25025)</ref>
      <ref url="http://www.osvdb.org/23643" source="OSVDB">23643</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0384" published="2006-03-02" name="CVE-2006-0384" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE">APPLE-SA-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25021" source="XF">macosx-automount-execute-code(25021)</ref>
      <ref url="http://www.osvdb.org/23640" source="OSVDB">23640</ref>
      <ref url="http://securitytracker.com/id?1015709" source="SECTRACK">1015709</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0386" published="2006-03-03" name="CVE-2006-0386" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25024" source="XF">macosx-filevault-file-access(25024)</ref>
      <ref url="http://www.osvdb.org/23642" source="OSVDB">23642</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0387" published="2006-03-06" name="CVE-2006-0387" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/176732" source="CERT-VN">VU#176732</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1" adv="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25032" source="XF">macosx-safari-bo(25032)</ref>
      <ref url="http://securitytracker.com/id?1015713" source="SECTRACK">1015713</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0388" published="2006-03-03" name="CVE-2006-0388" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://securitytracker.com/id?1015713" source="SECTRACK" patch="1">1015713</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25038" source="XF">macosx-safari-http-redirect(25038)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN" adv="1">ADV-2006-0791</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0389" published="2006-03-03" name="CVE-2006-0389" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25040" source="XF">macosx-syndication-xss(25040)</ref>
      <ref url="http://www.osvdb.org/23649" source="OSVDB">23649</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0390" reject="1" published="2006-03-06" name="CVE-2006-0390" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4504.  Reason: This candidate is a duplicate of CVE-2005-4504.  Notes: All CVE users should reference CVE-2005-4504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0391" published="2006-03-03" name="CVE-2006-0391" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=399" source="IDEFENSE" patch="1" adv="1">20060302 Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID">16907</ref>
      <ref url="http://www.osvdb.org/23641" source="OSVDB">23641</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA">19064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25023" source="XF">macosx-bom-directory-traversal(25023)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.1" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0392" published="2006-08-02" name="CVE-2006-0392" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/527236" source="CERT-VN">VU#527236</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28142" source="XF">macosx-raw-image-bo(28142)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.osvdb.org/27739" source="OSVDB">27739</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0393" published="2006-08-02" name="CVE-2006-0393" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28147" source="XF">macosx-openssh-nonexistent-user-dos(28147)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.osvdb.org/27745" source="OSVDB">27745</ref>
      <ref url="http://securitytracker.com/id?1016672" source="SECTRACK">1016672</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0394" reject="1" published="2006-03-01" name="CVE-2006-0394" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0848.  Reason: This candidate is a duplicate of CVE-2006-0848.  Notes: All CVE users should reference CVE-2006-0848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0395" published="2006-08-04" name="CVE-2006-0395" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://lists.apple.com/archives/client-management/2006/Mar/msg00030.html" source="APPLE">APPLE-SA-2006-03-01</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25027" source="XF">macosx-mail-bypass-security(25027)</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID">16907</ref>
      <ref url="http://www.osvdb.org/23645" source="OSVDB">23645</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA">19064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0396" published="2006-03-14" name="CVE-2006-0396" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/980084" source="CERT-VN">VU#980084</ref>
      <ref url="http://www.securityfocus.com/bid/17081" source="BID" patch="1">17081</ref>
      <ref url="http://securitytracker.com/id?1015762" source="SECTRACK" patch="1">1015762</ref>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427601/100/0/threaded" source="BUGTRAQ" adv="1">20060314 DMA[2006-0313a] - 'Apple OSX Mail.app RFC1740 Real Name Buffer Overflow'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt" source="MISC" adv="1">http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25209" source="XF">macosx-mail-attachment-bo(25209)</ref>
      <ref url="http://www.osvdb.org/23872" source="OSVDB">23872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0397" published="2006-03-14" name="CVE-2006-0397" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript>
      <descript source="nvd">Per Hyperlink 894663:
Vendor description specifies that the file is automatically opened by the application: Safari could automatically open a file which appears to be a safe file type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25269" source="XF">macosx-safefiletype-command-execution(25269)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.osvdb.org/23869" source="OSVDB">23869</ref>
      <ref url="http://securitytracker.com/id?1015760" source="SECTRACK">1015760</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0398" published="2006-03-14" name="CVE-2006-0398" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript>
      <descript source="nvd">Hyperlink Record 894667 specifies: Safari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25269" source="XF">macosx-safefiletype-command-execution(25269)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.osvdb.org/23870" source="OSVDB">23870</ref>
      <ref url="http://securitytracker.com/id?1015760" source="SECTRACK">1015760</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0399" published="2006-03-14" name="CVE-2006-0399" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript>
      <descript source="nvd">Per Hyperlink Record 894671:
Safari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25269" source="XF">macosx-safefiletype-command-execution(25269)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.osvdb.org/23871" source="OSVDB">23871</ref>
      <ref url="http://securitytracker.com/id?1015760" source="SECTRACK">1015760</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0400" published="2006-03-14" name="CVE-2006-0400" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17082" source="BID" patch="1">17082</ref>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25208" source="XF">macosx-sameorigin-policy-bypass(25208)</ref>
      <ref url="http://www.osvdb.org/23873" source="OSVDB">23873</ref>
      <ref url="http://securitytracker.com/id?1015763" source="SECTRACK">1015763</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0401" published="2006-04-05" name="CVE-2006-0401" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in Single User Mode via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19462" source="SECUNIA" patch="1" adv="1">19462</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1215" source="VUPEN">ADV-2006-1215</ref>
      <ref url="http://www.securityfocus.com/bid/17364" source="BID">17364</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303567" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303567</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25620" source="XF">macosx-firmware-password-bypass(25620)</ref>
      <ref url="http://www.osvdb.org/24399" source="OSVDB">24399</ref>
      <ref url="http://securitytracker.com/id?1015859" source="SECTRACK">1015859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0402" published="2006-01-24" name="CVE-2006-0402" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24264" source="XF" patch="1">zoph-sql-injection(24264)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=69353&amp;release_id=387320" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=69353&amp;release_id=387320</ref>
      <ref url="http://secunia.com/advisories/18563" source="SECUNIA" patch="1" adv="1">18563</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0297" source="VUPEN">ADV-2006-0297</ref>
      <ref url="http://www.securityfocus.com/bid/16347" source="BID">16347</ref>
      <ref url="http://www.osvdb.org/22743" source="OSVDB">22743</ref>
      <ref url="http://www.debian.org/security/2006/dsa-989" source="DEBIAN">DSA-989</ref>
      <ref url="http://secunia.com/advisories/19153" source="SECUNIA">19153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_geiger" name="zoph">
        <vers num="0.3.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0403" published="2006-01-24" name="CVE-2006-0403" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the "monthly" parameter, but this is incorrect.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24245" source="XF">emoblog-index-sql-injection(24245)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0296" source="VUPEN" adv="1">ADV-2006-0296</ref>
      <ref url="http://www.securityfocus.com/bid/16344" source="BID">16344</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422938/100/0/threaded" source="BUGTRAQ">20060122 [eVuln] e-moBLOG SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22701" source="OSVDB">22701</ref>
      <ref url="http://www.osvdb.org/22700" source="OSVDB">22700</ref>
      <ref url="http://securitytracker.com/id?1015524" source="SECTRACK">1015524</ref>
      <ref url="http://securityreason.com/securityalert/370" source="SREASON">370</ref>
      <ref url="http://secunia.com/advisories/18567" source="SECUNIA" adv="1">18567</ref>
      <ref url="http://evuln.com/vulns/43/summary.html" source="MISC" adv="1">http://evuln.com/vulns/43/summary.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000511.html" source="VIM">20060125 The parameter in e-moBLOG is </ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-moblog" name="e-moblog">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0404" published="2006-01-24" name="CVE-2006-0404" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24270" source="XF">noteaday-archive-directory-insecure(24270)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24270" source="XF">noteaday-archive-information-disclosure(24270)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0299" source="VUPEN">ADV-2006-0299</ref>
      <ref url="http://secunia.com/advisories/18566" source="SECUNIA" adv="1">18566</ref>
      <ref url="http://evuln.com/vulns/44/summary.html" source="MISC" adv="1">http://evuln.com/vulns/44/summary.html</ref>
      <ref url="http://www.osvdb.org/22699" source="OSVDB">22699</ref>
      <ref url="http://securitytracker.com/id?1015539" source="SECTRACK">1015539</ref>
      <ref url="http://securityreason.com/securityalert/371" source="SREASON">371</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0389.html" source="BUGTRAQ">20060122 [eVuln] Note-A-Day Weblog Sensitive Information Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_macgirvin" name="note-a-day_weblog">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0405" published="2006-01-24" name="CVE-2006-0405" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField function.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24275" source="XF">libtiff-tiffvsetfield-dos(24275)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0302" source="VUPEN" adv="1">ADV-2006-0302</ref>
      <ref url="http://www.securityfocus.com/bid/18172" source="BID">18172</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml" source="GENTOO">GLSA-200605-17</ref>
      <ref url="http://secunia.com/advisories/20345" source="SECUNIA" adv="1">20345</ref>
      <ref url="http://secunia.com/advisories/18587" source="SECUNIA" adv="1">18587</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1034" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=1034</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1029" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=1029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0406" published="2006-01-24" name="CVE-2006-0406" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24272" source="XF">mybb-search-information-disclosure(24272)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422227/100/0/threaded" source="BUGTRAQ" adv="1">20060114 MyBB 1.0.2 Sniffing table perfix bug in search.php</ref>
      <ref url="http://www.osvdb.org/22736" source="OSVDB">22736</ref>
      <ref url="http://secunia.com/advisories/18577" source="SECUNIA" adv="1">18577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0407" published="2006-01-24" name="CVE-2006-0407" modified="2011-03-07" discovered="2006-01-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter.  NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24274" source="XF">azbulletinboard-post-xss(24274)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0298" source="VUPEN">ADV-2006-0298</ref>
      <ref url="http://www.securityfocus.com/bid/16351" source="BID">16351</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427194/100/0/threaded" source="BUGTRAQ">20060309 Re: Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427076/100/0/threaded" source="BUGTRAQ">20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting </ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423363/100/0/threaded" source="BUGTRAQ">20060128 [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423353/100/0/threaded" source="BUGTRAQ" adv="1">20060123 Azbb v1.1.00 Cross-Site Scripting</ref>
      <ref url="http://secunia.com/advisories/18565" source="SECUNIA" adv="1">18565</ref>
      <ref url="http://kapda.ir/advisory-236.html" source="MISC" adv="1">http://kapda.ir/advisory-236.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427076/30/6510/threaded" source="BUGTRAQ">20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azbb" name="az_bulletin_board">
        <vers num="1.0.0" />
        <vers num="1.0.0rc1" />
        <vers num="1.0.0rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0408" published="2006-01-24" name="CVE-2006-0408" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18580" source="SECUNIA" patch="1" adv="1">18580</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0308" source="VUPEN">ADV-2006-0308</ref>
      <ref url="http://gridengine.sunsource.net/project/gridengine/60patches.txt" source="CONFIRM">http://gridengine.sunsource.net/project/gridengine/60patches.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24281" source="XF">sge-rsh-gain-privileges(24281)</ref>
      <ref url="http://www.securityfocus.com/bid/16366" source="BID">16366</ref>
      <ref url="http://securitytracker.com/id?1015531" source="SECTRACK">1015531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="grid_engine">
        <vers num="6.0" edition="update1" />
        <vers num="6.0" edition="update2" />
        <vers num="6.0" edition="update3" />
        <vers num="6.0" edition="update4" />
        <vers num="6.0" edition="update5" />
        <vers num="6.0" edition="update6" />
        <vers num="6.0" edition="update7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0409" published="2006-01-24" name="CVE-2006-0409" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24261" source="XF">pixelpost-index-xss(24261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0309" source="VUPEN">ADV-2006-0309</ref>
      <ref url="http://www.securityfocus.com/bid/16362" source="BID">16362</ref>
      <ref url="http://secunia.com/advisories/18572" source="SECUNIA" adv="1">18572</ref>
      <ref url="http://evuln.com/vulns/45/summary.html" source="MISC" adv="1">http://evuln.com/vulns/45/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423384/100/0/threaded" source="BUGTRAQ">20060123 [eVuln] Pixelpost Photoblog XSS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015529" source="SECTRACK">1015529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelpost" name="photoblog">
        <vers num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0410" published="2006-01-24" name="CVE-2006-0410" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=387862&amp;group_id=42718" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=387862&amp;group_id=42718</ref>
      <ref url="http://secunia.com/advisories/18575" source="SECUNIA" patch="1" adv="1">18575</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24314" source="XF">adodb-postgresql-sql-injection(24314)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0448" source="VUPEN">ADV-2006-0448</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0315" source="VUPEN">ADV-2006-0315</ref>
      <ref url="http://www.securityfocus.com/bid/16364" source="BID">16364</ref>
      <ref url="http://www.osvdb.org/22705" source="OSVDB">22705</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO">GLSA-200604-07</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-02.xml" source="GENTOO">GLSA-200602-02</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN">DSA-1031</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN">DSA-1029</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA">19590</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA">19555</ref>
      <ref url="http://secunia.com/advisories/18745" source="SECUNIA">18745</ref>
      <ref url="http://secunia.com/advisories/18732" source="SECUNIA">18732</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA">19691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66" />
        <vers num="4.68" />
        <vers num="4.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0411" published="2006-01-25" name="CVE-2006-0411" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0320" source="VUPEN">ADV-2006-0320</ref>
      <ref url="http://www.securityfocus.com/bid/16341" source="BID">16341</ref>
      <ref url="http://www.securityfocus.com/archive/1/422482" source="BUGTRAQ">20060120 Claroline 1.7.2, sso identification vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24326" source="XF">claroline-cookie-bypass-security(24326)</ref>
      <ref url="http://secunia.com/advisories/18588" source="SECUNIA">18588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0412" published="2006-01-25" name="CVE-2006-0412" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24005" source="XF">cybershop-login-sql-injection(24005)</ref>
      <ref url="http://www.osvdb.org/22365" source="OSVDB">22365</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0064.html" source="BUGTRAQ">20060105 CyberShop User Login Sql Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gençbeyin_web_programlama" name="cybershop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0413" published="2006-01-25" name="CVE-2006-0413" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24320" source="XF">newsphp-index-sql-injection(24320)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0341" source="VUPEN" adv="1">ADV-2006-0341</ref>
      <ref url="http://www.securityfocus.com/bid/16339" source="BID">16339</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423129/100/0/threaded" source="BUGTRAQ">20060122 Newsphp Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22717" source="OSVDB">22717</ref>
      <ref url="http://secunia.com/advisories/18624" source="SECUNIA" adv="1">18624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsphp" name="newsphp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0414" published="2006-01-25" name="CVE-2006-0414" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18576" source="SECUNIA" patch="1" adv="1">18576</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2006/msg00001.html" source="CONFIRM" patch="1" adv="1">http://archives.seul.org/or/announce/Jan-2006/msg00001.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24285" source="XF">tor-service-information-disclosure(24285)</ref>
      <ref url="http://www.securityfocus.com/bid/18323" source="BID">18323</ref>
      <ref url="http://www.osvdb.org/22689" source="OSVDB">22689</ref>
      <ref url="http://tor.eff.org/cvs/tor/ChangeLog" source="CONFIRM">http://tor.eff.org/cvs/tor/ChangeLog</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200606-04.xml" source="GENTOO">GLSA-200606-04</ref>
      <ref url="http://secunia.com/advisories/20514" source="SECUNIA">20514</ref>
      <ref url="http://www.securityfocus.com/bid/19795" source="BID">19795</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2" />
        <vers num="0.0.2_pre13" />
        <vers num="0.0.2_pre14" />
        <vers num="0.0.2_pre15" />
        <vers num="0.0.2_pre16" />
        <vers num="0.0.2_pre17" />
        <vers num="0.0.2_pre18" />
        <vers num="0.0.2_pre19" />
        <vers num="0.0.2_pre20" />
        <vers num="0.0.2_pre21" />
        <vers num="0.0.2_pre22" />
        <vers num="0.0.2_pre23" />
        <vers num="0.0.2_pre24" />
        <vers num="0.0.2_pre25" />
        <vers num="0.0.2_pre26" />
        <vers num="0.0.2_pre27" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.6.1" />
        <vers num="0.0.6.2" />
        <vers num="0.0.7" />
        <vers num="0.0.7.1" />
        <vers num="0.0.7.2" />
        <vers num="0.0.7.3" />
        <vers num="0.0.8" />
        <vers num="0.0.8.1" />
        <vers num="0.0.9" />
        <vers num="0.0.9.1" />
        <vers num="0.0.9.10" />
        <vers num="0.0.9.2" />
        <vers num="0.0.9.3" />
        <vers num="0.0.9.4" />
        <vers num="0.0.9.5" />
        <vers num="0.0.9.6" />
        <vers num="0.0.9.7" />
        <vers num="0.0.9.8" />
        <vers num="0.0.9.9" />
        <vers num="0.1.0.10" />
        <vers num="0.1.0.11" />
        <vers num="0.1.0.12" />
        <vers num="0.1.0.13" />
        <vers num="0.1.0.14" />
        <vers num="0.1.0.15" />
        <vers num="0.1.0.16" />
        <vers num="0.1.0.17" />
        <vers num="0.1.1.10_alpha" />
        <vers num="0.1.1.1_alpha" />
        <vers num="0.1.1.2_alpha" />
        <vers num="0.1.1.3_alpha" />
        <vers num="0.1.1.4_alpha" />
        <vers num="0.1.1.5_alpha" />
        <vers num="0.1.1.6_alpha" />
        <vers num="0.1.1.7_alpha" />
        <vers num="0.1.1.8_alpha" />
        <vers num="0.1.1.9_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0415" published="2006-01-25" name="CVE-2006-0415" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16363" source="BID">16363</ref>
      <ref url="http://securitytracker.com/id?1015525" source="SECTRACK">1015525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24300" source="XF">sleeperchat-index-xss(24300)</ref>
      <ref url="http://www.osvdb.org/22784" source="OSVDB">22784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sleeperchat" name="sleeperchat">
        <vers prev="1" num="0.3f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0416" published="2006-01-25" name="CVE-2006-0416" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24357" source="XF">sleeperchat-txt-security-bypass(24357)</ref>
      <ref url="http://securitytracker.com/id?1015525" source="SECTRACK">1015525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sleeperchat" name="sleeperchat">
        <vers prev="1" num="0.3f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0417" published="2006-01-25" name="CVE-2006-0417" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0310" source="VUPEN">ADV-2006-0310</ref>
      <ref url="http://evuln.com/vulns/47/summary.html" source="MISC" adv="1">http://evuln.com/vulns/47/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24280" source="XF">minibloggie-login-sql-injection(24280)</ref>
      <ref url="http://www.securityfocus.com/bid/16367" source="BID">16367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423126/100/0/threaded" source="BUGTRAQ">20060124 [eVuln] miniBloggie Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22729" source="OSVDB">22729</ref>
      <ref url="http://securitytracker.com/id?1015534" source="SECTRACK">1015534</ref>
      <ref url="http://secunia.com/advisories/18604" source="SECUNIA">18604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="minibloggie">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0418" published="2006-01-25" name="CVE-2006-0418" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16360" source="BID" patch="1">16360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423164/100/0/threaded" source="BUGTRAQ" adv="1">20060124 [ISecAuditors Advisories] Arbitrary flash code remote execution in 123flashchat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="topcmm_computing" name="123_flash_chat_server">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0419" published="2006-01-25" name="CVE-2006-0419" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/163" source="BEA" adv="1">BEA06-81.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp6" />
        <vers num="7.0" edition="sp6:express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp5" />
        <vers num="8.1" edition="sp5:express" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0420" published="2006-01-25" name="CVE-2006-0420" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use relative forwarding, which allows remote attackers to cause a denial of service (slowdown) via unknown attack vectors that cause "looping stack overflow errors."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/164" source="BEA" patch="1" adv="1">BEA06-106.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp6" />
        <vers num="7.0" edition="sp6:express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0421" published="2006-01-25" name="CVE-2006-0421" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18581" source="SECUNIA" patch="1" adv="1">18581</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/165" source="BEA" patch="1" adv="1">BEA06-108.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24286" source="XF">weblogic-cross-domain-management(24286)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0422" published="2006-01-25" name="CVE-2006-0422" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/166" source="BEA" patch="1" adv="1">BEA06-109.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24294" source="XF">weblogic-java-mbean-access(24294)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp7" />
        <vers num="6.1" edition="sp7:express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp6" />
        <vers num="7.0" edition="sp6:express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0423" published="2006-01-25" name="CVE-2006-0423" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/167" source="BEA" patch="1" adv="1">BEA06-110.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40705" source="XF">weblogic-portal-config-info-disclosure(40705)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24284" source="XF">weblogicportal-config-info-disclosure(24284)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0613" source="VUPEN">ADV-2008-0613</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0312" source="VUPEN">ADV-2006-0312</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://secunia.com/advisories/18593" source="SECUNIA">18593</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/262" source="BEA">BEA08-110.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0424" published="2006-01-25" name="CVE-2006-0424" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/168" source="BEA" patch="1" adv="1">BEA06-111.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24295" source="XF">weblogic-server-log-disclosure(24295)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22776" source="OSVDB">22776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp7" />
        <vers num="6.1" edition="sp7:express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp6" />
        <vers num="7.0" edition="sp6:express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0425" published="2006-01-25" name="CVE-2006-0425" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/169" source="BEA" patch="1" adv="1">BEA06-112.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24297" source="XF">weblogic-deployment-descriptor-disclosure(24297)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0312" source="VUPEN">ADV-2006-0312</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://secunia.com/advisories/18593" source="SECUNIA">18593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0426" published="2006-01-25" name="CVE-2006-0426" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/170" source="BEA" patch="1" adv="1">BEA06-113.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24290" source="XF">weblogic-password-information-disclosure(24290)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22775" source="OSVDB">22775</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0427" published="2006-01-25" name="CVE-2006-0427" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/171" source="BEA" patch="1" adv="1">BEA06-114.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24291" source="XF">weblogic-servlets-obtain-information(24291)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22774" source="OSVDB">22774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp5" />
        <vers num="8.1" edition="sp5:express" />
        <vers num="9.0" edition="sp1" />
        <vers num="9.0" edition="sp1:express" />
        <vers num="9.0" edition="sp2" />
        <vers num="9.0" edition="sp2:express" />
        <vers num="9.0" edition="sp3" />
        <vers num="9.0" edition="sp3:express" />
        <vers num="9.0" edition="sp4" />
        <vers num="9.0" edition="sp4:express" />
        <vers num="9.0" edition="sp5" />
        <vers num="9.0" edition="sp5:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0428" published="2006-01-25" name="CVE-2006-0428" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/172" source="BEA" patch="1" adv="1">BEA06-115.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24293" source="XF">weblogic-wsrp-gain-access(24293)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0312" source="VUPEN">ADV-2006-0312</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22767" source="OSVDB">22767</ref>
      <ref url="http://secunia.com/advisories/18593" source="SECUNIA">18593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0429" published="2006-01-25" name="CVE-2006-0429" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/173" source="BEA" patch="1" adv="1">BEA06-116.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24298" source="XF">weblogic-security-provider-weakness(24298)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22773" source="OSVDB">22773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0430" published="2006-01-25" name="CVE-2006-0430" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/174" source="BEA" patch="1" adv="1">BEA06-117.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24301" source="XF">weblogic-connection-filter-dos(24301)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp6" />
        <vers num="7.0" edition="sp6:express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="9.0" edition="sp1" />
        <vers num="9.0" edition="sp1:express" />
        <vers num="9.0" edition="sp2" />
        <vers num="9.0" edition="sp2:express" />
        <vers num="9.0" edition="sp3" />
        <vers num="9.0" edition="sp3:express" />
        <vers num="9.0" edition="sp4" />
        <vers num="9.0" edition="sp4:express" />
        <vers num="9.0" edition="sp5" />
        <vers num="9.0" edition="sp5:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0431" published="2006-01-25" name="CVE-2006-0431" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server's SSL identity via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/175" source="BEA" patch="1" adv="1">BEA06-118.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24302" source="XF">weblogic-ssl-identity-exposure(24302)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp5" />
        <vers num="8.1" edition="sp5:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0432" published="2006-01-25" name="CVE-2006-0432" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/176" source="BEA" patch="1" adv="1">BEA06-119.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24299" source="XF">weblogic-jdni-security-weakness(24299)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0433" published="2006-02-02" name="CVE-2006-0433" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22861" source="OSVDB" patch="1">22861</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0409" source="VUPEN">ADV-2006-0409</ref>
      <ref url="http://www.securityfocus.com/bid/16466" source="BID">16466</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:08.sack.asc" source="FREEBSD">FreeBSD-SA-06:08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24453" source="XF">bsd-sack-handling-dos(24453)</ref>
      <ref url="http://securitytracker.com/id?1015566" source="SECTRACK">1015566</ref>
      <ref url="http://securityreason.com/securityalert/399" source="SREASON">399</ref>
      <ref url="http://secunia.com/advisories/18696" source="SECUNIA">18696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0434" published="2006-01-26" name="CVE-2006-0434" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244.  NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422434/100/0/threaded" source="BUGTRAQ">20060118 phpXplorer file inclusion biyosecurity.be</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39982" source="XF">phpxplorer-sshare-directory-traversal(39982)</ref>
      <ref url="http://www.securityfocus.com/bid/16292" source="BID">16292</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0435" published="2006-01-26" name="CVE-2006-0435" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/169164" source="CERT-VN">VU#169164</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423029/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060125 Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24363" source="XF">oracle-plsql-command-execution(24363)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0338" source="VUPEN" adv="1">ADV-2006-0338</ref>
      <ref url="http://www.securityfocus.com/bid/16384" source="BID">16384</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424394/100/0/threaded" source="BUGTRAQ">20060208 Re: Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423822/100/0/threaded" source="BUGTRAQ">20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423819/100/0/threaded" source="BUGTRAQ">20060202 The History of the Oracle PLSQL Gateway Flaw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423673/100/0/threaded" source="BUGTRAQ">20060131 Re: Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://www.osvdb.org/22719" source="OSVDB">22719</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html" source="MISC">http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015544" source="SECTRACK">1015544</ref>
      <ref url="http://securityreason.com/securityalert/403" source="SREASON">403</ref>
      <ref url="http://securityreason.com/securityalert/402" source="SREASON">402</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
      <ref url="http://secunia.com/advisories/18621" source="SECUNIA">18621</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041742.html" source="FULLDISC">20060125 Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041899.html" source="FULLDISC">20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041898.html" source="FULLDISC">20060202 The History of the Oracle PLSQL Gateway Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2" />
        <vers num="1.0.2.0" />
        <vers num="1.0.2.1" />
        <vers num="1.0.2.1s" />
        <vers num="1.0.2.2" />
        <vers num="1.0.2.2.2" />
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
        <vers num="10.1.0.4" />
        <vers num="10.1.2" />
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.1.0" />
        <vers num="10.1.2_.0.1" />
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
        <vers num="9.0.4.2" />
        <vers num="9.2.0.6" />
        <vers num="9.2.0.7" />
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="1.0.2.0" />
        <vers num="1.0.2.1" />
        <vers num="1.0.2.1s_for_apps" />
        <vers num="1.0.2.2" />
        <vers num="1.0.2.2_roll_up_2" />
        <vers num="8.1.7" />
        <vers num="9.0.1" />
        <vers num="9.0.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3.1" />
        <vers num="9.1" />
        <vers num="9.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0436" published="2006-01-26" name="CVE-2006-0436" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015530" source="SECTRACK" patch="1">1015530</ref>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00591401" source="HP">HPSBUX02091</ref>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00591401" source="HP">SSRT061099</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0322" source="VUPEN">ADV-2006-0322</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24318" source="XF">hpux-unspecified-privilege-escalation(24318)</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm</ref>
      <ref url="http://secunia.com/advisories/18600" source="SECUNIA">18600</ref>
      <ref url="http://secunia.com/advisories/18596" source="SECUNIA">18596</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1586" source="OVAL" sig="1">oval:org.mitre.oval:def:1586</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1577" source="OVAL" sig="1">oval:org.mitre.oval:def:1577</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1453" source="OVAL" sig="1">oval:org.mitre.oval:def:1453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0437" published="2006-02-06" name="CVE-2006-0437" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "&lt;" and ">" characters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24497" source="XF">phpbb-referer-header-http-xss(24497)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0445" source="VUPEN">ADV-2006-0445</ref>
      <ref url="http://www.osvdb.org/22928" source="OSVDB">22928</ref>
      <ref url="http://securityreason.com/achievement_securityalert/31" source="SREASONRES">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
      <ref url="http://secunia.com/advisories/18693" source="SECUNIA" adv="1">18693</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html" source="FULLDISC">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
      <ref url="http://securityreason.com/securityalert/406" source="SREASON">406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0438" published="2006-02-06" name="CVE-2006-0438" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0445" source="VUPEN">ADV-2006-0445</ref>
      <ref url="http://securityreason.com/achievement_securityalert/31" source="SREASONRES">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
      <ref url="http://secunia.com/advisories/18693" source="SECUNIA" adv="1">18693</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24497" source="XF">phpbb-referer-header-http-xss(24497)</ref>
      <ref url="http://www.osvdb.org/22929" source="OSVDB">22929</ref>
      <ref url="http://securityreason.com/securityalert/406" source="SREASON">406</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html" source="FULLDISC">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0439" published="2006-01-26" name="CVE-2006-0439" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24279" source="XF">textrider-data-information-disclosure(24279)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0321" source="VUPEN">ADV-2006-0321</ref>
      <ref url="http://secunia.com/advisories/18605" source="SECUNIA" adv="1">18605</ref>
      <ref url="http://evuln.com/vulns/46/summary.html" source="MISC" adv="1">http://evuln.com/vulns/46/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423130/100/0/threaded" source="BUGTRAQ">20060124 [eVuln] Text Rider Sensitive Information Disclosure</ref>
      <ref url="http://securitytracker.com/id?1015533" source="SECTRACK">1015533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text_rider" name="text_rider">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0440" published="2006-01-26" name="CVE-2006-0440" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://evuln.com/vulns/46/summary.html" source="MISC" adv="1">http://evuln.com/vulns/46/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423130/100/0/threaded" source="BUGTRAQ">20060124 [eVuln] Text Rider Sensitive Information Disclosure</ref>
      <ref url="http://securitytracker.com/id?1015533" source="SECTRACK">1015533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text_rider" name="text_rider">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0441" published="2006-01-26" name="CVE-2006-0441" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER command, which triggers the overflow when the log is viewed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0317" source="VUPEN">ADV-2006-0317</ref>
      <ref url="http://www.securityfocus.com/bid/16370" source="BID">16370</ref>
      <ref url="http://www.critical.lt/?vulnerabilities/208" source="MISC" adv="1">http://www.critical.lt/?vulnerabilities/208</ref>
      <ref url="http://secunia.com/advisories/18574" source="SECUNIA" adv="1">18574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24325" source="XF">samiftpserver-user-bo(24325)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423148/100/0/threaded" source="BUGTRAQ">20060124 SamiFTPd buffer overflow</ref>
      <ref url="http://www.karjasoft.com/samiftp/news" source="CONFIRM">http://www.karjasoft.com/samiftp/news</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_ftp_server">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0442" published="2006-01-26" name="CVE-2006-0442" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in a editsig action.  NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0316" source="VUPEN">ADV-2006-0316</ref>
      <ref url="http://www.securityfocus.com/bid/16361" source="BID">16361</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423128/100/0/threaded" source="BUGTRAQ">20060124 [KAPDA::#25] - MyBB 1.x Cross_Site_Scripting</ref>
      <ref url="http://securitytracker.com/id?1015535" source="SECTRACK">1015535</ref>
      <ref url="http://secunia.com/advisories/18603" source="SECUNIA" adv="1">18603</ref>
      <ref url="http://kapda.ir/advisory-241.html" source="MISC" adv="1">http://kapda.ir/advisory-241.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0443" published="2006-01-26" name="CVE-2006-0443" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0326" source="VUPEN">ADV-2006-0326</ref>
      <ref url="http://www.securityfocus.com/bid/16376" source="BID">16376</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423023/100/0/threaded" source="BUGTRAQ" adv="1">20060125 [eVuln] CheesyBlog XSS Vulnerability</ref>
      <ref url="http://evuln.com/vulns/49/summary.html" source="MISC" adv="1">http://evuln.com/vulns/49/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24292" source="XF">cheesyblog-archive-xss(24292)</ref>
      <ref url="http://www.osvdb.org/22716" source="OSVDB">22716</ref>
      <ref url="http://securityreason.com/securityalert/369" source="SREASON">369</ref>
      <ref url="http://secunia.com/advisories/18610" source="SECUNIA">18610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cheesyblog" name="cheesyblog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0444" published="2006-01-26" name="CVE-2006-0444" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page.  NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.</descript>
    </desc>
    <sols>
      <sol source="nvd">A simple fix has been released on the Main PCW site available directly at &lt;a href="http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1">http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1&lt;/a>
Please download and install imediately.
Tech note: Filters id number (par) to contain numbers only.
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16391" source="BID" patch="1">16391</ref>
      <ref url="http://secunia.com/advisories/18597" source="SECUNIA" patch="1" adv="1">18597</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0342" source="VUPEN">ADV-2006-0342</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423145/100/0/threaded" source="BUGTRAQ" adv="1">20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22722" source="OSVDB">22722</ref>
      <ref url="http://www.osvdb.org/22720" source="OSVDB">22720</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24355" source="XF">phpclanwebsite-index-sql-injection(24355)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpclanwebsite" name="phpclanwebsite">
        <vers num="1.23.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0445" published="2006-01-26" name="CVE-2006-0445" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display the full path of uploader.php.  NOTE: this might be the result of a file inclusion vulnerability.</descript>
    </desc>
    <sols>
      <sol source="nvd">Please add the following to the config.php file to avoid all such exploits.

ini_set('display_errors', false);
</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16391" source="BID">16391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423145/100/0/threaded" source="BUGTRAQ" adv="1">20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22721" source="OSVDB">22721</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpclanwebsite" name="phpclanwebsite">
        <vers num="1.23.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0446" published="2006-01-26" name="CVE-2006-0446" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privilged attackers to execute arbitrary commands as the web server via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18594" source="SECUNIA" patch="1" adv="1">18594</ref>
      <ref url="http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4" source="CONFIRM" patch="1">http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0319" source="VUPEN">ADV-2006-0319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24322" source="XF">webwork-unknown-command-execution(24322)</ref>
      <ref url="http://www.securityfocus.com/bid/16371" source="BID">16371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwork" name="webwork">
        <vers num="2.1.3" />
        <vers num="2.2-pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0447" published="2006-01-26" name="CVE-2006-0447" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3 command, which is not properly handled by (c) EPSTPOP4S.EXE or (d) SPA-POP3S.EXE; (4) a long IMAP DELETE command, which is not properly handled by (e) EPSTIMAP4S.EXE or (f) SPA-IMAP4S.EXE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2006-1/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-1/advisory/</ref>
      <ref url="http://secunia.com/advisories/18480" source="SECUNIA" patch="1" adv="1">18480</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0318" source="VUPEN">ADV-2006-0318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24334" source="XF">epost-imap-mailbox-dos(24334)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24333" source="XF">epost-pop3-username-bo(24333)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24331" source="XF">epost-smtp-username-bo(24331)</ref>
      <ref url="http://www.securityfocus.com/bid/16379" source="BID">16379</ref>
      <ref url="http://www.osvdb.org/22763" source="OSVDB">22763</ref>
      <ref url="http://www.osvdb.org/22762" source="OSVDB">22762</ref>
      <ref url="http://www.osvdb.org/22761" source="OSVDB">22761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="mail_server">
        <vers num="4.10" />
        <vers num="enterprise_4.10" />
      </prod>
      <prod vendor="e-post_corporation" name="smtp_server">
        <vers num="4.10" />
        <vers num="enterprise_4.10" />
      </prod>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.00" />
        <vers num="enterprise_4.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0448" published="2006-01-26" name="CVE-2006-0448" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command; or create arbitrary files via the (b) APPEND, (c) COPY, or (d) RENAME commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2006-1/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-1/advisory/</ref>
      <ref url="http://secunia.com/advisories/18480" source="SECUNIA" patch="1" adv="1">18480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24336" source="XF">epost--append-copy-rename-file-creation(24336)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0318" source="VUPEN">ADV-2006-0318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24336" source="XF">epost--append-copy-rename-file-creation(24336)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24335" source="XF">epost-imap-list-directory-traversal(24335)</ref>
      <ref url="http://www.securityfocus.com/bid/16379" source="BID">16379</ref>
      <ref url="http://www.osvdb.org/22765" source="OSVDB">22765</ref>
      <ref url="http://www.osvdb.org/22764" source="OSVDB">22764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="mail_server">
        <vers num="4.05" />
      </prod>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0449" published="2006-01-26" name="CVE-2006-0449" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2006-1/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-1/advisory/</ref>
      <ref url="http://secunia.com/advisories/18480" source="SECUNIA" patch="1" adv="1">18480</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0318" source="VUPEN">ADV-2006-0318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24341" source="XF">epost-imap-append-dos(24341)</ref>
      <ref url="http://www.securityfocus.com/bid/16379" source="BID">16379</ref>
      <ref url="http://www.osvdb.org/22766" source="OSVDB">22766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="mail_server">
        <vers num="4.05" />
      </prod>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0450" published="2006-01-26" name="CVE-2006-0450" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423030/100/0/threaded" source="BUGTRAQ" adv="1">20060125 HYSA-2006-001 phpBB 2.0.19 search.php and profile.php DOS Vulnerability</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt</ref>
      <ref url="http://h4cky0u.org/viewtopic.php?t=637" source="MISC">http://h4cky0u.org/viewtopic.php?t=637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24327" source="XF">phpbb-search-profile-dos(24327)</ref>
      <ref url="http://securityreason.com/securityalert/368" source="SREASON">368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0451" published="2006-02-14" name="CVE-2006-0451" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24794" source="XF">fedora-ber-memory-leak-dos(24794)</ref>
      <ref url="http://www.securityfocus.com/bid/16677" source="BID">16677</ref>
      <ref url="http://secunia.com/advisories/18960" source="SECUNIA">18960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="fedora_core">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":directory_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0452" published="2006-02-14" name="CVE-2006-0452" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24796" source="XF">fedora-dn2ancestor-dos(24796)</ref>
      <ref url="http://www.securityfocus.com/bid/16677" source="BID">16677</ref>
      <ref url="http://secunia.com/advisories/18960" source="SECUNIA">18960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="fedora_core">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":directory_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0453" published="2006-02-14" name="CVE-2006-0453" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24795" source="XF">fedora-ber-bad-sequence-dos(24795)</ref>
      <ref url="http://www.securityfocus.com/bid/16677" source="BID">16677</ref>
      <ref url="http://secunia.com/advisories/18960" source="SECUNIA">18960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="fedora_core">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":directory_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0454" published="2006-02-07" name="CVE-2006-0454" modified="2011-10-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16532" source="BID" patch="1">16532</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded" source="FEDORA" patch="1" adv="1">FLSA:157459-4</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html" source="FEDORA" patch="1" adv="1">FEDORA-2006-102</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_06_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:006</ref>
      <ref url="http://secunia.com/advisories/18861" source="SECUNIA" patch="1" adv="1">18861</ref>
      <ref url="http://secunia.com/advisories/18788" source="SECUNIA" patch="1" adv="1">18788</ref>
      <ref url="http://secunia.com/advisories/18784" source="SECUNIA" patch="1" adv="1">18784</ref>
      <ref url="http://secunia.com/advisories/18774" source="SECUNIA" patch="1" adv="1">18774</ref>
      <ref url="http://secunia.com/advisories/18766" source="SECUNIA" patch="1" adv="1">18766</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002909.html" source="MLIST" patch="1">[dailydave] 20060207 Fun with Linux (2.6.12 -> 2.6.15.2)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24575" source="XF">kernel-icmp-ipoptionsecho-dos(24575)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0464" source="VUPEN" adv="1">ADV-2006-0464</ref>
      <ref url="http://www.ubuntu.com/usn/usn-250-1" source="UBUNTU">USN-250-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0006" source="TRUSTIX" adv="1">2006-0006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040" source="MANDRIVA">MDKSA-2006:040</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113927648820694&amp;w=2" source="MLIST">[linux-kernel] 20060207 Re: Linux 2.6.15.3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113927617401569&amp;w=2" source="MLIST">[linux-kernel] 20060207 Linux 2.6.15.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0455" published="2006-02-15" name="CVE-2006-0455" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded.  Note: this also occurs when running the equivalent command "gpg --verify".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us.debian.org/security/2006/dsa-978" source="DEBIAN" patch="1" adv="1">DSA-978</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477" source="SLACKWARE" patch="1">SSA:2006-072-02</ref>
      <ref url="http://www.securityfocus.com/bid/16663" source="BID" patch="1">16663</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_09_gpg.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:009</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-10</ref>
      <ref url="http://secunia.com/advisories/18968" source="SECUNIA" patch="1" adv="1">18968</ref>
      <ref url="http://secunia.com/advisories/18956" source="SECUNIA" patch="1" adv="1">18956</ref>
      <ref url="http://secunia.com/advisories/18955" source="SECUNIA" patch="1" adv="1">18955</ref>
      <ref url="http://secunia.com/advisories/18942" source="SECUNIA" patch="1" adv="1">18942</ref>
      <ref url="http://secunia.com/advisories/18934" source="SECUNIA" patch="1" adv="1">18934</ref>
      <ref url="http://secunia.com/advisories/18933" source="SECUNIA" patch="1" adv="1">18933</ref>
      <ref url="http://marc.theaimsgroup.com/?l=gnupg-devel&amp;m=113999098729114&amp;w=2" source="MLIST" patch="1" adv="1">[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24744" source="XF">gnupg-gpgv-improper-verification(24744)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0610" source="VUPEN" adv="1">ADV-2006-0610</ref>
      <ref url="http://www.ubuntu.com/usn/usn-252-1" source="UBUNTU">USN-252-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0008" source="TRUSTIX">2006-0008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded" source="FEDORA">FLSA-2006:185355</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425289/100/0/threaded" source="BUGTRAQ">20060215 False positive signature verification in GnuPG</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0266.html" source="REDHAT">RHSA-2006:0266</ref>
      <ref url="http://www.osvdb.org/23221" source="OSVDB">23221</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.001-gnupg.html" source="OPENPKG" adv="1">OpenPKG-SA-2006.001</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_13_gpg.html" source="SUSE">SUSE-SA:2006:013</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:043" source="MANDRIVA">MDKSA-2006:043</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA" adv="1">19532</ref>
      <ref url="http://secunia.com/advisories/19249" source="SECUNIA" adv="1">19249</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA" adv="1">19130</ref>
      <ref url="http://secunia.com/advisories/18845" source="SECUNIA" adv="1">18845</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10084" source="OVAL">oval:org.mitre.oval:def:10084</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000211.html" source="MLIST">[gnupg-announce] 20060215 False positive signature verification in GnuPG</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2006-116.shtml" source="FEDORA">FEDORA-2006-116</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3b" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0456" published="2006-06-27" name="CVE-2006-0456" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html" source="CONFIRM">http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9909" source="OVAL">oval:org.mitre.oval:def:9909</ref>
      <ref url="http://www.securityfocus.com/bid/18687" source="BID">18687</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0457" published="2006-03-13" name="CVE-2006-0457" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="4.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1" source="UBUNTU" adv="1">USN-263-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9566" source="OVAL">oval:org.mitre.oval:def:9566</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25354" source="XF">kernel-addkey-dos(25354)</ref>
      <ref url="http://www.securityfocus.com/bid/17084" source="BID">17084</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.osvdb.org/23894" source="OSVDB">23894</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19220" source="SECUNIA">19220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0458" published="2006-03-06" name="CVE-2006-0458" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributions, allows remote attackers to cause a denial of service (application crash) via certain crafted arguments in a DCC command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19090" source="SECUNIA" patch="1" adv="1">19090</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-259-1" source="UBUNTU" adv="1">USN-259-1</ref>
      <ref url="http://www.securityfocus.com/bid/16913" source="BID">16913</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25147" source="XF">irssi-dcc-accept-dos(25147)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irssi" name="irssi">
        <vers num="0.8.10rc5" />
        <vers num="0.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0459" published="2006-03-29" name="CVE-2006-0459" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24995" source="XF" patch="1">flex-bypass-security(24995)</ref>
      <ref url="http://www.us.debian.org/security/2006/dsa-1020" source="DEBIAN" patch="1" adv="1">DSA-1020</ref>
      <ref url="http://www.securityfocus.com/bid/16896" source="BID" patch="1">16896</ref>
      <ref url="http://www.osvdb.org/23440" source="OSVDB" patch="1">23440</ref>
      <ref url="http://secunia.com/advisories/19424" source="SECUNIA" patch="1" adv="1">19424</ref>
      <ref url="http://secunia.com/advisories/19071" source="SECUNIA" patch="1" adv="1">19071</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0770" source="VUPEN">ADV-2006-0770</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-260-1" source="UBUNTU">USN-260-1</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml" source="GENTOO">GLSA-200603-07</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&amp;forum_name=flex-announce" source="MLIST">[flex-announce] 20060222 flex 2.5.33 released</ref>
      <ref url="http://securityreason.com/securityalert/570" source="SREASON">570</ref>
      <ref url="http://secunia.com/advisories/19228" source="SECUNIA" adv="1">19228</ref>
      <ref url="http://secunia.com/advisories/19126" source="SECUNIA" adv="1">19126</ref>
      <ref url="http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download" source="CONFIRM">http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download</ref>
    </refs>
    <vuln_soft>
      <prod vendor="will_estes_and_john_millaway" name="flex">
        <vers num="2.5.30" />
        <vers prev="1" num="2.5.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0460" published="2006-02-16" name="CVE-2006-0460" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-09.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-09</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0643" source="VUPEN">ADV-2006-0643</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24764" source="XF">bomberclone-error-message-bo(24764)</ref>
      <ref url="http://www.securityfocus.com/bid/16697" source="BID">16697</ref>
      <ref url="http://www.osvdb.org/23263" source="OSVDB">23263</ref>
      <ref url="http://www.debian.org/security/2006/dsa-997" source="DEBIAN">DSA-997</ref>
      <ref url="http://secunia.com/advisories/19210" source="SECUNIA">19210</ref>
      <ref url="http://secunia.com/advisories/18915" source="SECUNIA">18915</ref>
      <ref url="http://secunia.com/advisories/18914" source="SECUNIA">18914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bomberclone" name="bomberclone">
        <vers num="0.1" />
        <vers num="0.10.0" />
        <vers num="0.11.3" />
        <vers num="0.11.4" />
        <vers num="0.11.5" />
        <vers num="0.11.6" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0461" published="2006-01-27" name="CVE-2006-0461" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://evuln.com/vulns/48/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/48/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0325" source="VUPEN">ADV-2006-0325</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24296" source="XF">expressionengine-coreinput-xss(24296)</ref>
      <ref url="http://www.securityfocus.com/bid/16377" source="BID">16377</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423068/100/0/threaded" source="BUGTRAQ">20060125 [eVuln] ExpressionEngine 'Referer' XSS Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/372" source="SREASON">372</ref>
      <ref url="http://secunia.com/advisories/18602" source="SECUNIA">18602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmachine" name="expressionengine">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0462" published="2006-01-27" name="CVE-2006-0462" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0327" source="VUPEN">ADV-2006-0327</ref>
      <ref url="http://evuln.com/vulns/50/summary.html" source="MISC" adv="1">http://evuln.com/vulns/50/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24309" source="XF">andonetblog-index-sql-injection(24309)</ref>
      <ref url="http://www.securityfocus.com/bid/16393" source="BID">16393</ref>
      <ref url="http://www.securityfocus.com/archive/1/423162" source="BUGTRAQ">20060126 [eVuln] AndoNET Blog SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22755" source="OSVDB">22755</ref>
      <ref url="http://securityreason.com/securityalert/377" source="SREASON">377</ref>
      <ref url="http://secunia.com/advisories/18633" source="SECUNIA">18633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andonet" name="andonet_blog">
        <vers num="2004.09.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0463" published="2006-01-27" name="CVE-2006-0463" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22713" source="OSVDB">22713</ref>
      <ref url="http://www.osvdb.org/22712" source="OSVDB">22712</ref>
      <ref url="http://osvdb.org/ref/22/22712-ideocontent.txt" source="MISC">http://osvdb.org/ref/22/22712-ideocontent.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ideosoft_design" name="ideocontent_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0464" published="2006-01-27" name="CVE-2006-0464" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22714" source="OSVDB">22714</ref>
      <ref url="http://osvdb.org/ref/22/22712-ideocontent.txt" source="MISC">http://osvdb.org/ref/22/22712-ideocontent.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ideosoft_design" name="ideocontent_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0465" published="2006-01-27" name="CVE-2006-0465" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in risultati_ricerca.php in active121 Site Manager allows remote attackers to inject arbitrary web script or HTML via the cerca parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22715" source="OSVDB">22715</ref>
      <ref url="http://osvdb.org/ref/22/22715-active121.txt" source="MISC">http://osvdb.org/ref/22/22715-active121.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active121" name="site_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0466" published="2006-01-27" name="CVE-2006-0466" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22711" source="OSVDB">22711</ref>
      <ref url="http://osvdb.org/ref/22/22711-goldstag.txt" source="MISC">http://osvdb.org/ref/22/22711-goldstag.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25198" source="XF">goldstag-search-xss(25198)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goldstag" name="goldstag_content_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0467" published="2006-01-30" name="CVE-2006-0467" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Pioneers (formerly gnocatan) before 0.9.49 allows remote attackers to cause a denial of service (application crash) via long chat messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24383" source="XF" patch="1">pioneers-chat-message-dos(24383)</ref>
      <ref url="http://www.debian.org/security/2006/dsa-964" source="DEBIAN" patch="1" adv="1">DSA-964</ref>
      <ref url="http://secunia.com/advisories/18692" source="SECUNIA" patch="1" adv="1">18692</ref>
      <ref url="http://secunia.com/advisories/18647" source="SECUNIA" patch="1" adv="1">18647</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0376" source="VUPEN" adv="1">ADV-2006-0376</ref>
      <ref url="http://www.securityfocus.com/bid/16429" source="BID">16429</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pioneers" name="pioneers">
        <vers num="0.9.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0468" published="2006-01-30" name="CVE-2006-0468" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16407" source="BID" patch="1">16407</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423364/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060128 Multiple vulnerabilities in CommuniGate Pro Server</ref>
      <ref url="http://www.gleg.net/advisory_cg.shtml" source="MISC" patch="1" adv="1">http://www.gleg.net/advisory_cg.shtml</ref>
      <ref url="http://secunia.com/advisories/18640" source="SECUNIA" patch="1" adv="1">18640</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0364" source="VUPEN">ADV-2006-0364</ref>
      <ref url="http://www.stalker.com/CommuniGatePro/History.html" source="CONFIRM">http://www.stalker.com/CommuniGatePro/History.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24409" source="XF">communigate-ldap-bo(24409)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0c1" />
        <vers num="5.0c2" />
        <vers num="5.0c3" />
        <vers num="5.0c4" />
        <vers num="5.0c5" />
        <vers num="5.0c6" />
        <vers num="5.0c7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0469" published="2006-01-30" name="CVE-2006-0469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24375" source="XF">uebimiau-html-xss(24375)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0388" source="VUPEN">ADV-2006-0388</ref>
      <ref url="http://www.uebimiau.org/news.php" source="CONFIRM">http://www.uebimiau.org/news.php</ref>
      <ref url="http://www.securityfocus.com/bid/16413" source="BID">16413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423437/100/0/threaded" source="BUGTRAQ">20060129 UebiMiau Webmail System Security Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18655" source="SECUNIA">18655</ref>
      <ref url="http://securityreason.com/securityalert/387" source="SREASON">387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uebimiau" name="uebimiau">
        <vers num="2.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0470" published="2006-01-31" name="CVE-2006-0470" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0350" source="VUPEN">ADV-2006-0350</ref>
      <ref url="http://www.securityfocus.com/bid/16387" source="BID">16387</ref>
      <ref url="http://www.osvdb.org/22750" source="OSVDB">22750</ref>
      <ref url="http://secunia.com/advisories/18617" source="SECUNIA" adv="1">18617</ref>
      <ref url="http://seclists.org/lists/bugtraq/2006/Jan/0414.html" source="BUGTRAQ" adv="1">20060125 MyBB 1.0.2 XSS attack in search.php redirection</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=6418" source="CONFIRM">http://community.mybboard.net/showthread.php?tid=6418</ref>
      <ref url="http://community.mybboard.net/attachment.php?aid=2181" source="CONFIRM">http://community.mybboard.net/attachment.php?aid=2181</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24466" source="XF">mybb-search-xss(24466)</ref>
      <ref url="http://securityreason.com/securityalert/374" source="SREASON">374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="1.0_preview_release_2" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0471" published="2006-01-31" name="CVE-2006-0471" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24310" source="XF">mylittlehomepage-link-tag-xss(24310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0349" source="VUPEN">ADV-2006-0349</ref>
      <ref url="http://www.securityfocus.com/bid/16395" source="BID">16395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded" source="BUGTRAQ" adv="1">20060126 [eVuln] "my little homepage" products [link] BBCode XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18628" source="SECUNIA" adv="1">18628</ref>
      <ref url="http://evuln.com/vulns/51/summary.html" source="MISC" adv="1">http://evuln.com/vulns/51/summary.html</ref>
      <ref url="http://www.osvdb.org/22856" source="OSVDB">22856</ref>
      <ref url="http://evuln.com/vulns/51/" source="MISC">http://evuln.com/vulns/51/</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000520.html" source="VIM">20060130 My Little Homepage - source verify of different products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_little_homepage" name="my_little_forum">
        <vers num="2004-04-20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0472" published="2006-01-31" name="CVE-2006-0472" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24310" source="XF">mylittlehomepage-link-tag-xss(24310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0349" source="VUPEN">ADV-2006-0349</ref>
      <ref url="http://www.securityfocus.com/bid/16395" source="BID">16395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded" source="BUGTRAQ" adv="1">20060126 [eVuln] "my little homepage" products [link] BBCode XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18628" source="SECUNIA" adv="1">18628</ref>
      <ref url="http://evuln.com/vulns/51/summary.html" source="MISC" adv="1">http://evuln.com/vulns/51/summary.html</ref>
      <ref url="http://www.osvdb.org/22855" source="OSVDB">22855</ref>
      <ref url="http://evuln.com/vulns/51/" source="MISC">http://evuln.com/vulns/51/</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000520.html" source="VIM">20060130 My Little Homepage - source verify of different products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_little_homepage" name="my_little_guestbook">
        <vers num="2004-04-20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0473" published="2006-01-31" name="CVE-2006-0473" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24310" source="XF">mylittlehomepage-link-tag-xss(24310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0349" source="VUPEN">ADV-2006-0349</ref>
      <ref url="http://www.securityfocus.com/bid/16395" source="BID">16395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded" source="BUGTRAQ" adv="1">20060126 [eVuln] "my little homepage" products [link] BBCode XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18628" source="SECUNIA" adv="1">18628</ref>
      <ref url="http://evuln.com/vulns/51/summary.html" source="MISC" adv="1">http://evuln.com/vulns/51/summary.html</ref>
      <ref url="http://www.osvdb.org/22753" source="OSVDB">22753</ref>
      <ref url="http://securityreason.com/securityalert/378" source="SREASON">378</ref>
      <ref url="http://evuln.com/vulns/51/" source="MISC">http://evuln.com/vulns/51/</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000520.html" source="VIM">20060130 My Little Homepage - source verify of different products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_little_homepage" name="my_little_weblog">
        <vers num="2004-04-20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0474" published="2006-01-31" name="CVE-2006-0474" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in Shareaza 2.2.1.0 allow remote attackers to execute arbitrary code via (1) a large packet length field, which causes an overflow in the ReadBuffer function in (a) BTPacket.cpp and (b) EDPacket.cpp, or (2) a large packet, which causes a heap-based overflow in the Write function in (c) Packet.h.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16399" source="BID">16399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423293/100/0/threaded" source="BUGTRAQ" adv="1">20060127 Shareaza P2P Remote Vulnerability</ref>
      <ref url="http://www.hustlelabs.com/shareaza_advisory.pdf" source="MISC" adv="1">http://www.hustlelabs.com/shareaza_advisory.pdf</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&amp;r2=1.15.2.1" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&amp;r2=1.15.2.1</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&amp;r2=1.5.4.1" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&amp;r2=1.5.4.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24344" source="XF">shareaza-cpacket-bo(24344)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24343" source="XF">shareaza-cedpacket-bo(24343)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24342" source="XF">shareaza-btpacket-bo(24342)</ref>
      <ref url="http://securityreason.com/securityalert/382" source="SREASON">382</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0887.html" source="FULLDISC">20060126 Shareaza Remote Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shareaza" name="shareaza">
        <vers num="2.2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0475" published="2006-01-31" name="CVE-2006-0475" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0368" source="VUPEN">ADV-2006-0368</ref>
      <ref url="http://www.kapda.ir/advisory-231.html" source="MISC">http://www.kapda.ir/advisory-231.html</ref>
      <ref url="http://secunia.com/advisories/18645" source="SECUNIA" adv="1">18645</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24382" source="XF">phpping-negative-count-dos(24382)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="theworldsend.net" name="php-ping">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0476" published="2006-01-31" name="CVE-2006-0476" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-032A.html" source="CERT">TA06-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/604745" source="CERT-VN">VU#604745</ref>
      <ref url="http://secunia.com/advisories/18649" source="SECUNIA" patch="1" adv="1">18649</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24361" source="XF">winamp-playlist-filename-bo(24361)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24361" source="XF">winamp-playlist-filename-bo(24361)</ref>
      <ref url="http://www.winamp.com/player/version_history.php" source="MISC">http://www.winamp.com/player/version_history.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0361" source="VUPEN">ADV-2006-0361</ref>
      <ref url="http://www.securityfocus.com/bid/16410" source="BID">16410</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423548/100/0/threaded" source="BUGTRAQ">20060131 Re: Re: Winamp 5.12 - 0day exploit - code execution through playlist</ref>
      <ref url="http://www.securityfocus.com/archive/1/423436/100/0/threaded" source="BUGTRAQ">20060130 Winamp 5.12 - 0day exploit - code execution through playlist</ref>
      <ref url="http://www.osvdb.org/22789" source="OSVDB">22789</ref>
      <ref url="http://www.heise.de/newsticker/meldung/68981" source="MISC">http://www.heise.de/newsticker/meldung/68981</ref>
      <ref url="http://securitytracker.com/id?1015552" source="SECTRACK">1015552</ref>
      <ref url="http://www.milw0rm.com/exploits/3422" source="MILW0RM">3422</ref>
      <ref url="http://securityreason.com/securityalert/398" source="SREASON">398</ref>
      <ref url="http://securityreason.com/securityalert/386" source="SREASON">386</ref>
      <ref url="http://milw0rm.com/exploits/1458" source="MILW0RM">1458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1402" source="OVAL" sig="1">oval:org.mitre.oval:def:1402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0477" published="2006-01-31" name="CVE-2006-0477" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18643" source="SECUNIA" patch="1" adv="1">18643</ref>
      <ref url="http://lwn.net/Articles/169623/" source="CONFIRM" patch="1">http://lwn.net/Articles/169623/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0367" source="VUPEN">ADV-2006-0367</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24360" source="XF">git-gitcheckoutindex-bo(24360)</ref>
      <ref url="http://www.securityfocus.com/bid/16417" source="BID">16417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="git" name="git">
        <vers num="1.0.0" />
        <vers num="1.0.0b" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0478" published="2006-01-31" name="CVE-2006-0478" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php.  NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases.  We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16415" source="BID" patch="1">16415</ref>
      <ref url="http://secunia.com/advisories/18648" source="SECUNIA" patch="1" adv="1">18648</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24377" source="XF">creloaded-files-auth-bypass(24377)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0373" source="VUPEN">ADV-2006-0373</ref>
      <ref url="http://www.osvdb.org/22793" source="OSVDB">22793</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-February/000527.html" source="VIM">20060203 vendor ack/fix: 22793: CRE Loaded files.php Unauthenticated Arbitrary File Upload (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cre_loaded" name="cre_loaded">
        <vers num="6.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0479" published="2006-01-31" name="CVE-2006-0479" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24368" source="XF">pmwiki-multiple-xss(24368)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24367" source="XF">pmwiki-file-include(24367)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24366" source="XF">pmwiki-path-disclosure(24366)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0375" source="VUPEN">ADV-2006-0375</ref>
      <ref url="http://www.ush.it/2006/01/24/pmwiki-multiple-vulnerabilities/" source="MISC" adv="1">http://www.ush.it/2006/01/24/pmwiki-multiple-vulnerabilities/</ref>
      <ref url="http://www.securityfocus.com/bid/16421" source="BID">16421</ref>
      <ref url="http://securitytracker.com/id?1015550" source="SECTRACK">1015550</ref>
      <ref url="http://secunia.com/advisories/18634" source="SECUNIA" adv="1">18634</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0931.html" source="FULLDISC">20060128 PmWiki Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmwiki" name="pmwiki">
        <vers num="2.1_beta_20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0480" published="2006-01-31" name="CVE-2006-0480" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the query parameter in the search file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0386" source="VUPEN">ADV-2006-0386</ref>
      <ref url="http://www.securityfocus.com/bid/16412" source="BID">16412</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423451/100/0/threaded" source="BUGTRAQ">20060129 sPaiz-Nuke Cross-Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24389" source="XF">spaiznuke-modules-xss(24389)</ref>
      <ref url="http://securityreason.com/securityalert/384" source="SREASON">384</ref>
      <ref url="http://secunia.com/advisories/18672" source="SECUNIA">18672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spaiz" name="spaiz-nuke_cms">
        <vers num="0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0481" published="2006-01-31" name="CVE-2006-0481" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16626" source="BID" patch="1">16626</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0205.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0205</ref>
      <ref url="http://securitytracker.com/id?1015617" source="SECTRACK" patch="1">1015617</ref>
      <ref url="http://securitytracker.com/id?1015615" source="SECTRACK" patch="1">1015615</ref>
      <ref url="http://secunia.com/advisories/18863" source="SECUNIA" patch="1" adv="1">18863</ref>
      <ref url="http://secunia.com/advisories/18654" source="SECUNIA" patch="1" adv="1">18654</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24396" source="XF">libpng-pngsetstripalpha-bo(24396)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0393" source="VUPEN" adv="1">ADV-2006-0393</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200812-15.xml" source="GENTOO">GLSA-200812-15</ref>
      <ref url="http://secunia.com/advisories/33137" source="SECUNIA" adv="1">33137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10780" source="OVAL">oval:org.mitre.oval:def:10780</ref>
      <ref url="ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txt" source="CONFIRM">ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng">
        <vers num="1.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0482" published="2006-01-31" name="CVE-2006-0482" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0418" source="VUPEN">ADV-2006-0418</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-sparc&amp;m=113861287813463&amp;w=2" source="MLIST">[linux-sparc] 20060130 Re: Attempts to set date with 'date -s' hang the machine</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-sparc&amp;m=113861010514065&amp;w=2" source="MLIST">[linux-sparc] 20060130 Attempts to set date with 'date -s' hang the machine</ref>
      <ref url="http://lists.debian.org/debian-sparc/2006/01/msg00129.html" source="MLIST">[debian-sparc] 20060128 `date -s' on sparc64</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24475" source="XF">kernel-date-s-dos(24475)</ref>
      <ref url="http://www.securityfocus.com/bid/17216" source="BID">17216</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="" />
        <vers num="2.6.0" edition=":64-bit_x86" />
        <vers num="2.6.0" edition=":itanium_ia64_montecito" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0483" published="2006-01-31" name="CVE-2006-0483" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060126-vpn.shtml" source="CISCO" patch="1" adv="1">20060126 Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack</ref>
      <ref url="http://secunia.com/advisories/18629" source="SECUNIA" patch="1" adv="1">18629</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24330" source="XF">cisco-vpn-http-dos(24330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0346" source="VUPEN">ADV-2006-0346</ref>
      <ref url="http://www.securityfocus.com/bid/16394" source="BID">16394</ref>
      <ref url="http://www.osvdb.org/22754" source="OSVDB">22754</ref>
      <ref url="http://securitytracker.com/id?1015546" source="SECTRACK">1015546</ref>
      <ref url="http://securityreason.com/securityalert/375" source="SREASON">375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="4.7" />
        <vers num="4.7(rel)" />
        <vers num="4.7.1" />
        <vers num="4.7.1.f" />
        <vers num="4.7.2" />
        <vers num="4.7.2.a" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="4.7" />
        <vers num="4.7(rel)" />
        <vers num="4.7.1" />
        <vers num="4.7.1.f" />
        <vers num="4.7.2" />
        <vers num="4.7.2.a" />
      </prod>
      <prod vendor="cisco" name="vpn_3020_concentrator">
        <vers num="4.7" />
        <vers num="4.7(rel)" />
        <vers num="4.7.1" />
        <vers num="4.7.1.f" />
        <vers num="4.7.2" />
        <vers num="4.7.2.a" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="4.7" />
        <vers num="4.7(rel)" />
        <vers num="4.7.1" />
        <vers num="4.7.1.f" />
        <vers num="4.7.2" />
        <vers num="4.7.2.a" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="4.7" />
        <vers num="4.7(rel)" />
        <vers num="4.7.1" />
        <vers num="4.7.1.f" />
        <vers num="4.7.2" />
        <vers num="4.7.2.a" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="4.7" />
        <vers num="4.7(rel)" />
        <vers num="4.7.1" />
        <vers num="4.7.1.f" />
        <vers num="4.7.2.a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0484" published="2006-01-31" name="CVE-2006-0484" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Vis.pl, as part of the FACE CONTROL product, allows remote attackers to read arbitrary files via a .. (dot dot) in any parameter that opens a file, such as (1) s or (2) p.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015547" source="SECTRACK" patch="1">1015547</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24374" source="XF">facecontrol-vis-directory-traversal(24374)</ref>
      <ref url="http://www.securityfocus.com/bid/16401" source="BID">16401</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423155/100/0/threaded" source="BUGTRAQ">20060126 [HSC] Multiple transversal bug in vis</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=22236" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=22236</ref>
      <ref url="http://securityreason.com/securityalert/376" source="SREASON">376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elido" name="face_control">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0485" published="2006-01-31" name="CVE-2006-0485" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0337" source="VUPEN">ADV-2006-0337</ref>
      <ref url="http://www.securityfocus.com/bid/16383" source="BID">16383</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-response-20060125-aaatcl.shtml" source="CISCO" adv="1">20060125 Response to AAA Command Authorization by-pass</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5836" source="OVAL">oval:org.mitre.oval:def:5836</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24308" source="XF">cisco-aaa-tcl-auth-bypass(24308)</ref>
      <ref url="http://www.osvdb.org/34892" source="OSVDB">34892</ref>
      <ref url="http://securitytracker.com/id?1015543" source="SECTRACK">1015543</ref>
      <ref url="http://secunia.com/advisories/18613" source="SECUNIA">18613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0t" />
        <vers num="12.0xh" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xn" />
        <vers num="12.0xr" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1e" />
        <vers num="12.1ec" />
        <vers num="12.1ez" />
        <vers num="12.1ga" />
        <vers num="12.1gb" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xe" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bw" />
        <vers num="12.2by" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2mx" />
        <vers num="12.2n" />
        <vers num="12.2s" />
        <vers num="12.2su" />
        <vers num="12.2sw" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sz" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xq" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yh" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3(11)yk2" />
        <vers num="12.3(11)yl" />
        <vers num="12.3b" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xm" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xw" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yb" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0486" published="2006-01-31" name="CVE-2006-0486" modified="2009-03-04" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-response-20060125-aaatcl.shtml" source="CISCO" adv="1">20060125 Response to AAA Command Authorization by-pass</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4905" source="OVAL">oval:org.mitre.oval:def:4905</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24308" source="XF">cisco-aaa-tcl-auth-bypass(24308)</ref>
      <ref url="http://www.osvdb.org/22723" source="OSVDB">22723</ref>
      <ref url="http://securitytracker.com/id?1015543" source="SECTRACK">1015543</ref>
      <ref url="http://secunia.com/advisories/18613" source="SECUNIA">18613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(25)s" />
        <vers num="12.3t" />
        <vers num="12.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0487" published="2006-01-31" name="CVE-2006-0487" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spam" during "spam outbreaks."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422591/100/0/threaded" source="BUGTRAQ">20060121 Tumbleweed EMF 6.x Processing Issues</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0488" published="2006-01-31" name="CVE-2006-0488" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.asm.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423169/100/0/threaded" source="BUGTRAQ">20060124 Windows mem leakage</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24471" source="XF">windows-vdm-obtain-information(24471)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0489" published="2006-01-31" name="CVE-2006-0489" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">** DISPUTED ** Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated "as far as I can tell, this is neither an exploit nor a vulnerability.  The above report describes a local bug in mIRC."  It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423192/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060124 Buffer Overflow /Font on mIRC</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423758/100/0/threaded" source="BUGTRAQ">20060201 Re: Buffer Overflow /Font on mIRC</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5IP080AHPQ.html" source="MISC">http://www.securiteam.com/windowsntfocus/5IP080AHPQ.html</ref>
      <ref url="http://www.osvdb.org/22942" source="OSVDB">22942</ref>
      <ref url="http://trout.snt.utwente.nl/ubbthreads/showflat.php?Cat=0&amp;Board=bugreports&amp;Number=118751" source="MISC">http://trout.snt.utwente.nl/ubbthreads/showflat.php?Cat=0&amp;Board=bugreports&amp;Number=118751</ref>
      <ref url="http://securityreason.com/securityalert/383" source="SREASON">383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="khaled_mardam-bey" name="mirc">
        <vers num="6.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0490" published="2006-01-31" name="CVE-2006-0490" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0372" source="VUPEN">ADV-2006-0372</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24359" source="XF">aspthai-login-sql-injection(24359)</ref>
      <ref url="http://www.securityfocus.com/bid/16404" source="BID">16404</ref>
      <ref url="http://www.osvdb.org/22790" source="OSVDB">22790</ref>
      <ref url="http://securitytracker.com/id?1015548" source="SECTRACK">1015548</ref>
      <ref url="http://securityreason.com/securityalert/381" source="SREASON">381</ref>
      <ref url="http://secunia.com/advisories/18636" source="SECUNIA">18636</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113837847503661&amp;w=2" source="BUGTRAQ">20060127 hello</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspthai.net" name="aspthai_forums">
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0491" published="2006-01-31" name="CVE-2006-0491" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24339" source="XF">szusermgnt-username-sql-injection(24339)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0366" source="VUPEN">ADV-2006-0366</ref>
      <ref url="http://www.evuln.com/vulns/53/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/53/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16454" source="BID">16454</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423658/100/0/threaded" source="BUGTRAQ">20060201 [eVuln] SZUserMgnt Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22809" source="OSVDB">22809</ref>
      <ref url="http://securitytracker.com/id?1015569" source="SECTRACK">1015569</ref>
      <ref url="http://securityreason.com/securityalert/396" source="SREASON">396</ref>
      <ref url="http://secunia.com/advisories/18666" source="SECUNIA">18666</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subzane" name="szusermgnt">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0492" published="2006-01-31" name="CVE-2006-0492" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php.  NOTE: the catview vector might overlap CVE-2005-1865.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0365" source="VUPEN">ADV-2006-0365</ref>
      <ref url="http://www.evuln.com/vulns/52/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/52/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24332" source="XF">calendarix-multiple-sql-injection(24332)</ref>
      <ref url="http://www.securityfocus.com/bid/16456" source="BID">16456</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423656/100/0/threaded" source="BUGTRAQ">20060201 [eVuln] Calendarix SQL Injection &amp; Authorization Bypass Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22811" source="OSVDB">22811</ref>
      <ref url="http://www.osvdb.org/22810" source="OSVDB">22810</ref>
      <ref url="http://securitytracker.com/id?1015560" source="SECTRACK">1015560</ref>
      <ref url="http://securityreason.com/securityalert/394" source="SREASON">394</ref>
      <ref url="http://secunia.com/advisories/18667" source="SECUNIA">18667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vincent_hor" name="calendarix">
        <vers num="0.6.2005-08-30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0493" published="2006-01-31" name="CVE-2006-0493" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MG2 (formerly known as Minigal) 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field in a comment associated with a picture.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16428" source="BID">16428</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423477/100/0/threaded" source="BUGTRAQ">20060130 XSS flaw in MG2 Image Gallery (v.0.5.1)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24378" source="XF">mg2-name-xss(24378)</ref>
      <ref url="http://securityreason.com/securityalert/389" source="SREASON">389</ref>
      <ref url="http://secunia.com/advisories/17374" source="SECUNIA">17374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomas_rybak" name="mg2">
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0494" published="2006-01-31" name="CVE-2006-0494" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423465/100/0/threaded" source="BUGTRAQ">20060130 MyBB 1.2 Local File Incusion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24461" source="XF">mybb-plugins-file-include(24461)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0495" published="2006-01-31" name="CVE-2006-0495" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24392" source="XF">mybb-usercp2-xss(24392)</ref>
      <ref url="http://www.securityfocus.com/bid/16419" source="BID">16419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423443/100/0/threaded" source="BUGTRAQ">20060129 MyBB 1.2 usercp2.php [ $url ] CrossSiteScripting ( XSS )</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0496" published="2006-01-31" name="CVE-2006-0496" modified="2011-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=324253" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=324253</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24427" source="XF">mozilla-mozbinding-xss(24427)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0403" source="VUPEN">ADV-2006-0403</ref>
      <ref url="http://www.securityfocus.com/bid/16427" source="BID">16427</ref>
      <ref url="http://www.osvdb.org/22924" source="OSVDB">22924</ref>
      <ref url="http://www.davidpashley.com/cgi/pyblosxom.cgi/computing/livejournal-mozilla-bug.html" source="MISC">http://www.davidpashley.com/cgi/pyblosxom.cgi/computing/livejournal-mozilla-bug.html</ref>
      <ref url="http://securitytracker.com/id?1015563" source="SECTRACK">1015563</ref>
      <ref url="http://securitytracker.com/id?1015553" source="SECTRACK">1015553</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113847912709062&amp;w=2" source="FULLDISC">20060128 -moz-binding CSS property: more XSS fun</ref>
      <ref url="http://community.livejournal.com/lj_dev/708069.html" source="MISC">http://community.livejournal.com/lj_dev/708069.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0497" published="2006-02-01" name="CVE-2006-0497" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0408" source="VUPEN">ADV-2006-0408</ref>
      <ref url="http://www.eyce.be/php_gen/NEWS" source="CONFIRM">http://www.eyce.be/php_gen/NEWS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24441" source="XF">phpgen-multiple-sql-injection(24441)</ref>
      <ref url="http://www.securityfocus.com/bid/15458" source="BID">15458</ref>
      <ref url="http://www.osvdb.org/22885" source="OSVDB">22885</ref>
      <ref url="http://secunia.com/advisories/18715" source="SECUNIA">18715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_gen" name="php_gen">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0498" published="2006-02-01" name="CVE-2006-0498" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0408" source="VUPEN">ADV-2006-0408</ref>
      <ref url="http://www.eyce.be/php_gen/NEWS" source="CONFIRM">http://www.eyce.be/php_gen/NEWS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24443" source="XF">phpgen-parameters-xss(24443)</ref>
      <ref url="http://www.osvdb.org/22884" source="OSVDB">22884</ref>
      <ref url="http://secunia.com/advisories/18715" source="SECUNIA">18715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_gen" name="php_gen">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0499" published="2006-02-01" name="CVE-2006-0499" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0390" source="VUPEN">ADV-2006-0390</ref>
      <ref url="http://www.securityfocus.com/bid/16448" source="BID">16448</ref>
      <ref url="http://secunia.com/advisories/18620" source="SECUNIA" adv="1">18620</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24410" source="XF">phpbb-rlink-xss(24410)</ref>
      <ref url="http://www.osvdb.org/22818" source="OSVDB">22818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yourboard" name="rlink">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0500" published="2006-02-01" name="CVE-2006-0500" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24438" source="XF">myco-admin-information-disclosure(24438)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423565/100/0/threaded" source="BUGTRAQ">20060131 MyCO multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punctweb" name="myco_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0501" published="2006-02-01" name="CVE-2006-0501" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423565/100/0/threaded" source="BUGTRAQ">20060131 MyCO multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24439" source="XF">myco-name-xss(24439)</ref>
      <ref url="http://www.securityfocus.com/bid/16444" source="BID">16444</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423696/100/0/threaded" source="BUGTRAQ">20060201 Re: MyCO multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punctweb" name="myco_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0502" published="2006-02-01" name="CVE-2006-0502" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0411" source="VUPEN">ADV-2006-0411</ref>
      <ref url="http://www.securityfocus.com/bid/16440" source="BID">16440</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423568/100/0/threaded" source="BUGTRAQ" adv="1">20060131 FarsiNews 2.1 PHP Remote File Inclusion</ref>
      <ref url="http://www.hamid.ir/security/farsinews.txt" source="MISC" adv="1">http://www.hamid.ir/security/farsinews.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24419" source="XF">farsinews-loginout-file-include(24419)</ref>
      <ref url="http://www.osvdb.org/22878" source="OSVDB">22878</ref>
      <ref url="http://securitytracker.com/id?1015554" source="SECTRACK">1015554</ref>
      <ref url="http://securityreason.com/securityalert/390" source="SREASON">390</ref>
      <ref url="http://secunia.com/advisories/18637" source="SECUNIA">18637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="farsinews" name="farsinews">
        <vers prev="1" num="2.1_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0503" published="2006-02-01" name="CVE-2006-0503" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mailenable.com/professionalhistory.asp" source="CONFIRM" patch="1">http://www.mailenable.com/professionalhistory.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24424" source="XF">mailenable-imap-examine-dos(24424)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0397" source="VUPEN">ADV-2006-0397</ref>
      <ref url="http://www.securityfocus.com/bid/16457" source="BID">16457</ref>
      <ref url="http://securitytracker.com/id?1015558" source="SECTRACK">1015558</ref>
      <ref url="http://secunia.com/advisories/18668" source="SECUNIA" adv="1">18668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0504" published="2006-02-01" name="CVE-2006-0504" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in MailEnable Enterprise Edition before 1.2 allows remote attackers to cause a denial of service (CPU utilization) by viewing "formatted quoted-printable emails" via webmail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24517" source="XF">mailenable-webmail-dos(24517)</ref>
      <ref url="http://www.mailenable.com/enterprisehistory.asp" source="CONFIRM">http://www.mailenable.com/enterprisehistory.asp</ref>
      <ref url="http://secunia.com/advisories/18716" source="SECUNIA">18716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0505" published="2006-02-01" name="CVE-2006-0505" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24369" source="XF">zbattle-command-dos(24369)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423431/100/0/threaded" source="BUGTRAQ">20060128 zbattle.net</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zbattle.net" name="zbattle_client">
        <vers num="1.09_sr-1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0506" published="2006-02-01" name="CVE-2006-0506" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0387" source="VUPEN">ADV-2006-0387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423454/100/0/threaded" source="BUGTRAQ">20060130 Nuked-klaN Cross-Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24387" source="XF">nukedklan-index-xss(24387)</ref>
      <ref url="http://www.securityfocus.com/bid/16424" source="BID">16424</ref>
      <ref url="http://www.osvdb.org/22805" source="OSVDB">22805</ref>
      <ref url="http://securityreason.com/securityalert/385" source="SREASON">385</ref>
      <ref url="http://secunia.com/advisories/18670" source="SECUNIA">18670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0507" published="2006-02-01" name="CVE-2006-0507" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24371" source="XF">easycms-xss(24371)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0385" source="VUPEN">ADV-2006-0385</ref>
      <ref url="http://www.securityfocus.com/bid/16430" source="BID">16430</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423563/100/0/threaded" source="BUGTRAQ">20060131 Re: EasyCMS vulnerable to XSS injection.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423442/100/0/threaded" source="BUGTRAQ">20060129 EasyCMS vulnerable to XSS injection.</ref>
      <ref url="http://secunia.com/advisories/18673" source="SECUNIA" adv="1">18673</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424431/100/0/threaded" source="BUGTRAQ">20060208 Re: Re: EasyCMS vulnerable to XSS injection.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_cms" name="easy_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0508" published="2006-02-01" name="CVE-2006-0508" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Easy CMS stores the images directory under the web document root with insufficient access control and browsing enabled, which allows remote attackers to list and possibly read images that are stored in that directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24373" source="XF">easycms-insecure-directories(24373)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423442/100/0/threaded" source="BUGTRAQ">20060129 EasyCMS vulnerable to XSS injection.</ref>
      <ref url="http://secunia.com/advisories/18673" source="SECUNIA" adv="1">18673</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424431/100/0/threaded" source="BUGTRAQ">20060208 Re: Re: EasyCMS vulnerable to XSS injection.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_cms" name="easy_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0509" published="2006-02-01" name="CVE-2006-0509" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24388" source="XF">cerberus-clients-xss(24388)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0395" source="VUPEN">ADV-2006-0395</ref>
      <ref url="http://www.securityfocus.com/bid/16439" source="BID">16439</ref>
      <ref url="http://www.securityfocus.com/archive/1/423547/30/0/threaded" source="BUGTRAQ">20060130 Cerberus Helpdesk vulnerable to XSS</ref>
      <ref url="http://www.osvdb.org/22843" source="OSVDB">22843</ref>
      <ref url="http://secunia.com/advisories/18657" source="SECUNIA">18657</ref>
      <ref url="http://securityreason.com/securityalert/391" source="SREASON">391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerberus" name="cerberus_helpdesk">
        <vers num="2.7" />
        <vers num="2.7.1_development_release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0510" published="2006-02-01" name="CVE-2006-0510" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24450" source="XF">daffodilcrm-userlogin-sql-injection(24450)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0412" source="VUPEN" adv="1">ADV-2006-0412</ref>
      <ref url="http://www.securityfocus.com/bid/16433" source="BID">16433</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423718/100/0/threaded" source="BUGTRAQ">20060130 Daffodil CRM - vulnerable to SQL-injection.</ref>
      <ref url="http://www.osvdb.org/22879" source="OSVDB">22879</ref>
      <ref url="http://secunia.com/advisories/18685" source="SECUNIA" adv="1">18685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daffodil_software" name="daffodil_crm">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0511" published="2006-02-01" name="CVE-2006-0511" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED ** Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges.  NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16438" source="BID">16438</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423778/100/0/threaded" source="BUGTRAQ">20060202 Re: Blackboard Authentication Error</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423654/100/0/threaded" source="BUGTRAQ">20060201 Blackboard Authentication Error</ref>
      <ref url="http://www.securityfocus.com/archive/1/423686/100/0/threaded" source="BUGTRAQ">20060201 Re: Blackboard Authentication Error</ref>
      <ref url="http://www.osvdb.org/28023" source="OSVDB">28023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackboard" name="blackboard">
        <vers num="5.0" />
        <vers num="5.0.2" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="6.0" />
      </prod>
      <prod vendor="blackboard" name="blackboard_academic_suite">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0512" published="2006-02-02" name="CVE-2006-0512" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migrate_all_netinfo_online.sh, (4) migrate_all_netinfo_offline.sh, (5) migrate_all_nis_online.sh, (6) migrate_all_nis_offline.sh, (7) migrate_all_nisplus_online.sh, and (8) migrate_all_nisplus_offline.sh.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2005/2427" source="VUPEN">ADV-2005-2427</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=338920" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=338920</ref>
      <ref url="http://secunia.com/advisories/22243" source="SECUNIA">22243</ref>
      <ref url="http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00281.html" source="DEBIAN">DSA-1187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="padl_software" name="migrationtools">
        <vers num="46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0513" published="2006-02-06" name="CVE-2006-0513" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/bulletins/advisories/2006/tam-file-retrieval.txt" source="MISC" patch="1" adv="1">http://www.vsecurity.com/bulletins/advisories/2006/tam-file-retrieval.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423946/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24011562" source="AIXAPAR" patch="1">IY79724</ref>
      <ref url="http://securitytracker.com/id?1015582" source="SECTRACK" patch="1">1015582</ref>
      <ref url="http://secunia.com/advisories/18725" source="SECUNIA" patch="1" adv="1">18725</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0442" source="VUPEN">ADV-2006-0442</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24485" source="XF">tivoli-pkmslogout-directory-traversal(24485)</ref>
      <ref url="http://www.securityfocus.com/bid/16494" source="BID">16494</ref>
      <ref url="http://securityreason.com/securityalert/412" source="SREASON">412</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041930.html" source="FULLDISC">20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_access_manager_for_e-business">
        <vers num="5.1.0.10" />
        <vers num="6.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0515" published="2006-05-09" name="CVE-2006-0515" modified="2011-03-07" discovered="2005-11-04" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspection, aka bugs CSCsc67612, CSCsc68472, and CSCsd81734.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/bulletins/advisories/2006/cisco-websense-bypass.txt" source="MISC" patch="1" adv="1">http://www.vsecurity.com/bulletins/advisories/2006/cisco-websense-bypass.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433270/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060508 VSR Advisory: WebSense content filter bypass when deployed in conjunction with Cisco filtering devices</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1738" source="VUPEN">ADV-2006-1738</ref>
      <ref url="http://www.securityfocus.com/bid/17883" source="BID">17883</ref>
      <ref url="http://securitytracker.com/id?1016040" source="SECTRACK">1016040</ref>
      <ref url="http://securitytracker.com/id?1016039" source="SECTRACK">1016039</ref>
      <ref url="http://secunia.com/advisories/20044" source="SECUNIA">20044</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26308" source="XF">cisco-websense-content-filtering-bypass(26308)</ref>
      <ref url="http://www.osvdb.org/25453" source="OSVDB">25453</ref>
      <ref url="http://www.cisco.com/en/US/products/sw/netmgtsw/ps2032/tsd_products_security_response09186a00806824ec.html" source="CISCO">20060508 PIX/ASA/FWSM Websense/N2H2 Content Filter Bypass</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045899.html" source="FULLDISC">20060508 VSR Advisory: WebSense content filter bypass when deployed in conjunction with Cisco filtering devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2.111" />
        <vers num="6.2.3_(110)" />
        <vers num="6.3.3_(133)" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="2.3" />
        <vers num="3.1" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.3" />
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="7.0" />
        <vers num="7.0(4)" />
        <vers num="7.0.1.4" />
        <vers num="7.0.4.3" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="2.7" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
        <vers num="4.1(6)" />
        <vers num="4.1(6b)" />
        <vers num="4.2" />
        <vers num="4.2(1)" />
        <vers num="4.2(2)" />
        <vers num="4.2(5)" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4(4)" />
        <vers num="4.4(7.202)" />
        <vers num="4.4(8)" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.1(4)" />
        <vers num="5.1(4.206)" />
        <vers num="5.2" />
        <vers num="5.2(1)" />
        <vers num="5.2(2)" />
        <vers num="5.2(3.210)" />
        <vers num="5.2(5)" />
        <vers num="5.2(6)" />
        <vers num="5.2(7)" />
        <vers num="5.2(9)" />
        <vers num="5.3" />
        <vers num="5.3(1)" />
        <vers num="5.3(1.200)" />
        <vers num="5.3(2)" />
        <vers num="5.3(3)" />
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.0(3)" />
        <vers num="6.0(4)" />
        <vers num="6.0(4.101)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(2)" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1(5)" />
        <vers num="6.1.5(104)" />
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3.100)" />
        <vers num="6.3" />
        <vers num="6.3(1)" />
        <vers num="6.3(2)" />
        <vers num="6.3(3)" />
        <vers num="6.3(3.102)" />
        <vers num="6.3(3.109)" />
        <vers num="6.3(5)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0516" published="2006-02-02" name="CVE-2006-0516" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0394" source="VUPEN">ADV-2006-0394</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102149-1" source="SUNALERT">102149</ref>
      <ref url="http://secunia.com/advisories/18671" source="SECUNIA" adv="1">18671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24395" source="XF">solaris-x64-kernel-dos(24395)</ref>
      <ref url="http://www.securityfocus.com/bid/16460" source="BID">16460</ref>
      <ref url="http://securitytracker.com/id?1015557" source="SECTRACK">1015557</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:219" source="OVAL" sig="1">oval:org.mitre.oval:def:219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1163" source="OVAL" sig="1">oval:org.mitre.oval:def:1163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":64_bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0517" published="2006-02-02" name="CVE-2006-0517" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to "session handling"; and (5) when posting "petitions".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zone-h.org/en/advisories/read/id=8650/" source="MISC" patch="1" adv="1">http://www.zone-h.org/en/advisories/read/id=8650/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0398" source="VUPEN">ADV-2006-0398</ref>
      <ref url="http://secunia.com/advisories/18676" source="SECUNIA" adv="1">18676</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24397" source="XF">spip-forum-sql-injection(24397)</ref>
      <ref url="http://www.securityfocus.com/bid/24397" source="BID">24397</ref>
      <ref url="http://www.securityfocus.com/bid/16458" source="BID">16458</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423655/100/0/threaded" source="BUGTRAQ">20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22848" source="OSVDB">22848</ref>
      <ref url="http://www.osvdb.org/22845" source="OSVDB">22845</ref>
      <ref url="http://www.osvdb.org/22844" source="OSVDB">22844</ref>
      <ref url="http://securitytracker.com/id?1015556" source="SECTRACK">1015556</ref>
      <ref url="http://securityreason.com/securityalert/395" source="SREASON">395</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0990.html" source="FULLDISC">20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers prev="1" num="1.8.2e" />
        <vers prev="1" num="1.9_alpha2_5539" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0518" published="2006-02-02" name="CVE-2006-0518" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zone-h.org/en/advisories/read/id=8650/" source="MISC" adv="1">http://www.zone-h.org/en/advisories/read/id=8650/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0398" source="VUPEN">ADV-2006-0398</ref>
      <ref url="http://secunia.com/advisories/18676" source="SECUNIA" adv="1">18676</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24401" source="XF">spip-index-xss(24401)</ref>
      <ref url="http://www.securityfocus.com/bid/16461" source="BID">16461</ref>
      <ref url="http://www.osvdb.org/22849" source="OSVDB">22849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers prev="1" num="1.8.2e" />
        <vers prev="1" num="1.9_alpha2_5539" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0519" published="2006-02-02" name="CVE-2006-0519" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zone-h.org/en/advisories/read/id=8650/" source="MISC" adv="1">http://www.zone-h.org/en/advisories/read/id=8650/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0398" source="VUPEN">ADV-2006-0398</ref>
      <ref url="http://secunia.com/advisories/18676" source="SECUNIA" adv="1">18676</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24399" source="XF">spip-incmessforum-path-disclosure(24399)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers prev="1" num="1.8.2e" />
        <vers prev="1" num="1.9_alpha2_5539" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0520" published="2006-02-02" name="CVE-2006-0520" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24404" source="XF">portal-index-sql-injection(24404)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0396" source="VUPEN">ADV-2006-0396</ref>
      <ref url="http://secunia.com/advisories/18664" source="SECUNIA" adv="1">18664</ref>
      <ref url="http://www.securityfocus.com/bid/16447" source="BID">16447</ref>
      <ref url="http://www.osvdb.org/22851" source="OSVDB">22851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dragoran" name="portal_module">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0521" published="2006-02-02" name="CVE-2006-0521" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in results.php in BrowserCRM allows remote attackers to inject arbitrary web script or HTML via certain manipulations of the query parameter, as demonstrated using an IMG SRC tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0391" source="VUPEN">ADV-2006-0391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423546/100/0/threaded" source="BUGTRAQ">20060131 BrowserCRM vulnerable for XSS</ref>
      <ref url="http://secunia.com/advisories/18658" source="SECUNIA" adv="1">18658</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24390" source="XF">browsercrm-results-xss(24390)</ref>
      <ref url="http://www.securityfocus.com/bid/16435" source="BID">16435</ref>
      <ref url="http://www.osvdb.org/22841" source="OSVDB">22841</ref>
      <ref url="http://securityreason.com/securityalert/393" source="SREASON">393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="browsercrm" name="browsercrm">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0522" published="2006-02-02" name="CVE-2006-0522" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0402" source="VUPEN">ADV-2006-0402</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24413" source="XF">symantec-sms-sql-injection(24413)</ref>
      <ref url="http://www.securityfocus.com/bid/16452" source="BID">16452</ref>
      <ref url="http://www.osvdb.org/22883" source="OSVDB">22883</ref>
      <ref url="http://securitytracker.com/id?1015561" source="SECTRACK">1015561</ref>
      <ref url="http://secunia.com/advisories/18689" source="SECUNIA">18689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="sygate_management_server">
        <vers num="3.5_mr_3_build_894_english" />
        <vers num="4.0_mr_1_build_1104_english" />
        <vers num="4.1_ga_build_1258_japanese" />
        <vers num="4.1_mr1_build_1351_chinese" />
        <vers prev="1" num="4.1_mr_2_build_1417_english" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0523" published="2006-02-02" name="CVE-2006-0523" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18678" source="SECUNIA" patch="1" adv="1">18678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24416" source="XF">mybb-global-sql-injection(24416)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0400" source="VUPEN">ADV-2006-0400</ref>
      <ref url="http://www.osvdb.org/22903" source="OSVDB">22903</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=6418" source="CONFIRM">http://community.mybboard.net/showthread.php?tid=6418</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="1.0_preview_release_2" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0524" published="2006-02-02" name="CVE-2006-0524" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24365" source="XF">ashnews-ashnews-xss(24365)</ref>
      <ref url="http://www.securityfocus.com/bid/16426" source="BID">16426</ref>
      <ref url="http://www.osvdb.org/22934" source="OSVDB">22934</ref>
      <ref url="http://secunia.com/advisories/9331" source="SECUNIA">9331</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0979.html" source="FULLDISC">20060131 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0969.html" source="FULLDISC">20060130 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0955.html" source="FULLDISC">20060130 ashnews Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashwebstudio" name="ashnews">
        <vers num="0.83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0525" published="2006-02-02" name="CVE-2006-0525" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/953860" source="CERT-VN" adv="1">VU#953860</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24464" source="XF">adobe-insecure-default-permissions(24464)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0431" source="VUPEN" adv="1">ADV-2006-0431</ref>
      <ref url="http://www.securityfocus.com/bid/16451" source="BID">16451</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded" source="BUGTRAQ">20060131 Windows Access Control Demystified</ref>
      <ref url="http://www.osvdb.org/22908" source="OSVDB">22908</ref>
      <ref url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf" source="MISC">http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf</ref>
      <ref url="http://www.adobe.com/support/techdocs/332644.html" source="CONFIRM">http://www.adobe.com/support/techdocs/332644.html</ref>
      <ref url="http://securitytracker.com/id?1015579" source="SECTRACK">1015579</ref>
      <ref url="http://securitytracker.com/id?1015578" source="SECTRACK">1015578</ref>
      <ref url="http://securitytracker.com/id?1015577" source="SECTRACK">1015577</ref>
      <ref url="http://secunia.com/advisories/18698" source="SECUNIA" adv="1">18698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
      </prod>
      <prod vendor="adobe" name="creative_suite">
        <vers num="1.0" />
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="adobe" name="illustrator">
        <vers num="10.0" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="cs" />
        <vers num="cs3" />
      </prod>
      <prod vendor="adobe" name="indesign">
        <vers num="cs" />
        <vers num="cs3" />
      </prod>
      <prod vendor="adobe" name="pagemaker">
        <vers num="6.5" edition="" />
        <vers num="6.5" edition=":plus" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":plus" />
      </prod>
      <prod vendor="adobe" name="photoshop">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0.2" />
        <vers num="le" />
      </prod>
      <prod vendor="adobe" name="premiere">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":pro" />
      </prod>
      <prod vendor="adobe" name="version_cue">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":mac_os_x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0526" published="2006-02-02" name="CVE-2006-0526" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file name, which might allow local users to gain privileges via a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/953860" source="CERT-VN">VU#953860</ref>
      <ref url="http://www.securityfocus.com/bid/16453" source="BID">16453</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded" source="BUGTRAQ">20060131 Windows Access Control Demystified</ref>
      <ref url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf" source="MISC">http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24498" source="XF">aol-insecure-default-permissions(24498)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol_client_software">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":plus" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":optimized" />
        <vers num="9.0" edition=":security" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0527" published="2006-02-02" name="CVE-2006-0527" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425083/100/0/threaded" source="HP" patch="1" adv="1">HPSBUX02097</ref>
      <ref url="http://securitytracker.com/id?1015606" source="SECTRACK" patch="1">1015606</ref>
      <ref url="http://securitytracker.com/id?1015551" source="SECTRACK" patch="1">1015551</ref>
      <ref url="http://secunia.com/advisories/18690" source="SECUNIA" patch="1" adv="1">18690</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24414" source="XF">tru64-dns-bind-unauth-access(24414)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00595837" source="HP">HPSBTU02095</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00595837" source="HP">SSRT051007</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0399" source="VUPEN" adv="1">ADV-2006-0399</ref>
      <ref url="http://www.securityfocus.com/bid/16455" source="BID">16455</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425083/100/0/threaded" source="HP">HPSBUX02097</ref>
      <ref url="http://www.osvdb.org/22888" source="OSVDB">22888</ref>
      <ref url="http://securityreason.com/securityalert/748" source="SREASON">748</ref>
      <ref url="http://securityreason.com/securityalert/438" source="SREASON">438</ref>
      <ref url="http://computerworld.com/networkingtopics/networking/story/0,10801,103744,00.html" source="MISC">http://computerworld.com/networkingtopics/networking/story/0,10801,103744,00.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000551.html" source="VIM">20060216 Recent HP advisories outline BIND problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0528" published="2006-02-02" name="CVE-2006-0528" modified="2010-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-265-1" source="UBUNTU">USN-265-1</ref>
      <ref url="http://www.securityfocus.com/bid/16408" source="BID">16408</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_07_sr.html" source="SUSE" adv="1">SUSE-SR:2006:007</ref>
      <ref url="http://secunia.com/advisories/19504" source="SECUNIA" adv="1">19504</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0925.html" source="FULLDISC">20060128 gnome evolution mail client inline text file DoS issue</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:057" source="MANDRIVA">MDKSA-2006:057</ref>
      <ref url="http://securityreason.com/securityalert/610" source="SREASON">610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution">
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.6.1" />
        <vers num="2.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0529" published="2006-02-02" name="CVE-2006-0529" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via a crafted message to TCP port 4105.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581" source="MISC" patch="1" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423785/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060202 CAID 33581 - CA Message Queuing Denial of Service Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18681" source="SECUNIA" patch="1" adv="1">18681</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0414" source="VUPEN">ADV-2006-0414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24448" source="XF">ca-cam-port4105-dos(24448)</ref>
      <ref url="http://www.securityfocus.com/bid/16475" source="BID">16475</ref>
      <ref url="http://www.osvdb.org/21146" source="OSVDB">21146</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/camessagsecurity_notice.asp" source="CONFIRM">http://supportconnectw.ca.com/public/ca_common_docs/camessagsecurity_notice.asp</ref>
      <ref url="http://securitytracker.com/id?1015571" source="SECTRACK">1015571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="messaging">
        <vers num="1.05" edition="" />
        <vers num="1.05" edition=":aix" />
        <vers num="1.05" edition=":windows" />
        <vers num="1.05" edition=":linux" />
        <vers num="1.05" edition=":solaris" />
        <vers num="1.07.210.0" edition="" />
        <vers num="1.07.210.0" edition=":solaris" />
        <vers num="1.07.210.0" edition=":aix" />
        <vers num="1.07.220.0" edition="" />
        <vers num="1.07.220.0" edition=":solaris" />
        <vers num="1.07.220.0" edition=":windows" />
        <vers num="1.07.220.10" edition="" />
        <vers num="1.07.220.10" edition=":windows" />
        <vers num="1.07.220.11" edition="" />
        <vers num="1.07.220.11" edition=":solaris" />
        <vers num="1.07.220.11" edition=":aix" />
        <vers num="1.07.220.11" edition=":linux" />
        <vers num="1.07.220.11" edition=":windows" />
        <vers num="1.07.220.11" edition=":hp_ux" />
        <vers num="1.07.220.13" edition="" />
        <vers num="1.07.220.13" edition=":hp_ux" />
        <vers num="1.07.220.13" edition=":solaris" />
        <vers num="1.07.220.13" edition=":aix" />
        <vers num="1.07.220.13" edition=":windows" />
        <vers num="1.07.220.13" edition=":linux" />
        <vers num="1.07.220.14" edition="" />
        <vers num="1.07.220.14" edition=":solaris" />
        <vers num="1.07.220.14" edition=":aix" />
        <vers num="1.07.220.14" edition=":hp_ux" />
        <vers num="1.07.220.14" edition=":windows" />
        <vers num="1.07.220.14" edition=":linux" />
        <vers num="1.07.220.15" edition="" />
        <vers num="1.07.220.15" edition=":windows" />
        <vers num="1.07.220.15" edition=":hp_ux" />
        <vers num="1.07.220.15" edition=":aix" />
        <vers num="1.07.220.15" edition=":linux" />
        <vers num="1.07.220.15" edition=":solaris" />
        <vers num="1.07.220.3" edition="" />
        <vers num="1.07.220.3" edition=":windows" />
        <vers num="1.07.220.4" edition="" />
        <vers num="1.07.220.4" edition=":windows" />
        <vers num="1.07.220.5" edition="" />
        <vers num="1.07.220.5" edition=":solaris" />
        <vers num="1.07.220.5" edition=":aix" />
        <vers num="1.07.220.5" edition=":hp_ux" />
        <vers num="1.07.220.5" edition=":windows" />
        <vers num="1.07.220.6" edition="" />
        <vers num="1.07.220.6" edition=":windows" />
        <vers num="1.07.220.7" edition="" />
        <vers num="1.07.220.7" edition=":hp_ux" />
        <vers num="1.07.220.7" edition=":aix" />
        <vers num="1.07.220.7" edition=":windows" />
        <vers num="1.07.220.8" edition="" />
        <vers num="1.07.220.8" edition=":solaris" />
        <vers num="1.07.220.8" edition=":hp_ux" />
        <vers num="1.07.220.8" edition=":aix" />
        <vers num="1.07.220.9" edition="" />
        <vers num="1.07.220.9" edition=":windows" />
        <vers num="1.07.220.9" edition=":solaris" />
        <vers num="1.11.18.0" edition="" />
        <vers num="1.11.18.0" edition=":hp_ux" />
        <vers num="1.11.19.0" edition="" />
        <vers num="1.11.19.0" edition=":solaris" />
        <vers num="1.11.19.0" edition=":aix" />
        <vers num="1.11.21" edition="" />
        <vers num="1.11.21" edition=":windows" />
        <vers num="1.11.22" edition="" />
        <vers num="1.11.22" edition=":windows" />
        <vers num="1.11.23" edition="" />
        <vers num="1.11.23" edition=":windows" />
        <vers num="1.11.24" edition="" />
        <vers num="1.11.24" edition=":windows" />
        <vers num="1.11.25" edition="" />
        <vers num="1.11.25" edition=":windows" />
        <vers num="1.11.26" edition="" />
        <vers num="1.11.26" edition=":windows" />
        <vers num="1.11.26.1" edition="" />
        <vers num="1.11.26.1" edition=":windows" />
        <vers num="1.11.26.10" edition="" />
        <vers num="1.11.26.10" edition=":windows" />
        <vers num="1.11.26.2" edition="" />
        <vers num="1.11.26.2" edition=":windows" />
        <vers num="1.11.26.6" edition="" />
        <vers num="1.11.26.6" edition=":windows" />
        <vers num="1.11.26.7" edition="" />
        <vers num="1.11.26.7" edition=":windows" />
        <vers num="1.11.26.8" edition="" />
        <vers num="1.11.26.8" edition=":windows" />
        <vers num="1.11.26.9" edition="" />
        <vers num="1.11.26.9" edition=":windows" />
        <vers num="1.11.27.0" edition="" />
        <vers num="1.11.27.0" edition=":solaris" />
        <vers num="1.11.27.0" edition=":hp_ux" />
        <vers num="1.11.27.0" edition=":aix" />
        <vers num="1.11.27.1" edition="" />
        <vers num="1.11.27.1" edition=":solaris" />
        <vers num="1.11.27.1" edition=":aix" />
        <vers num="1.11.27.1" edition=":hp_ux" />
        <vers num="1.11.27.1" edition=":windows" />
        <vers num="1.11.27.2" edition="" />
        <vers num="1.11.27.2" edition=":windows" />
        <vers num="1.11.27.3" edition="" />
        <vers num="1.11.27.3" edition=":windows" />
        <vers num="1.11.28.0" edition="" />
        <vers num="1.11.28.0" edition=":linux" />
        <vers num="1.11.29.0" edition="" />
        <vers num="1.11.29.0" edition=":windows" />
        <vers num="1.11.29.13" edition="" />
        <vers num="1.11.29.13" edition=":hp_ux" />
        <vers num="1.11.29.13" edition=":aix" />
        <vers num="1.11.29.13" edition=":windows" />
        <vers num="1.11.29.13" edition=":linux" />
        <vers num="1.11.29.13" edition=":solaris" />
        <vers num="1.11.29.14" edition="" />
        <vers num="1.11.29.14" edition=":hp_ux" />
        <vers num="1.11.29.14" edition=":windows" />
        <vers num="1.11.29.14" edition=":solaris" />
        <vers num="1.11.29.14" edition=":linux" />
        <vers num="1.11.29.14" edition=":aix" />
        <vers num="1.11.29.15" edition="" />
        <vers num="1.11.29.15" edition=":linux" />
        <vers num="1.11.29.15" edition=":hp_ux" />
        <vers num="1.11.29.15" edition=":windows" />
        <vers num="1.11.29.15" edition=":aix" />
        <vers num="1.11.29.15" edition=":solaris" />
        <vers num="1.11.29.16" edition="" />
        <vers num="1.11.29.16" edition=":aix" />
        <vers num="1.11.29.16" edition=":solaris" />
        <vers num="1.11.29.16" edition=":linux" />
        <vers num="1.11.29.16" edition=":windows" />
        <vers num="1.11.29.16" edition=":hp_ux" />
        <vers num="1.11.29.17" edition="" />
        <vers num="1.11.29.17" edition=":linux" />
        <vers num="1.11.29.17" edition=":windows" />
        <vers num="1.11.29.17" edition=":solaris" />
        <vers num="1.11.29.17" edition=":aix" />
        <vers num="1.11.29.17" edition=":hp_ux" />
        <vers num="1.11.29.18" edition="" />
        <vers num="1.11.29.18" edition=":linux" />
        <vers num="1.11.29.18" edition=":windows" />
        <vers num="1.11.29.18" edition=":solaris" />
        <vers num="1.11.29.18" edition=":hp_ux" />
        <vers num="1.11.29.18" edition=":aix" />
        <vers num="1.11.29.19" edition="" />
        <vers num="1.11.29.19" edition=":solaris" />
        <vers num="1.11.29.19" edition=":hp_ux" />
        <vers num="1.11.29.19" edition=":linux" />
        <vers num="1.11.29.19" edition=":aix" />
        <vers num="1.11.29.19" edition=":windows" />
        <vers num="1.11.29.2" edition="" />
        <vers num="1.11.29.2" edition=":aix" />
        <vers num="1.11.29.2" edition=":solaris" />
        <vers num="1.11.29.2" edition=":hp_ux" />
        <vers num="1.11.29.2" edition=":windows" />
        <vers num="1.11.29.3" edition="" />
        <vers num="1.11.29.3" edition=":windows" />
        <vers num="1.11.29.3" edition=":aix" />
        <vers num="1.11.29.3" edition=":hp_ux" />
        <vers num="1.11.29.3" edition=":solaris" />
        <vers num="1.11.29.4" edition="" />
        <vers num="1.11.29.4" edition=":solaris" />
        <vers num="1.11.29.4" edition=":hp_ux" />
        <vers num="1.11.29.4" edition=":windows" />
        <vers num="1.11.29.4" edition=":aix" />
        <vers num="1.11.29.5" edition="" />
        <vers num="1.11.29.5" edition=":solaris" />
        <vers num="1.11.29.5" edition=":aix" />
        <vers num="1.11.29.5" edition=":linux" />
        <vers num="1.11.29.5" edition=":hp_ux" />
        <vers num="1.11.29.5" edition=":windows" />
        <vers num="1.11.29.6" edition="" />
        <vers num="1.11.29.6" edition=":windows" />
        <vers num="1.11.29.7" edition="" />
        <vers num="1.11.29.7" edition=":windows" />
        <vers num="1.11.29.8" edition="" />
        <vers num="1.11.29.8" edition=":windows" />
        <vers num="1.11.29.8" edition=":hp_ux" />
        <vers num="1.11.29.8" edition=":aix" />
        <vers num="1.11.29.8" edition=":solaris" />
        <vers num="1.11.29.8" edition=":linux" />
        <vers num="1.11.29.9" edition="" />
        <vers num="1.11.29.9" edition=":hp_ux" />
        <vers num="1.11.29.9" edition=":aix" />
        <vers num="1.11.29.9" edition=":windows" />
        <vers num="1.11.29.9" edition=":linux" />
        <vers num="1.11.29.9" edition=":solaris" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0530" published="2006-02-02" name="CVE-2006-0530" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via spoofed CAM control messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423785/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060202 CAID 33581 - CA Message Queuing Denial of Service Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18681" source="SECUNIA" patch="1" adv="1">18681</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581" source="MISC" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0414" source="VUPEN">ADV-2006-0414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24449" source="XF">ca-cam-spoofed-message-dos(24449)</ref>
      <ref url="http://www.securityfocus.com/bid/16475" source="BID">16475</ref>
      <ref url="http://securitytracker.com/id?1015571" source="SECTRACK">1015571</ref>
      <ref url="http://securityreason.com/securityalert/404" source="SREASON">404</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="messaging">
        <vers num="1.05" edition="" />
        <vers num="1.05" edition=":hp_ux" />
        <vers num="1.05" edition=":aix" />
        <vers num="1.05" edition=":windows" />
        <vers num="1.05" edition=":linux" />
        <vers num="1.05" edition=":solaris" />
        <vers num="1.07.210.0" edition="" />
        <vers num="1.07.210.0" edition=":solaris" />
        <vers num="1.07.210.0" edition=":aix" />
        <vers num="1.07.220.0" edition="" />
        <vers num="1.07.220.0" edition=":solaris" />
        <vers num="1.07.220.0" edition=":windows" />
        <vers num="1.07.220.10" edition="" />
        <vers num="1.07.220.10" edition=":windows" />
        <vers num="1.07.220.11" edition="" />
        <vers num="1.07.220.11" edition=":solaris" />
        <vers num="1.07.220.11" edition=":aix" />
        <vers num="1.07.220.11" edition=":linux" />
        <vers num="1.07.220.11" edition=":windows" />
        <vers num="1.07.220.11" edition=":hp_ux" />
        <vers num="1.07.220.13" edition="" />
        <vers num="1.07.220.13" edition=":hp_ux" />
        <vers num="1.07.220.13" edition=":solaris" />
        <vers num="1.07.220.13" edition=":aix" />
        <vers num="1.07.220.13" edition=":windows" />
        <vers num="1.07.220.13" edition=":linux" />
        <vers num="1.07.220.14" edition="" />
        <vers num="1.07.220.14" edition=":solaris" />
        <vers num="1.07.220.14" edition=":aix" />
        <vers num="1.07.220.14" edition=":hp_ux" />
        <vers num="1.07.220.14" edition=":windows" />
        <vers num="1.07.220.14" edition=":linux" />
        <vers num="1.07.220.15" edition="" />
        <vers num="1.07.220.15" edition=":windows" />
        <vers num="1.07.220.15" edition=":hp_ux" />
        <vers num="1.07.220.15" edition=":aix" />
        <vers num="1.07.220.15" edition=":linux" />
        <vers num="1.07.220.15" edition=":solaris" />
        <vers num="1.07.220.3" edition="" />
        <vers num="1.07.220.3" edition=":windows" />
        <vers num="1.07.220.4" edition="" />
        <vers num="1.07.220.4" edition=":windows" />
        <vers num="1.07.220.5" edition="" />
        <vers num="1.07.220.5" edition=":solaris" />
        <vers num="1.07.220.5" edition=":aix" />
        <vers num="1.07.220.5" edition=":hp_ux" />
        <vers num="1.07.220.5" edition=":windows" />
        <vers num="1.07.220.6" edition="" />
        <vers num="1.07.220.6" edition=":windows" />
        <vers num="1.07.220.7" edition="" />
        <vers num="1.07.220.7" edition=":hp_ux" />
        <vers num="1.07.220.7" edition=":aix" />
        <vers num="1.07.220.7" edition=":windows" />
        <vers num="1.07.220.8" edition="" />
        <vers num="1.07.220.8" edition=":solaris" />
        <vers num="1.07.220.8" edition=":hp_ux" />
        <vers num="1.07.220.8" edition=":aix" />
        <vers num="1.07.220.9" edition="" />
        <vers num="1.07.220.9" edition=":windows" />
        <vers num="1.07.220.9" edition=":solaris" />
        <vers num="1.11.18.0" edition="" />
        <vers num="1.11.18.0" edition=":hp_ux" />
        <vers num="1.11.19.0" edition="" />
        <vers num="1.11.19.0" edition=":solaris" />
        <vers num="1.11.19.0" edition=":aix" />
        <vers num="1.11.21" edition="" />
        <vers num="1.11.21" edition=":windows" />
        <vers num="1.11.22" edition="" />
        <vers num="1.11.22" edition=":windows" />
        <vers num="1.11.23" edition="" />
        <vers num="1.11.23" edition=":windows" />
        <vers num="1.11.24" edition="" />
        <vers num="1.11.24" edition=":windows" />
        <vers num="1.11.25" edition="" />
        <vers num="1.11.25" edition=":windows" />
        <vers num="1.11.26" edition="" />
        <vers num="1.11.26" edition=":windows" />
        <vers num="1.11.26.1" edition="" />
        <vers num="1.11.26.1" edition=":windows" />
        <vers num="1.11.26.10" edition="" />
        <vers num="1.11.26.10" edition=":windows" />
        <vers num="1.11.26.2" edition="" />
        <vers num="1.11.26.2" edition=":windows" />
        <vers num="1.11.26.6" edition="" />
        <vers num="1.11.26.6" edition=":windows" />
        <vers num="1.11.26.7" edition="" />
        <vers num="1.11.26.7" edition=":windows" />
        <vers num="1.11.26.8" edition="" />
        <vers num="1.11.26.8" edition=":windows" />
        <vers num="1.11.26.9" edition="" />
        <vers num="1.11.26.9" edition=":windows" />
        <vers num="1.11.27.0" edition="" />
        <vers num="1.11.27.0" edition=":solaris" />
        <vers num="1.11.27.0" edition=":hp_ux" />
        <vers num="1.11.27.0" edition=":aix" />
        <vers num="1.11.27.1" edition="" />
        <vers num="1.11.27.1" edition=":solaris" />
        <vers num="1.11.27.1" edition=":aix" />
        <vers num="1.11.27.1" edition=":hp_ux" />
        <vers num="1.11.27.1" edition=":windows" />
        <vers num="1.11.27.2" edition="" />
        <vers num="1.11.27.2" edition=":windows" />
        <vers num="1.11.27.3" edition="" />
        <vers num="1.11.27.3" edition=":windows" />
        <vers num="1.11.28.0" edition="" />
        <vers num="1.11.28.0" edition=":linux" />
        <vers num="1.11.29.0" edition="" />
        <vers num="1.11.29.0" edition=":windows" />
        <vers num="1.11.29.13" edition="" />
        <vers num="1.11.29.13" edition=":hp_ux" />
        <vers num="1.11.29.13" edition=":aix" />
        <vers num="1.11.29.13" edition=":windows" />
        <vers num="1.11.29.13" edition=":linux" />
        <vers num="1.11.29.13" edition=":solaris" />
        <vers num="1.11.29.14" edition="" />
        <vers num="1.11.29.14" edition=":hp_ux" />
        <vers num="1.11.29.14" edition=":windows" />
        <vers num="1.11.29.14" edition=":solaris" />
        <vers num="1.11.29.14" edition=":linux" />
        <vers num="1.11.29.14" edition=":aix" />
        <vers num="1.11.29.15" edition="" />
        <vers num="1.11.29.15" edition=":linux" />
        <vers num="1.11.29.15" edition=":hp_ux" />
        <vers num="1.11.29.15" edition=":windows" />
        <vers num="1.11.29.15" edition=":aix" />
        <vers num="1.11.29.15" edition=":solaris" />
        <vers num="1.11.29.16" edition="" />
        <vers num="1.11.29.16" edition=":aix" />
        <vers num="1.11.29.16" edition=":solaris" />
        <vers num="1.11.29.16" edition=":linux" />
        <vers num="1.11.29.16" edition=":windows" />
        <vers num="1.11.29.16" edition=":hp_ux" />
        <vers num="1.11.29.17" edition="" />
        <vers num="1.11.29.17" edition=":linux" />
        <vers num="1.11.29.17" edition=":windows" />
        <vers num="1.11.29.17" edition=":solaris" />
        <vers num="1.11.29.17" edition=":aix" />
        <vers num="1.11.29.17" edition=":hp_ux" />
        <vers num="1.11.29.18" edition="" />
        <vers num="1.11.29.18" edition=":linux" />
        <vers num="1.11.29.18" edition=":windows" />
        <vers num="1.11.29.18" edition=":solaris" />
        <vers num="1.11.29.18" edition=":hp_ux" />
        <vers num="1.11.29.18" edition=":aix" />
        <vers num="1.11.29.19" edition="" />
        <vers num="1.11.29.19" edition=":solaris" />
        <vers num="1.11.29.19" edition=":hp_ux" />
        <vers num="1.11.29.19" edition=":linux" />
        <vers num="1.11.29.19" edition=":aix" />
        <vers num="1.11.29.19" edition=":windows" />
        <vers num="1.11.29.2" edition="" />
        <vers num="1.11.29.2" edition=":aix" />
        <vers num="1.11.29.2" edition=":solaris" />
        <vers num="1.11.29.2" edition=":hp_ux" />
        <vers num="1.11.29.2" edition=":windows" />
        <vers num="1.11.29.3" edition="" />
        <vers num="1.11.29.3" edition=":windows" />
        <vers num="1.11.29.3" edition=":aix" />
        <vers num="1.11.29.3" edition=":hp_ux" />
        <vers num="1.11.29.3" edition=":solaris" />
        <vers num="1.11.29.4" edition="" />
        <vers num="1.11.29.4" edition=":solaris" />
        <vers num="1.11.29.4" edition=":hp_ux" />
        <vers num="1.11.29.4" edition=":windows" />
        <vers num="1.11.29.4" edition=":aix" />
        <vers num="1.11.29.5" edition="" />
        <vers num="1.11.29.5" edition=":solaris" />
        <vers num="1.11.29.5" edition=":aix" />
        <vers num="1.11.29.5" edition=":linux" />
        <vers num="1.11.29.5" edition=":hp_ux" />
        <vers num="1.11.29.5" edition=":windows" />
        <vers num="1.11.29.6" edition="" />
        <vers num="1.11.29.6" edition=":windows" />
        <vers num="1.11.29.7" edition="" />
        <vers num="1.11.29.7" edition=":windows" />
        <vers num="1.11.29.8" edition="" />
        <vers num="1.11.29.8" edition=":windows" />
        <vers num="1.11.29.8" edition=":hp_ux" />
        <vers num="1.11.29.8" edition=":aix" />
        <vers num="1.11.29.8" edition=":solaris" />
        <vers num="1.11.29.8" edition=":linux" />
        <vers num="1.11.29.9" edition="" />
        <vers num="1.11.29.9" edition=":hp_ux" />
        <vers num="1.11.29.9" edition=":aix" />
        <vers num="1.11.29.9" edition=":windows" />
        <vers num="1.11.29.9" edition=":linux" />
        <vers num="1.11.29.9" edition=":solaris" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0531" published="2006-02-03" name="CVE-2006-0531" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18699" source="SECUNIA" patch="1" adv="1">18699</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24423" source="XF">sun-jsam-admin-access(24423)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0430" source="VUPEN">ADV-2006-0430</ref>
      <ref url="http://www.securityfocus.com/bid/16474" source="BID">16474</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102140-1" source="SUNALERT">102140</ref>
      <ref url="http://securitytracker.com/id?1015567" source="SECTRACK">1015567</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:755" source="OVAL" sig="1">oval:org.mitre.oval:def:755</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:360" source="OVAL" sig="1">oval:org.mitre.oval:def:360</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":solaris_s" />
        <vers num="7.0" edition=":linux" />
        <vers num="7.0" edition=":solaris_x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0532" published="2006-02-03" name="CVE-2006-0532" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24451" source="XF">softmakershop-image-xss(24451)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0434" source="VUPEN">ADV-2006-0434</ref>
      <ref url="http://www.securityfocus.com/bid/16471" source="BID">16471</ref>
      <ref url="http://www.securityfocus.com/archive/1/423768" source="BUGTRAQ">20060201 SoftMaker Shop is vulnerable to XSS</ref>
      <ref url="http://www.osvdb.org/22911" source="OSVDB">22911</ref>
      <ref url="http://secunia.com/advisories/18683" source="SECUNIA" adv="1">18683</ref>
      <ref url="http://securityreason.com/securityalert/400" source="SREASON">400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="media2_cms" name="shop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0533" published="2006-02-03" name="CVE-2006-0533" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24468" source="XF">cpanel-scripts-xss(24468)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0433" source="VUPEN">ADV-2006-0433</ref>
      <ref url="http://www.osvdb.org/22906" source="OSVDB">22906</ref>
      <ref url="http://secunia.com/advisories/18691" source="SECUNIA" adv="1">18691</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113894933522271&amp;w=2" source="FULLDISC">20060203 Re: cPanel Multiple Cross Site Scripting</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0534" published="2006-02-03" name="CVE-2006-0534" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16473" source="BID">16473</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423787/100/0/threaded" source="BUGTRAQ">20060202 CyberShop Ultimate E-commerce Script Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24454" source="XF">cybershop-xss(24454)</ref>
      <ref url="http://securityreason.com/securityalert/401" source="SREASON">401</ref>
      <ref url="http://secunia.com/advisories/18730" source="SECUNIA">18730</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybershop" name="asp_ultimate_e-commerce_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0535" published="2006-02-03" name="CVE-2006-0535" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: this candidate does not contain any actionable or distinguishing information.  Perhaps it should not be included in CVE.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16478" source="BID">16478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="communityserver.org" name="community_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0536" published="2006-02-03" name="CVE-2006-0536" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.  NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24470" source="XF">neomail-neomail-script-xss(24470)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0449" source="VUPEN">ADV-2006-0449</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423901/100/0/threaded" source="BUGTRAQ" adv="1">20060203 Neomail Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.osvdb.org/22978" source="OSVDB">22978</ref>
      <ref url="http://securitytracker.com/id?1015581" source="SECTRACK">1015581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neomail" name="neomail">
        <vers num="1.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0537" published="2006-02-03" name="CVE-2006-0537" modified="2011-03-07" discovered="2006-01-14" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24477" source="XF">exchangepop3-rcptto-bo(24477)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0437" source="VUPEN">ADV-2006-0437</ref>
      <ref url="http://www.securityfocus.com/bid/16485" source="BID">16485</ref>
      <ref url="http://www.osvdb.org/22907" source="OSVDB">22907</ref>
      <ref url="http://www.milw0rm.com/exploits/1466" source="MILW0RM">1466</ref>
      <ref url="http://securitytracker.com/id?1015580" source="SECTRACK">1015580</ref>
      <ref url="http://secunia.com/advisories/18687" source="SECUNIA" adv="1">18687</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.pl</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0040.html" source="BUGTRAQ">20060203 Exchangepop3 rcpt buffer overflow vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/408" source="SREASON">408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kinesphere_corporation" name="exchange_pop3">
        <vers num="5.0_build_050203" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0538" published="2006-02-03" name="CVE-2006-0538" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16465" source="BID">16465</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423898/100/0/threaded" source="BUGTRAQ" adv="1">20060203 IronMail-5.0.1-Denial of-Service-Protection-Lets-Remote-Users-Deny-Service</ref>
      <ref url="http://securitytracker.com/id?1015555" source="SECTRACK">1015555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24445" source="XF">ironmail-tcpsyn-flood-dos(24445)</ref>
      <ref url="http://securityreason.com/securityalert/407" source="SREASON">407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ciphertrust" name="ironmail">
        <vers prev="1" num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0539" published="2006-02-03" name="CVE-2006-0539" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can "overwrite some data."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0435" source="VUPEN">ADV-2006-0435</ref>
      <ref url="http://www.securityfocus.com/bid/16467" source="BID">16467</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423697/100/0/threaded" source="BUGTRAQ">20060201 Fcrontab - memory corruption on heap.</ref>
      <ref url="http://secunia.com/advisories/18719" source="SECUNIA">18719</ref>
      <ref url="https://bugs.trustix.org/show_bug.cgi?id=1754" source="CONFIRM">https://bugs.trustix.org/show_bug.cgi?id=1754</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24444" source="XF">fcron-syslog-bo(24444)</ref>
      <ref url="http://www.trustix.org/errata/2006/0036" source="TRUSTIX">2006-0036</ref>
      <ref url="http://fcron.free.fr/news.php#a20060206a.xml" source="CONFIRM">http://fcron.free.fr/news.php#a20060206a.xml</ref>
      <ref url="http://fcron.free.fr/doc/en/changes.html" source="CONFIRM">http://fcron.free.fr/doc/en/changes.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0999.html" source="FULLDISC">20060201 Fcrontab - memory corruption on heap.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0540" published="2006-02-03" name="CVE-2006-0540" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16464" source="BID">16464</ref>
      <ref url="http://www.evuln.com/vulns/54/summary.html" source="MISC">http://www.evuln.com/vulns/54/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24412" source="XF">vanillaguestbook-messages-sql-injection(24412)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423957/100/0/threaded" source="BUGTRAQ">20060201 [eVuln] Vanilla Guestbook Multiple XSS &amp; SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tachyon" name="vanilla_guestbook">
        <vers num="1.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0541" published="2006-02-03" name="CVE-2006-0541" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "posting new messages."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16464" source="BID">16464</ref>
      <ref url="http://www.evuln.com/vulns/54/summary.html" source="MISC">http://www.evuln.com/vulns/54/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24411" source="XF">vanillaguestbook-name-xss(24411)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426200/100/0/threaded" source="BUGTRAQ">20060227 Re: [eVuln] Vanilla Guestbook Multiple XSS &amp; SQL Injection Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423957/100/0/threaded" source="BUGTRAQ">20060201 [eVuln] Vanilla Guestbook Multiple XSS &amp; SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tachyon" name="vanilla_guestbook">
        <vers num="1.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0542" published="2006-02-03" name="CVE-2006-0542" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24406" source="XF">guestbookhost-login-sql-injection(24406)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0465" source="VUPEN">ADV-2006-0465</ref>
      <ref url="http://www.evuln.com/vulns/56/summary.html" source="MISC">http://www.evuln.com/vulns/56/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16545" source="BID">16545</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424714/100/0/threaded" source="BUGTRAQ">20060209 [eVuln] GuestBookHost Authentication Bypass</ref>
      <ref url="http://secunia.com/advisories/18761" source="SECUNIA">18761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukedweb" name="guestbookhost">
        <vers num="2005-04-25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0543" published="2006-02-03" name="CVE-2006-0543" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \'d1, (2) \'d2, (3) \'d3, (4) \'d4, and (5) \'d5.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22877" source="OSVDB" patch="1">22877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="3.1.0.120" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0544" published="2006-02-03" name="CVE-2006-0544" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16463" source="BID">16463</ref>
      <ref url="http://www.security-protocols.com/advisory/sp-x23-advisory.txt" source="MISC">http://www.security-protocols.com/advisory/sp-x23-advisory.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" edition="beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0545" published="2006-02-03" name="CVE-2006-0545" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24381" source="XF">ubbthreads-showflat-sql-injection(24381)</ref>
      <ref url="http://www.securityfocus.com/bid/16520" source="BID">16520</ref>
      <ref url="http://www.osvdb.org/22808" source="OSVDB">22808</ref>
      <ref url="http://www.cyberlords.net/advisories/cl_ubb.txt" source="MISC">http://www.cyberlords.net/advisories/cl_ubb.txt</ref>
      <ref url="http://securitytracker.com/id?1015549" source="SECTRACK">1015549</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-03/0494.html" source="BUGTRAQ">20060325 UBBThreads&lt;=5.5.1+6.0.2+6.0 br5+6.0.1 SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0546" published="2006-02-03" name="CVE-2006-0546" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in index.php in a certain application available from /v1/tr/portfoy.php on www.egeinternet.com allows remote attackers to execute arbitrary code via "evilcode" in the key parameter, possibly a PHP remote file include vulnerability in which the attack vector is a URL in the key parameter.  NOTE: it is not clear whether this vulnerability is associated with an online service or application service provider.  If so, then it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423365/100/0/threaded" source="BUGTRAQ">20060128 Ege Internet Web Desing Remote Command Exucetion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="egeinternet" name="egeinternet">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0547" published="2006-02-03" name="CVE-2006-0547" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB18 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0265.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT" adv="1">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/871756" source="CERT-VN" adv="1">VU#871756</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="MISC" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC" adv="1">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://www.imperva.com/application_defense_center/papers/oracle-dbms-01172006.html" source="MISC" adv="1">http://www.imperva.com/application_defense_center/papers/oracle-dbms-01172006.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24184" source="XF">oracle-login-command-execute(24184)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041464.html" source="FULLDISC">20060117 Oracle DBMS - Access Control Bypass in Login</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.3" edition="r1" />
        <vers num="10.1.0.4" edition="r1" />
        <vers num="10.1.0.5" edition="r1" />
        <vers num="10.2.0.1" edition="r2" />
        <vers num="8.1.7.4" edition="r3" />
        <vers num="9.2.0.6" edition="r2" />
        <vers num="9.2.0.7" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0548" published="2006-02-03" name="CVE-2006-0548" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB15 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT" adv="1">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/150332" source="CERT-VN" adv="1">VU#150332</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="MISC" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC" adv="1">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4.2" edition="r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0549" published="2006-02-03" name="CVE-2006-0549" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB05 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.  However, there are some inconsistencies that make this unclear, and there is also a possibility that this is related to DB06, which is subsumed by CVE-2006-0259.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT" adv="1">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/629316" source="CERT-VN" adv="1">VU#629316</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_metadata_util.html" source="MISC">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_metadata_util.html</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="MISC" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC" adv="1">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" edition="r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0550" published="2006-02-03" name="CVE-2006-0550" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DBC02 from the January 2006 CPU, in which case this would be a duplicate of CVE-2006-0283.  However, there are enough inconsistencies that the mapping can not be made authoritatively.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT" patch="1" adv="1">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/999268" source="CERT-VN" patch="1" adv="1">VU#999268</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC" patch="1">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="MISC" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle_client">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0551" published="2006-02-03" name="CVE-2006-0551" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB06 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0259 or, if it is DB05, subsumed by CVE-2006-0260.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT" patch="1" adv="1">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/983340" source="CERT-VN" patch="1" adv="1">VU#983340</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC" patch="1">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="MISC" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.3" />
        <vers num="10.1.0.4" />
        <vers num="10.1.0.5" />
        <vers num="10.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0552" published="2006-02-04" name="CVE-2006-0552" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" patch="1">18493</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22549" source="OSVDB">22549</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="10g_enterprise_manager_grid_control">
        <vers num="10.1_.0.3" />
        <vers num="10.1_.0.4" />
      </prod>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2" edition="r1" />
        <vers num="10.1.2" />
        <vers num="10.1.2.0.0" edition="r2" />
        <vers num="10.1.2.0.1" edition="r2" />
        <vers num="10.1.2.0.2" edition="r2" />
        <vers num="10.1.2.1.0" />
        <vers num="9.0.4" />
        <vers num="9.0.4.1" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.1" edition="r1" />
        <vers num="10.1.2" edition="r1" />
        <vers num="9.0.4.2" edition="r2" />
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="8.0.6" />
        <vers num="8.0.6.3" />
        <vers num="8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="developer_suite">
        <vers num="10.1.2" />
        <vers num="9.0.2.1" />
        <vers num="9.0.4.1" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.10" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.95.f1" />
        <vers num="sp23_l1" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.3" />
        <vers num="enterprise_10.1.0.4" />
        <vers num="personal_10.1.0.3" />
        <vers num="personal_10.1.0.4" />
        <vers num="standard_10.1.0.3" />
        <vers num="standard_10.1.0.4" />
        <vers num="standard_10.1.0.4.2" />
        <vers num="standard_10.1.0.5" />
        <vers num="standard_10.2.0.1" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6.3" />
        <vers num="standard_8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.0.1.5_fips" />
        <vers num="standard_9.2.0.6" />
        <vers num="standard_9.2.0.7" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_portal">
        <vers num="8.4" />
        <vers num="8.8" />
        <vers num="8.9" />
      </prod>
      <prod vendor="oracle" name="workflow">
        <vers num="11.5.1" />
        <vers num="11.5.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0553" published="2006-02-14" name="CVE-2006-0553" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a crafted SET ROLE to other database users, a different vulnerability than CVE-2006-0678.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/567452" source="CERT-VN">VU#567452</ref>
      <ref url="http://secunia.com/advisories/18890" source="SECUNIA" patch="1" adv="1">18890</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24718" source="XF">postgresql-setrole-privilege-elevation(24718)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0605" source="VUPEN">ADV-2006-0605</ref>
      <ref url="http://www.securityfocus.com/bid/16649" source="BID">16649</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425037/100/0/threaded" source="BUGTRAQ">20060215 PostgreSQL security releases 8.1.3, 8.0.7, 7.4.12, 7.3.14</ref>
      <ref url="http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3" source="CONFIRM">http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html" source="OPENPKG" adv="1">OpenPKG-SA-2006.004</ref>
      <ref url="http://securitytracker.com/id?1015636" source="SECTRACK">1015636</ref>
      <ref url="http://archives.postgresql.org/pgsql-announce/2006-02/msg00008.php" source="MLIST">[pgsql-announce] 20060214 Minor Releases 7.3 thru 8.1 Available to Fix Security Issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.1.0" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0554" published="2006-03-06" name="CVE-2006-0554" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5" source="CONFIRM" patch="1">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0804" source="VUPEN">ADV-2006-0804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24999" source="XF">kernel-ftruncate-information-disclosure(24999)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1" source="UBUNTU">USN-263-1</ref>
      <ref url="http://www.securityfocus.com/bid/16921" source="BID">16921</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19220" source="SECUNIA">19220</ref>
      <ref url="http://secunia.com/advisories/19083" source="SECUNIA">19083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="" />
        <vers num="2.6.0" edition=":64-bit_x86" />
        <vers num="2.6.0" edition=":itanium_ia64_montecito" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0555" published="2006-03-06" name="CVE-2006-0555" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0804" source="VUPEN">ADV-2006-0804</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9932" source="OVAL">oval:org.mitre.oval:def:9932</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25000" source="XF">kernel-odirect-dos(25000)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1" source="UBUNTU">USN-263-1</ref>
      <ref url="http://www.securityfocus.com/bid/16922" source="BID">16922</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00003.html" source="FEDORA">FEDORA-2006-131</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
      <ref url="http://secunia.com/advisories/19220" source="SECUNIA">19220</ref>
      <ref url="http://secunia.com/advisories/19108" source="SECUNIA">19108</ref>
      <ref url="http://secunia.com/advisories/19083" source="SECUNIA">19083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="" />
        <vers num="2.6.0" edition=":64-bit_x86" />
        <vers num="2.6.0" edition=":itanium_ia64_montecito" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0557" published="2006-03-12" name="CVE-2006-0557" modified="2011-07-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16924" source="BID" patch="1">16924</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63</ref>
      <ref url="http://securitytracker.com/id?1015752" source="SECTRACK" patch="1">1015752</ref>
      <ref url="http://lkml.org/lkml/2006/2/27/355" source="CONFIRM" patch="1">http://lkml.org/lkml/2006/2/27/355</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184510" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184510</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25204" source="XF">linux-get-nodes-dos(25204)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN" adv="1">ADV-2006-2554</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.osvdb.org/23895" source="OSVDB">23895</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA" adv="1">20914</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA" adv="1">20398</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA" adv="1">19955</ref>
      <ref url="http://rhn.redhat.com/errata/RHBA-2007-0304.html" source="REDHAT">RHBA-2007-0304</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9674" source="OVAL">oval:org.mitre.oval:def:9674</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers prev="1" num="2.6.16" edition="rc1" />
        <vers prev="1" num="2.6.16" edition="rc2" />
        <vers prev="1" num="2.6.16" edition="rc3" />
        <vers prev="1" num="2.6.16" edition="rc4" />
        <vers prev="1" num="2.6.16" edition="rc5" />
        <vers prev="1" num="2.6.16" edition="rc6" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0558" published="2006-04-14" name="CVE-2006-0558" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=185082" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=185082</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1444" source="VUPEN">ADV-2006-1444</ref>
      <ref url="http://www.securityfocus.com/bid/17482" source="BID">17482</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10177" source="OVAL">oval:org.mitre.oval:def:10177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-ia64&amp;m=113882384921688" source="MLIST">[linux-ia64] [PATCH 1/1] ia64: perfmon.c trips BUG_ON in put_page_testzero</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0774.html" source="REDHAT">RHSA-2007:0774</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://secunia.com/advisories/26709" source="SECUNIA">26709</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/19737" source="SECUNIA">19737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0559" published="2006-04-04" name="CVE-2006-0559" modified="2011-03-07" discovered="2006-04-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has released a patch (P0803), along with version 4.5 MR2 to address this issue.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16742" source="BID" patch="1">16742</ref>
      <ref url="http://secunia.com/advisories/19491" source="SECUNIA" patch="1" adv="1">19491</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1219" source="VUPEN">ADV-2006-1219</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429812/100/0/threaded" source="BUGTRAQ" adv="1">20060404 SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25621" source="XF">webshield-smtp-format-string(25621)</ref>
      <ref url="http://www.osvdb.org/24366" source="OSVDB">24366</ref>
      <ref url="http://securitytracker.com/id?1015861" source="SECTRACK">1015861</ref>
      <ref url="http://securityreason.com/securityalert/671" source="SREASON">671</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="webshield_smtp">
        <vers prev="1" num="4.5" edition="mr2_patch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0561" published="2006-05-09" name="CVE-2006-0561" modified="2011-03-07" discovered="2006-05-08" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Cisco, Secure Access Control Server, 4.0.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.symantec.com/enterprise/research/SYMSA-2006-003.txt" source="MISC" patch="1" adv="1">http://www.symantec.com/enterprise/research/SYMSA-2006-003.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16743" source="BID" patch="1">16743</ref>
      <ref url="http://www.securityfocus.com/archive/1/433301/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060508 Re: SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclosure</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sr-20060508-acs.shtml" source="CISCO" patch="1">20060508 Response to Symantec SYMSA-2006-003 Cisco Secure ACS for Windows - Administrator Password Disclosure</ref>
      <ref url="http://securitytracker.com/id?1016042" source="SECTRACK" patch="1">1016042</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1741" source="VUPEN">ADV-2006-1741</ref>
      <ref url="http://www.securityfocus.com/archive/1/433286/100/0/threaded" source="BUGTRAQ" adv="1">20060508 SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclosure</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26307" source="XF">cisco-acs-admin-password-disclosure(26307)</ref>
      <ref url="http://www.osvdb.org/25892" source="OSVDB">25892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows_nt" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows_nt" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows_nt" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows_nt" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows_nt" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows_nt" />
        <vers num="3.2" edition=":windows_server" />
        <vers num="3.3" edition="" />
        <vers num="3.3" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0562" published="2006-02-06" name="CVE-2006-0562" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in problem.php in PluggedOut Blog 1.9.9c allows remote attackers to inject arbitrary web script or HTML via the data parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24482" source="XF">pluggedoutblog-problem-xss(24482)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0440" source="VUPEN">ADV-2006-0440</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423948/100/0/threaded" source="BUGTRAQ">20060204 PluggedOut Blog SQL injection and XSS</ref>
      <ref url="http://securitytracker.com/id?1015586" source="SECTRACK">1015586</ref>
      <ref url="http://secunia.com/advisories/18726" source="SECUNIA" adv="1">18726</ref>
      <ref url="http://hamid.ir/security/pluggedoutblog.txt" source="MISC">http://hamid.ir/security/pluggedoutblog.txt</ref>
      <ref url="http://www.osvdb.org/22927" source="OSVDB">22927</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000530.html" source="VIM">20060206 VERIFY Pluggedout Blog 1.9.9c problem.php XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pluggedout" name="pluggedout_blog">
        <vers num="1.9.9c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0563" published="2006-02-06" name="CVE-2006-0563" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24480" source="XF">pluggedoutblog-exec-sql-injection(24480)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0440" source="VUPEN">ADV-2006-0440</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423948/100/0/threaded" source="BUGTRAQ">20060204 PluggedOut Blog SQL injection and XSS</ref>
      <ref url="http://securitytracker.com/id?1015586" source="SECTRACK">1015586</ref>
      <ref url="http://secunia.com/advisories/18726" source="SECUNIA" adv="1">18726</ref>
      <ref url="http://hamid.ir/security/pluggedoutblog.txt" source="MISC">http://hamid.ir/security/pluggedoutblog.txt</ref>
      <ref url="http://www.osvdb.org/22926" source="OSVDB">22926</ref>
      <ref url="http://securityreason.com/securityalert/415" source="SREASON">415</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000531.html" source="VIM">20060206 VERIFY Pluggedout Blog 1.9.9c exec.php SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pluggedout" name="pluggedout_blog">
        <vers num="1.9.9c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0564" published="2006-02-06" name="CVE-2006-0564" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/124460" source="CERT-VN">VU#124460</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0446" source="VUPEN">ADV-2006-0446</ref>
      <ref url="http://users.pandora.be/bratax/advisories/b008.html" source="MISC">http://users.pandora.be/bratax/advisories/b008.html</ref>
      <ref url="http://securitytracker.com/id?1015585" source="SECTRACK">1015585</ref>
      <ref url="http://secunia.com/advisories/18740" source="SECUNIA" adv="1">18740</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24481" source="XF">mshtmlhelp-workshop-hhp-bo(24481)</ref>
      <ref url="http://www.osvdb.org/22941" source="OSVDB">22941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help">
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":sdk" />
      </prod>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.74.8702.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0565" published="2006-02-06" name="CVE-2006-0565" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the $GLOBALS[path] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24479" source="XF">louadblog-backendsettings-file-include(24479)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24479" source="XF">louadblog-backendsettings-file-include(24479)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0441" source="VUPEN" adv="1">ADV-2006-0441</ref>
      <ref url="http://www.securityfocus.com/bid/16495" source="BID">16495</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423947/100/0/threaded" source="BUGTRAQ">20060204 LoudBlog &lt;= 0.4 arbitrary remote inclusion</ref>
      <ref url="http://www.osvdb.org/22921" source="OSVDB">22921</ref>
      <ref url="http://securitytracker.com/id?1015583" source="SECTRACK">1015583</ref>
      <ref url="http://securityreason.com/securityalert/556" source="SREASON">556</ref>
      <ref url="http://securityreason.com/securityalert/410" source="SREASON">410</ref>
      <ref url="http://secunia.com/advisories/18722" source="SECUNIA" adv="1">18722</ref>
      <ref url="http://retrogod.altervista.org/loudblog_04_incl_xpl.html" source="MISC">http://retrogod.altervista.org/loudblog_04_incl_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gerrit_van_aaken" name="loudblog">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers prev="1" num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0566" published="2006-02-06" name="CVE-2006-0566" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The LDAP component in CommuniGate Pro Core Server 5.0.7 allows remote attackers to cause a denial of service (application crash) via LDAP messages that contain Distinguished Names (DN) fields with a large number of elements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0444" source="VUPEN">ADV-2006-0444</ref>
      <ref url="http://www.stalker.com/CommuniGatePro/History.html" source="CONFIRM">http://www.stalker.com/CommuniGatePro/History.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423968/100/0/threaded" source="BUGTRAQ">20060204 ProtoVer LDAP vs CommuniGate Pro 5.0.7</ref>
      <ref url="http://www.gleg.net/advisory_cg2.shtml" source="MISC">http://www.gleg.net/advisory_cg2.shtml</ref>
      <ref url="http://securitytracker.com/id?1015587" source="SECTRACK">1015587</ref>
      <ref url="http://secunia.com/advisories/18701" source="SECUNIA" adv="1">18701</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24409" source="XF">communigate-ldap-bo(24409)</ref>
      <ref url="http://www.osvdb.org/22932" source="OSVDB">22932</ref>
      <ref url="http://securityreason.com/securityalert/416" source="SREASON">416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="communigate" name="communigate_pro_core_server">
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0567" published="2006-02-07" name="CVE-2006-0567" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24393" source="XF" patch="1">files-archive-directory-directory-traversal(24393)</ref>
      <ref url="http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things" source="CONFIRM" patch="1">http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0371" source="VUPEN">ADV-2006-0371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curtis_farnham" name="files_xaraya_module">
        <vers num="0.3.0" />
        <vers num="0.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0568" published="2006-02-07" name="CVE-2006-0568" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in throw.main in Outblaze allows remote attackers to inject arbitrary web script or HTML via the file parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24476" source="XF">outblaze-email-thrownmain-xss(24476)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0439" source="VUPEN">ADV-2006-0439</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423915/100/0/threaded" source="BUGTRAQ" adv="1">20060203 Outblaze Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.osvdb.org/22909" source="OSVDB">22909</ref>
      <ref url="http://www.morx.org/outblazeXSS.txt" source="MISC" adv="1">http://www.morx.org/outblazeXSS.txt</ref>
      <ref url="http://secunia.com/advisories/18710" source="SECUNIA" adv="1">18710</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0024.html" source="FULLDISC" adv="1">20060202 Outblaze Cross Site Scripting Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/411" source="SREASON">411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="outblaze" name="outblaze">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0569" published="2006-02-07" name="CVE-2006-0569" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the username field during the registration of a new account.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18721" source="SECUNIA" patch="1" adv="1">18721</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0438" source="VUPEN">ADV-2006-0438</ref>
      <ref url="http://www.osvdb.org/22913" source="OSVDB">22913</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24500" source="XF">papoo-username-xss(24500)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="papoo" name="papoo">
        <vers prev="1" num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0570" published="2006-02-07" name="CVE-2006-0570" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0450" source="VUPEN">ADV-2006-0450</ref>
      <ref url="http://evuln.com/vulns/61/summary.html" source="MISC" adv="1">http://evuln.com/vulns/61/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16587" source="BID">16587</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424842/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] phpstatus Authentication Bypass</ref>
      <ref url="http://securityreason.com/securityalert/427" source="SREASON">427</ref>
      <ref url="http://secunia.com/advisories/18791" source="SECUNIA">18791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phpstatus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0571" published="2006-02-07" name="CVE-2006-0571" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0450" source="VUPEN">ADV-2006-0450</ref>
      <ref url="http://evuln.com/vulns/61/summary.html" source="MISC" adv="1">http://evuln.com/vulns/61/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16587" source="BID">16587</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424842/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] phpstatus Authentication Bypass</ref>
      <ref url="http://securityreason.com/securityalert/427" source="SREASON">427</ref>
      <ref url="http://secunia.com/advisories/18791" source="SECUNIA">18791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phpstatus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0572" published="2006-02-07" name="CVE-2006-0572" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://evuln.com/vulns/61/summary.html" source="MISC" adv="1">http://evuln.com/vulns/61/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16587" source="BID">16587</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424842/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] phpstatus Authentication Bypass</ref>
      <ref url="http://securityreason.com/securityalert/427" source="SREASON">427</ref>
      <ref url="http://secunia.com/advisories/18791" source="SECUNIA">18791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phpstatus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0573" published="2006-02-07" name="CVE-2006-0573" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to (a) editquota.html or (b) dodelpop.html; (2) showtree parameter to (c) diskusage.html; or the (3) mon, (4) year, (5) target, or (6) domain parameter to (d) stats/detailbw.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24468" source="XF">cpanel-scripts-xss(24468)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0433" source="VUPEN">ADV-2006-0433</ref>
      <ref url="http://secunia.com/advisories/18695" source="SECUNIA" adv="1">18695</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113898556313924&amp;w=2" source="BUGTRAQ" adv="1">20060203 cPanel Multiple Cross Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0025.html" source="FULLDISC" adv="1">20060202 cPanel Multiple Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.osvdb.org/22939" source="OSVDB">22939</ref>
      <ref url="http://www.osvdb.org/22938" source="OSVDB">22938</ref>
      <ref url="http://www.osvdb.org/22937" source="OSVDB">22937</ref>
      <ref url="http://www.osvdb.org/22936" source="OSVDB">22936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="10" />
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0574" published="2006-02-07" name="CVE-2006-0574" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mime/handle.html in cPanel 10 allows remote attackers to inject arbitrary web script or HTML via the (1) file extension or (2) mime-type.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0433" source="VUPEN">ADV-2006-0433</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424148/100/0/threaded" source="BUGTRAQ">20060205 cPanel 10 handle.html XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18695" source="SECUNIA" adv="1">18695</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0062.html" source="FULLDISC">20060204 cPanel 10 mime/handle.html XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22940" source="OSVDB">22940</ref>
      <ref url="http://securitytracker.com/id?1015589" source="SECTRACK">1015589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0575" published="2006-02-07" name="CVE-2006-0575" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via ".." sequences and a symlink attack on the temporary file that is used during conversion.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24504" source="XF">fcron-dotdot-directory-traversal(24504)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0435" source="VUPEN">ADV-2006-0435</ref>
      <ref url="http://www.trustix.org/errata/2006/0006" source="TRUSTIX">2006-0006</ref>
      <ref url="http://www.osvdb.org/22905" source="OSVDB">22905</ref>
      <ref url="http://secunia.com/advisories/18719" source="SECUNIA" adv="1">18719</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113890734603201&amp;w=2" source="FULLDISC">20060202 Re: Fcrontab - memory corruption on heap.</ref>
      <ref url="http://www.securityfocus.com/bid/25693" source="BID">25693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="2.9.5" />
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0576" published="2006-02-07" name="CVE-2006-0576" modified="2011-06-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs.  NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo.  In such a context, this is a vulnerability.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16536" source="BID">16536</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424325/100/0/threaded" source="BUGTRAQ">20060207 Arbitrary code execution via OProfile</ref>
      <ref url="http://www.redhat.com/magazine/012oct05/features/oprofile/" source="MISC">http://www.redhat.com/magazine/012oct05/features/oprofile/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10890" source="OVAL">oval:org.mitre.oval:def:10890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maynard_johnson" name="oprofile">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.9" />
        <vers prev="1" num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0577" published="2006-02-07" name="CVE-2006-0577" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the "Appearance" dialog and selecting the "Additional styles (skins) are available on the Lexmark web site" option, which launches a web browser that is running with SYSTEM privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0482" source="VUPEN">ADV-2006-0482</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424322/100/0/threaded" source="BUGTRAQ">20060207 Re: High Risk Vulnerability in Lexmark Printer Sharing Service</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24596" source="XF">lexmark-x1185-privilege-elevation(24596)</ref>
      <ref url="http://www.securityfocus.com/bid/16534" source="BID">16534</ref>
      <ref url="http://secunia.com/advisories/18728" source="SECUNIA">18728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="x1185">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0578" published="2006-02-07" name="CVE-2006-0578" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0401" source="VUPEN">ADV-2006-0401</ref>
      <ref url="http://www.secumind.net/content/french/modules/news/article.php?storyid=8" source="MISC" adv="1">http://www.secumind.net/content/french/modules/news/article.php?storyid=8</ref>
      <ref url="http://secunia.com/advisories/18622" source="SECUNIA" adv="1">18622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24446" source="XF">proxysg-connect-bypass-security(24446)</ref>
      <ref url="http://www.osvdb.org/22853" source="OSVDB">22853</ref>
      <ref url="http://www.bluecoat.com/support/knowledge/advisory_connect_denial_ignore.html" source="CONFIRM">http://www.bluecoat.com/support/knowledge/advisory_connect_denial_ignore.html</ref>
      <ref url="http://securitytracker.com/id?1015644" source="SECTRACK">1015644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="proxysg">
        <vers num="4.1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0579" published="2006-02-07" name="CVE-2006-0579" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) the new_demux_packet function in demuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in MPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary code via an ASF file with a large packet length value. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0457" source="VUPEN">ADV-2006-0457</ref>
      <ref url="http://secunia.com/advisories/18718" source="SECUNIA" adv="1">18718</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24531" source="XF">mplayer-asf-integer-overflow(24531)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:048" source="MANDRIVA">MDKSA-2006:048</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-03.xml" source="GENTOO">GLSA-200603-03</ref>
      <ref url="http://secunia.com/advisories/19114" source="SECUNIA">19114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers prev="1" num="1.0_pre7try2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0580" published="2006-02-07" name="CVE-2006-0580" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0458" source="VUPEN">ADV-2006-0458</ref>
      <ref url="http://secunia.com/advisories/18738" source="SECUNIA" adv="1">18738</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002896.html" source="MLIST">[Dailydave] 20060203 ProtoVer vs Lotus Domino Server 7.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24518" source="XF">lotus-domino-ldap-dos(24518)</ref>
      <ref url="http://www.securityfocus.com/bid/16523" source="BID">16523</ref>
      <ref url="http://securitytracker.com/id?1015592" source="SECTRACK">1015592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0581" published="2006-02-07" name="CVE-2006-0581" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0460" source="VUPEN">ADV-2006-0460</ref>
      <ref url="http://securitytracker.com/id?1015584" source="SECTRACK">1015584</ref>
      <ref url="http://secunia.com/advisories/18731" source="SECUNIA" adv="1">18731</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24537" source="XF">hosting-controller-sql-injection(24537)</ref>
      <ref url="http://www.osvdb.org/22983" source="OSVDB">22983</ref>
      <ref url="http://www.osvdb.org/22982" source="OSVDB">22982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="6.1_hotfix_2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0582" published="2006-02-07" name="CVE-2006-0582" modified="2011-05-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24532" source="XF" patch="1">heimdal-rshd-privilege-elevation(24532)</ref>
      <ref url="http://www.securityfocus.com/bid/16524" source="BID" patch="1">16524</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426043/100/0/threaded" source="SUSE" patch="1">SUSE-SA:2006:011</ref>
      <ref url="http://www.pdc.kth.se/heimdal/advisory/2006-02-06/" source="CONFIRM" patch="1">http://www.pdc.kth.se/heimdal/advisory/2006-02-06/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-14</ref>
      <ref url="http://www.debian.org/security/2006/dsa-977" source="DEBIAN" patch="1" adv="1">DSA-977</ref>
      <ref url="http://secunia.com/advisories/19302" source="SECUNIA" patch="1" adv="1">19302</ref>
      <ref url="http://secunia.com/advisories/19005" source="SECUNIA" patch="1" adv="1">19005</ref>
      <ref url="http://secunia.com/advisories/18894" source="SECUNIA" patch="1" adv="1">18894</ref>
      <ref url="http://secunia.com/advisories/18806" source="SECUNIA" patch="1" adv="1">18806</ref>
      <ref url="http://secunia.com/advisories/18733" source="SECUNIA" patch="1" adv="1">18733</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0628" source="VUPEN" adv="1">ADV-2006-0628</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0456" source="VUPEN" adv="1">ADV-2006-0456</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-247-1" source="UBUNTU">USN-247-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-253-1" source="UBUNTU">USN-253-1</ref>
      <ref url="http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html" source="MLIST">[heimdal-discuss] 20060206 Heimdal 0.7.2 and 0.6.6</ref>
      <ref url="http://www.osvdb.org/22986" source="OSVDB">22986</ref>
      <ref url="http://securitytracker.com/id?1015591" source="SECTRACK">1015591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="heimdal">
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.7.1" />
        <vers num="0.7.1.1" />
        <vers num="0.7.1.2" />
        <vers num="0.7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0583" published="2006-02-07" name="CVE-2006-0583" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24545" source="XF">clevercopy-mailarticle-sql-injection(24545)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0462" source="VUPEN">ADV-2006-0462</ref>
      <ref url="http://www.osvdb.org/22984" source="OSVDB">22984</ref>
      <ref url="http://securitytracker.com/id?1015590" source="SECTRACK">1015590</ref>
      <ref url="http://secunia.com/advisories/18749" source="SECUNIA">18749</ref>
      <ref url="http://retrogod.altervista.org/Clever_Copy_V3_sql_xpl.html" source="MISC">http://retrogod.altervista.org/Clever_Copy_V3_sql_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="2.0" />
        <vers num="2.0a" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0584" published="2006-02-07" name="CVE-2006-0584" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16507" source="BID">16507</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424086/100/0/threaded" source="BUGTRAQ" adv="1">20060204 PeopleSoft (Oracle) PSCipher Encryption Weakness</ref>
      <ref url="http://www.osvdb.org/22952" source="OSVDB">22952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.4" />
        <vers num="8.40" />
        <vers num="8.41" />
        <vers num="8.42" />
        <vers num="8.43" />
        <vers num="8.45.5" />
        <vers num="8.46.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0585" published="2006-02-07" name="CVE-2006-0585" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16441" source="BID">16441</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423675/100/0/threaded" source="BUGTRAQ" adv="1">20060131 Internet Explorer remotely exploitable vulnerability in JScript's document.write() method</ref>
      <ref url="http://securitytracker.com/id?1015559" source="SECTRACK">1015559</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425422/30/6890/threaded" source="BUGTRAQ">20060217 Re: Internet Explorer remotely exploitable vulnerability in JScript's document.write() method</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0586" published="2006-02-07" name="CVE-2006-0586" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DELETE_JOB, (10) DELETE_MASTER_TABLE, (11) DETACH_JOB, (12) GET_JOB_INFO, (13) GET_JOB_QUEUES, (14) GET_SOLE_JOBNAME, (15) MASTER_TBL_LOCK, and (16) VALID_HANDLE functions in the SYS.KUPV$FT_INT package.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that these issues has been addressed by Oracle.  It is unclear which, if any, Oracle Vuln# identifiers apply to these issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24197" source="XF">oracle-syskupvftint-sql-injection(24197)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24197" source="XF">oracle-syskupv$ftint-sql-injection(24197)</ref>
      <ref url="http://www.securityfocus.com/bid/16294" source="BID">16294</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422424/30/7370/threaded" source="BUGTRAQ">20060117 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422423/30/7370/threaded" source="BUGTRAQ">20060117 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22840" source="OSVDB">22840</ref>
      <ref url="http://www.osvdb.org/22839" source="OSVDB">22839</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041499.html" source="FULLDISC" adv="1">20060118 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041498.html" source="FULLDISC" adv="1">20060118 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.0.2" />
        <vers num="10.1.0.3" />
        <vers num="10.1.0.3.1" />
        <vers num="10.1.0.4" />
        <vers num="10.1.2" />
        <vers num="10.1.2.0.1" />
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.1.0" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_10.1.0.3" />
        <vers num="enterprise_10.1.0.3.1" />
        <vers num="enterprise_10.1.0.4" />
        <vers num="personal_10.1.0.2" />
        <vers num="personal_10.1.0.3" />
        <vers num="personal_10.1.0.4" />
        <vers num="personal_10.10.3.1" />
        <vers num="standard_10.1.0.2" />
        <vers num="standard_10.1.0.3" />
        <vers num="standard_10.1.0.3.1" />
        <vers num="standard_10.1.0.4" />
        <vers num="standard_10.1.0.4.2" />
        <vers num="standard_10.1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0587" published="2006-02-07" name="CVE-2006-0587" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24768" source="XF" patch="1">gallery-util-file-include(24768)</ref>
      <ref url="http://www.securityfocus.com/bid/16533" source="BID" patch="1">16533</ref>
      <ref url="http://www.osvdb.org/22944" source="OSVDB" patch="1">22944</ref>
      <ref url="http://securitytracker.com/id?1015641" source="SECTRACK" patch="1">1015641</ref>
      <ref url="http://secunia.com/advisories/18735" source="SECUNIA" patch="1" adv="1">18735</ref>
      <ref url="http://gallery.menalto.com/gallery_1_5_2_pl2_security_release" source="CONFIRM" patch="1">http://gallery.menalto.com/gallery_1_5_2_pl2_security_release</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24538" source="XF">gallery-album-data-modification(24538)</ref>
      <ref url="http://www.osvdb.org/23256" source="OSVDB">23256</ref>
      <ref url="http://www.digitalarmaments.com/2006140293402395.html" source="MISC">http://www.digitalarmaments.com/2006140293402395.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0286.html" source="BUGTRAQ">20060216 Re: Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gallery remote file execution</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0224.html" source="BUGTRAQ">20060214 Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gallery remote file execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.4" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_pl1" />
        <vers num="1.4.3_pl2" />
        <vers num="1.4.4_pl2" />
        <vers num="1.4.4_pl3" />
        <vers num="1.4.4_pl4" />
        <vers num="1.4.4_pl5" />
        <vers num="1.4_pl1" />
        <vers num="1.4_pl2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1_rc2" />
        <vers num="1.5.2_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0588" published="2006-02-07" name="CVE-2006-0588" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in MyTopix 1.2.3 allows remote attackers to execute arbitrary SQL commands via the (1) mid and (2) keywords parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423950/100/0/threaded" source="BUGTRAQ" adv="1">20060204 [KAPDA::#26] - MyTopix Sql Injection &amp; Path Disclosure</ref>
      <ref url="http://kapda.ir/advisory-249.html" source="MISC" adv="1">http://kapda.ir/advisory-249.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24502" source="XF">mytopix-search-sql-injection(24502)</ref>
      <ref url="http://securityreason.com/securityalert/413" source="SREASON">413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaia_interactive" name="mytopix">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0589" published="2006-02-07" name="CVE-2006-0589" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MyTopix 1.2.3 allows remote attackers to obtain the installation path via a direct request to logon.mod.php, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423950/100/0/threaded" source="BUGTRAQ" adv="1">20060204 [KAPDA::#26] - MyTopix Sql Injection &amp; Path Disclosure</ref>
      <ref url="http://kapda.ir/advisory-249.html" source="MISC" adv="1">http://kapda.ir/advisory-249.html</ref>
      <ref url="http://securityreason.com/securityalert/413" source="SREASON">413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaia_interactive" name="mytopix">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0590" published="2006-02-07" name="CVE-2006-0590" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MyTopix 1.2.3 allows remote attackers to obtain the installation path via an invalid hl parameter to index.php, which leads to path disclosure, possibly related to invalid SQL syntax.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423950/100/0/threaded" source="BUGTRAQ" adv="1">20060204 [KAPDA::#26] - MyTopix Sql Injection &amp; Path Disclosure</ref>
      <ref url="http://kapda.ir/advisory-249.html" source="MISC" adv="1">http://kapda.ir/advisory-249.html</ref>
      <ref url="http://securityreason.com/securityalert/413" source="SREASON">413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaia_interactive" name="mytopix">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0591" published="2006-02-07" name="CVE-2006-0591" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.</descript>
      <descript source="nvd">This vulnerability may only be exploited in conjunction with another vulnerability.  The password file (normally shadowed) must first be stolen.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24590" source="XF" patch="1">cryptblowfish-salt-information-disclosure(24590)</ref>
      <ref url="http://secunia.com/advisories/18772" source="SECUNIA" patch="1" adv="1">18772</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0477" source="VUPEN" adv="1">ADV-2006-0477</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424260/100/0/threaded" source="BUGTRAQ">20060207 crypt_blowfish 1.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0526.html" source="REDHAT">RHSA-2006:0526</ref>
      <ref url="http://www.osvdb.org/23005" source="OSVDB">23005</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm</ref>
      <ref url="http://secunia.com/advisories/20782" source="SECUNIA" adv="1">20782</ref>
      <ref url="http://secunia.com/advisories/20653" source="SECUNIA" adv="1">20653</ref>
      <ref url="http://secunia.com/advisories/20232" source="SECUNIA" adv="1">20232</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11502" source="OVAL">oval:org.mitre.oval:def:11502</ref>
      <ref url="http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/glibc/crypt_blowfish/crypt_gensalt.c?only_with_tag=CRYPT_BLOWFISH_1_0" source="MISC">http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/glibc/crypt_blowfish/crypt_gensalt.c?only_with_tag=CRYPT_BLOWFISH_1_0</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" source="SGI">20060602-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solar_designer" name="crypt_blowfish">
        <vers num="0.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0592" published="2006-02-07" name="CVE-2006-0592" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Lexmark Printer Sharing LexBce Server Service (LexPPS), possibly 8.29 and 9.41, allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based on a vague initial disclosure; details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24581" source="XF">lexmark-lexpps-code-execution(24581)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0481" source="VUPEN" adv="1">ADV-2006-0481</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424273/100/0/threaded" source="BUGTRAQ" adv="1">20060207 High Risk Vulnerability in Lexmark Printer Sharing Service</ref>
      <ref url="http://securitytracker.com/id?1015593" source="SECTRACK">1015593</ref>
      <ref url="http://secunia.com/advisories/18744" source="SECUNIA" adv="1">18744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="printer_sharing">
        <vers num="8.29" />
        <vers num="9.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0593" published="2006-02-07" name="CVE-2006-0593" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via the (1) shout_name field in shoutbox_panel.php and the (2) comments field in comments_include.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0463" source="VUPEN">ADV-2006-0463</ref>
      <ref url="http://www.php-fusion.co.uk/news.php?readmore=307" source="CONFIRM">http://www.php-fusion.co.uk/news.php?readmore=307</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24548" source="XF">phpfusion-multiple-xss(24548)</ref>
      <ref url="http://www.securityfocus.com/bid/16548" source="BID">16548</ref>
      <ref url="http://www.php-fusion.co.uk/downloads.php?cat_id=3" source="CONFIRM">http://www.php-fusion.co.uk/downloads.php?cat_id=3</ref>
      <ref url="http://www.osvdb.org/22981" source="OSVDB">22981</ref>
      <ref url="http://www.osvdb.org/22980" source="OSVDB">22980</ref>
      <ref url="http://secunia.com/advisories/18949" source="SECUNIA">18949</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="6.00.100" />
        <vers num="6.00.101" />
        <vers num="6.00.102" />
        <vers num="6.00.103" />
        <vers num="6.00.104" />
        <vers num="6.00.105" />
        <vers num="6.00.106" />
        <vers num="6.00.107" />
        <vers num="6.00.108" />
        <vers num="6.00.109" />
        <vers num="6.00.110" />
        <vers num="6.00.200" />
        <vers num="6.00.204" />
        <vers num="6.00.205" />
        <vers num="6.00.206" />
        <vers num="6.00.207" />
        <vers num="6.00.300" />
        <vers num="6.00.303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0597" published="2006-02-13" name="CVE-2006-0597" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long "revision attributes".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN" patch="1" adv="1">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA" patch="1" adv="1">18783</ref>
      <ref url="http://www.securityfocus.com/bid/16579" source="BID">16579</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/0001-r1333-Fixed-crashes-with-very-long-revisions-attributes.txt?bug=349528;msg=15;att=1" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi/0001-r1333-Fixed-crashes-with-very-long-revisions-attributes.txt?bug=349528;msg=15;att=1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24704" source="XF">elog-elogd-bo(24704)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0598" published="2006-02-13" name="CVE-2006-0598" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16579" source="BID" patch="1">16579</ref>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN" patch="1" adv="1">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA" patch="1" adv="1">18783</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/0002-r1335-Applied-patch-from-Emiliano-to-fix-possible-buffer-overflow.txt?bug=349528;msg=15;att=2" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi/0002-r1335-Applied-patch-from-Emiliano-to-fix-possible-buffer-overflow.txt?bug=349528;msg=15;att=2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24705" source="XF">elog-elogd-log-bo(24705)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0599" published="2006-02-13" name="CVE-2006-0599" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN" patch="1" adv="1">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA" patch="1" adv="1">18783</ref>
      <ref url="http://www.securityfocus.com/bid/16579" source="BID">16579</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/0003-r1472-Do-not-distinguish-between-invalid-user-name-and-invalid-password.txt?bug=349528;msg=15;att=3" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi/0003-r1472-Do-not-distinguish-between-invalid-user-name-and-invalid-password.txt?bug=349528;msg=15;att=3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24706" source="XF">elog-elog-elogd-user-enumeration(24706)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0600" published="2006-02-13" name="CVE-2006-0600" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN" patch="1" adv="1">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA" patch="1" adv="1">18783</ref>
      <ref url="http://www.securityfocus.com/bid/16579" source="BID">16579</ref>
      <ref url="http://savannah.psi.ch/viewcvs/trunk/src/elogd.c?root=elog&amp;rev=1487&amp;view=diff&amp;r1=1487&amp;r2=1486&amp;p1=trunk/src/elogd.c&amp;p2=/trunk/src/elogd.c" source="MISC">http://savannah.psi.ch/viewcvs/trunk/src/elogd.c?root=elog&amp;rev=1487&amp;view=diff&amp;r1=1487&amp;r2=1486&amp;p1=trunk/src/elogd.c&amp;p2=/trunk/src/elogd.c</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24707" source="XF">elog-fail-redirect-dos(24707)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0602" published="2006-02-08" name="CVE-2006-0602" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5) admin/add_lang.php, or (6) admin/edit_filter.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0480" source="VUPEN" adv="1">ADV-2006-0480</ref>
      <ref url="http://www.securityfocus.com/bid/16541" source="BID">16541</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424740/100/0/threaded" source="BUGTRAQ">20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015620" source="SECTRACK">1015620</ref>
      <ref url="http://secunia.com/advisories/18758" source="SECUNIA" adv="1">18758</ref>
      <ref url="http://evuln.com/vulns/58/summary.html" source="MISC">http://evuln.com/vulns/58/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphg_guestbook">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0603" published="2006-02-08" name="CVE-2006-0603" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18758" source="SECUNIA" patch="1" adv="1">18758</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0480" source="VUPEN" adv="1">ADV-2006-0480</ref>
      <ref url="http://www.securityfocus.com/bid/16541" source="BID">16541</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424740/100/0/threaded" source="BUGTRAQ">20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015620" source="SECTRACK">1015620</ref>
      <ref url="http://evuln.com/vulns/58/summary.html" source="MISC" adv="1">http://evuln.com/vulns/58/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphg_guestbook">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0604" published="2006-02-08" name="CVE-2006-0604" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0480" source="VUPEN">ADV-2006-0480</ref>
      <ref url="http://www.securityfocus.com/bid/16541" source="BID">16541</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424740/100/0/threaded" source="BUGTRAQ">20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015620" source="SECTRACK">1015620</ref>
      <ref url="http://secunia.com/advisories/18758" source="SECUNIA" adv="1">18758</ref>
      <ref url="http://evuln.com/vulns/58/description.html" source="MISC">http://evuln.com/vulns/58/description.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphg_guestbook">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0605" published="2006-02-08" name="CVE-2006-0605" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0476" source="VUPEN">ADV-2006-0476</ref>
      <ref url="http://secunia.com/advisories/18759" source="SECUNIA" adv="1">18759</ref>
      <ref url="http://evuln.com/vulns/55/summary.html" source="MISC" adv="1">http://evuln.com/vulns/55/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24440" source="XF">shoutbox-multiple-xss(24440)</ref>
      <ref url="http://www.securityfocus.com/bid/16543" source="BID">16543</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424679/100/0/threaded" source="BUGTRAQ">20060209 [eVuln] Unknown Domain Shoutbox multiple XSS &amp; SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unknown_domain" name="shoutbox">
        <vers num="2005-07-21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0606" published="2006-02-08" name="CVE-2006-0606" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0476" source="VUPEN">ADV-2006-0476</ref>
      <ref url="http://secunia.com/advisories/18759" source="SECUNIA" adv="1">18759</ref>
      <ref url="http://evuln.com/vulns/55/summary.html" source="MISC" adv="1">http://evuln.com/vulns/55/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16543" source="BID">16543</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424679/100/0/threaded" source="BUGTRAQ">20060209 [eVuln] Unknown Domain Shoutbox multiple XSS &amp; SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unknown_domain" name="shoutbox">
        <vers num="2005-07-21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0607" published="2006-02-08" name="CVE-2006-0607" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24510" source="XF">phphd-check-security-bypass(24510)</ref>
      <ref url="http://www.evuln.com/vulns/60/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/60/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16586" source="BID">16586</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424827/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] phphd Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23026" source="OSVDB">23026</ref>
      <ref url="http://secunia.com/advisories/18793" source="SECUNIA">18793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphd">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0608" published="2006-02-08" name="CVE-2006-0608" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknown attack vectors to scripts that display information from the database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24515" source="XF">phphd-multiple-sql-injection(24515)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24508" source="XF">phphd-check-sql-injection(24508)</ref>
      <ref url="http://www.evuln.com/vulns/60/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/60/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16586" source="BID">16586</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424827/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] phphd Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23028" source="OSVDB">23028</ref>
      <ref url="http://www.osvdb.org/23025" source="OSVDB">23025</ref>
      <ref url="http://secunia.com/advisories/18793" source="SECUNIA">18793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphd">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0609" published="2006-02-08" name="CVE-2006-0609" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24513" source="XF">phphd-add-xss(24513)</ref>
      <ref url="http://www.evuln.com/vulns/60/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/60/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16586" source="BID">16586</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424827/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] phphd Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23027" source="OSVDB">23027</ref>
      <ref url="http://secunia.com/advisories/18793" source="SECUNIA">18793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphd">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0610" published="2006-02-08" name="CVE-2006-0610" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in 2200net Calendar system 1.2, with gpc_magic_quotes disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the fm_data[id] parameter to calendar.php and (2) the $ad['acc'] variable in adminlogin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24484" source="XF">2200net-adminlogin-sql-injection(24484)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24483" source="XF">2200net-calendar-sql-injection(24483)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0486" source="VUPEN">ADV-2006-0486</ref>
      <ref url="http://www.evuln.com/vulns/62/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/62/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16569" source="BID">16569</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425094/100/0/threaded" source="BUGTRAQ">20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication Bypass Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23038" source="OSVDB">23038</ref>
      <ref url="http://www.osvdb.org/23037" source="OSVDB">23037</ref>
      <ref url="http://secunia.com/advisories/18781" source="SECUNIA">18781</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114003781801861&amp;w=2" source="BUGTRAQ">20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2200net" name="2200net_calendar">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0611" published="2006-02-08" name="CVE-2006-0611" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18646" source="SECUNIA" patch="1" adv="1">18646</ref>
      <ref url="http://kb.atmail.com/view_article.php?num=374" source="CONFIRM" patch="1">http://kb.atmail.com/view_article.php?num=374</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0415" source="VUPEN">ADV-2006-0415</ref>
      <ref url="http://www.securityfocus.com/bid/16470" source="BID">16470</ref>
      <ref url="http://www.osvdb.org/22882" source="OSVDB">22882</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atmail" name="atmail">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0612" published="2006-02-08" name="CVE-2006-0612" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Powersave daemon before 0.10.15.2 allows local users to gain privileges (unauthorized access to an X session) via unspecified vectors. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=379792&amp;group_id=124576" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=379792&amp;group_id=124576</ref>
      <ref url="http://secunia.com/advisories/18651" source="SECUNIA" patch="1" adv="1">18651</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24458" source="XF">powersave-daemon-gain-privileges(24458)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0416" source="VUPEN">ADV-2006-0416</ref>
      <ref url="http://www.securityfocus.com/bid/16469" source="BID">16469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powersave" name="powersave">
        <vers prev="1" num="0.10.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0613" published="2006-02-08" name="CVE-2006-0613" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Java Web Start after 1.0.1_02, as used in J2SE 5.0 Update 5 and earlier, allows remote attackers to obtain privileges via unspecified vectors involving untrusted applications.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/652636" source="CERT-VN">VU#652636</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102170-1" source="SUNALERT" patch="1" adv="1">102170</ref>
      <ref url="http://secunia.com/advisories/18762" source="SECUNIA" patch="1" adv="1">18762</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1398" source="VUPEN">ADV-2006-1398</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0468" source="VUPEN">ADV-2006-0468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24568" source="XF">javawebstart-jnlp-privilege-elevation(24568)</ref>
      <ref url="http://www.securityfocus.com/bid/16540" source="BID">16540</ref>
      <ref url="http://securitytracker.com/id?1015597" source="SECTRACK">1015597</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303658" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2se">
        <vers prev="1" num="5.0_update5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0614" published="2006-02-08" name="CVE-2006-0614" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "first issue."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/759996" source="CERT-VN">VU#759996</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1" source="SUNALERT" patch="1" adv="1">102171</ref>
      <ref url="http://secunia.com/advisories/18760" source="SECUNIA" patch="1" adv="1">18760</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1398" source="VUPEN">ADV-2006-1398</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0828" source="VUPEN">ADV-2006-0828</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0467" source="VUPEN">ADV-2006-0467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24561" source="XF">sun-jre-reflection-privilege-elevation(24561)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml" source="GENTOO">GLSA-200602-07</ref>
      <ref url="http://securitytracker.com/id?1015596" source="SECTRACK">1015596</ref>
      <ref url="http://secunia.com/advisories/18884" source="SECUNIA">18884</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303658" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update3" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.3.1" edition="update16" />
        <vers prev="1" num="1.4.2" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update3" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers prev="1" num="1.3.1_16" />
        <vers prev="1" num="1.4.2_08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0615" published="2006-02-08" name="CVE-2006-0615" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third issues."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/759996" source="CERT-VN">VU#759996</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1" source="SUNALERT" patch="1" adv="1">102171</ref>
      <ref url="http://secunia.com/advisories/18760" source="SECUNIA" patch="1" adv="1">18760</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1398" source="VUPEN">ADV-2006-1398</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0828" source="VUPEN">ADV-2006-0828</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0467" source="VUPEN">ADV-2006-0467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24561" source="XF">sun-jre-reflection-privilege-elevation(24561)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml" source="GENTOO">GLSA-200602-07</ref>
      <ref url="http://securitytracker.com/id?1015596" source="SECTRACK">1015596</ref>
      <ref url="http://secunia.com/advisories/18884" source="SECUNIA">18884</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303658" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update4" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.4.2" edition="update9" />
        <vers prev="1" num="1.5.0" edition="update4" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers prev="1" num="1.4.2_09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0616" published="2006-02-08" name="CVE-2006-0616" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/759996" source="CERT-VN">VU#759996</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1" source="SUNALERT" patch="1" adv="1">102171</ref>
      <ref url="http://secunia.com/advisories/18760" source="SECUNIA" patch="1" adv="1">18760</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1398" source="VUPEN">ADV-2006-1398</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0828" source="VUPEN">ADV-2006-0828</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0467" source="VUPEN">ADV-2006-0467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24561" source="XF">sun-jre-reflection-privilege-elevation(24561)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml" source="GENTOO">GLSA-200602-07</ref>
      <ref url="http://securitytracker.com/id?1015596" source="SECTRACK">1015596</ref>
      <ref url="http://secunia.com/advisories/18884" source="SECUNIA">18884</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303658" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update4" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0617" published="2006-02-08" name="CVE-2006-0617" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fifth, sixth, and seventh issues."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/759996" source="CERT-VN">VU#759996</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1" source="SUNALERT" patch="1" adv="1">102171</ref>
      <ref url="http://secunia.com/advisories/18760" source="SECUNIA" patch="1" adv="1">18760</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1398" source="VUPEN">ADV-2006-1398</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0828" source="VUPEN">ADV-2006-0828</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0467" source="VUPEN">ADV-2006-0467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24561" source="XF">sun-jre-reflection-privilege-elevation(24561)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml" source="GENTOO">GLSA-200602-07</ref>
      <ref url="http://securitytracker.com/id?1015596" source="SECTRACK">1015596</ref>
      <ref url="http://secunia.com/advisories/18884" source="SECUNIA">18884</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303658" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update5" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0618" published="2006-02-08" name="CVE-2006-0618" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN">ADV-2006-0474</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=380" source="IDEFENSE" adv="1">20060207 QNX Neutrino RTOS fontsleuth Command Format String Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24559" source="XF">qnx-fontsleuth-format-string(24559)</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://www.osvdb.org/22966" source="OSVDB">22966</ref>
      <ref url="http://securitytracker.com/id?1015599" source="SECTRACK">1015599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="neutrino_rtos">
        <vers num="6.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0619" published="2006-02-08" name="CVE-2006-0619" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so.2) or (3) a long PHOTON_PATH environment variable to the setitem function in the libph library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24558" source="XF">qnx-libap-bo(24558)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24557" source="XF">qnx-libph-bo(24557)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN" adv="1">ADV-2006-0474</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://www.osvdb.org/22965" source="OSVDB">22965</ref>
      <ref url="http://www.osvdb.org/22964" source="OSVDB">22964</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=382" source="IDEFENSE" adv="1">20060207 QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=381" source="IDEFENSE" adv="1">20060207 QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015599" source="SECTRACK">1015599</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0620" published="2006-02-08" name="CVE-2006-0620" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN">ADV-2006-0474</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=383" source="IDEFENSE">20060207 QNX Neutrino RTOS phfont Race Condition Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24555" source="XF">qnx-phfont-race-condition(24555)</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://www.osvdb.org/22963" source="OSVDB">22963</ref>
      <ref url="http://securitytracker.com/id?1015599" source="SECTRACK">1015599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.2.1" />
        <vers num="6.2.1a" />
        <vers num="6.2.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0621" published="2006-02-08" name="CVE-2006-0621" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN">ADV-2006-0474</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=388" source="IDEFENSE">20060207 QNX Neutrino RTOS passwd Command Buffer Overflow</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=385" source="IDEFENSE">20060207 QNX Neutrino RTOS su Command Buffer Overflow</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24554" source="XF">qnx-su-bo(24554)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24551" source="XF">qnx-passwd-bo(24551)</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://www.osvdb.org/22961" source="OSVDB">22961</ref>
      <ref url="http://www.osvdb.org/22959" source="OSVDB">22959</ref>
      <ref url="http://securitytracker.com/id?1015599" source="SECTRACK">1015599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0622" published="2006-02-08" name="CVE-2006-0622" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a "break *0xb032d59f" command to gdb.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24553" source="XF">qnx-gdb-dos(24553)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN" adv="1">ADV-2006-0474</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://www.osvdb.org/22960" source="OSVDB">22960</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=386" source="IDEFENSE" adv="1">20060207 QNX RTOS 6.3.0 Local Denial of Service Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015598" source="SECTRACK">1015598</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0623" published="2006-02-08" name="CVE-2006-0623" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0474" source="VUPEN">ADV-2006-0474</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=387" source="IDEFENSE" adv="1">20060207 QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18750" source="SECUNIA" adv="1">18750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24552" source="XF">qnx-rclocal-root-privileges(24552)</ref>
      <ref url="http://www.securityfocus.com/bid/16539" source="BID">16539</ref>
      <ref url="http://www.osvdb.org/22958" source="OSVDB">22958</ref>
      <ref url="http://securitytracker.com/id?1015598" source="SECTRACK">1015598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0624" published="2006-02-08" name="CVE-2006-0624" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0489" source="VUPEN">ADV-2006-0489</ref>
      <ref url="http://www.securityfocus.com/bid/16544" source="BID">16544</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424389/100/0/threaded" source="BUGTRAQ">20060208 Whomp Real Estate Manager XP 2005 Sql Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24592" source="XF">whomp-login-sql-injection(24592)</ref>
      <ref url="http://www.osvdb.org/22969" source="OSVDB">22969</ref>
      <ref url="http://securityreason.com/securityalert/418" source="SREASON">418</ref>
      <ref url="http://secunia.com/advisories/18780" source="SECUNIA">18780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webeveyn" name="whomp_real_estate_manager_xp_2005">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0625" published="2006-02-09" name="CVE-2006-0625" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".."  sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0483" source="VUPEN">ADV-2006-0483</ref>
      <ref url="http://www.securityfocus.com/bid/16556" source="BID">16556</ref>
      <ref url="http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html" source="MISC">http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24600" source="XF">spip-rss-file-include(24600)</ref>
      <ref url="http://www.osvdb.org/23086" source="OSVDB">23086</ref>
      <ref url="http://securitytracker.com/id?1015602" source="SECTRACK">1015602</ref>
      <ref url="http://secunia.com/advisories/18676" source="SECUNIA">18676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers num="1.8.2d" />
        <vers num="1.8.2e" />
        <vers num="1.8.2g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0626" published="2006-02-09" name="CVE-2006-0626" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0483" source="VUPEN">ADV-2006-0483</ref>
      <ref url="http://www.securityfocus.com/bid/16551" source="BID">16551</ref>
      <ref url="http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html" source="MISC">http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24599" source="XF">spip-access-doc-sql-injection(24599)</ref>
      <ref url="http://www.osvdb.org/23087" source="OSVDB">23087</ref>
      <ref url="http://securitytracker.com/id?1015602" source="SECTRACK">1015602</ref>
      <ref url="http://secunia.com/advisories/18676" source="SECUNIA">18676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers num="1.8.2g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0627" published="2006-02-09" name="CVE-2006-0627" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Referer or (2) X-Forwarded-For headers in an HTTP request, which are not properly handled when the administrator accesses Site Stats.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24524" source="XF" adv="1">clevercopy-script-xss(24524)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0495" source="VUPEN">ADV-2006-0495</ref>
      <ref url="http://www.securityfocus.com/bid/16607" source="BID">16607</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424831/100/0/threaded" source="BUGTRAQ">20060212 [eVuln] Clever Copy 'Referer' &amp; 'X-Forwarded-For' XSS Vulnerabilities</ref>
      <ref url="http://www.evuln.com/vulns/64/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/64/summary.html</ref>
      <ref url="http://secunia.com/advisories/18790" source="SECUNIA">18790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="2.0" />
        <vers num="2.0a" />
        <vers num="23.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0628" published="2006-02-10" name="CVE-2006-0628" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.evuln.com/vulns/57/summary.html" source="MISC" patch="1" adv="1">http://www.evuln.com/vulns/57/summary.html</ref>
      <ref url="http://www.corantodemo.net/coranto/viewnews.cgi?id=EpApAAAVkyirPGThSf&amp;style=dldetails" source="MISC" patch="1">http://www.corantodemo.net/coranto/viewnews.cgi?id=EpApAAAVkyirPGThSf&amp;style=dldetails</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0443" source="VUPEN">ADV-2006-0443</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423921/100/0/threaded" source="BUGTRAQ" adv="1">20060203 [eVuln] MyQuiz Arbitrary Command Execution Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24501" source="XF">myquiz-pathinfo-command-execution(24501)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424266/100/0/threaded" source="BUGTRAQ">20060207 MyQuiz Arbitrary Command Execution Exploit (perl)</ref>
      <ref url="http://www.osvdb.org/22925" source="OSVDB">22925</ref>
      <ref url="http://securityreason.com/securityalert/409" source="SREASON">409</ref>
      <ref url="http://secunia.com/advisories/18737" source="SECUNIA">18737</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000537.html" source="VIM">20060209 Vendor ACK for MyQuiz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dale_ray" name="myquiz">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0629" published="2006-02-10" name="CVE-2006-0629" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denial of service (client crash) and possibly execute arbitrary code by tricking the user into requesting Buddy Info about a long screen name, which might cause a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24362" source="XF">aim-buddy-info-bo(24362)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423920/100/0/threaded" source="BUGTRAQ">20060203 Re: AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423906/100/0/threaded" source="BUGTRAQ">20060203 AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0948.html" source="FULLDISC">20060129 AOL Instant Messenger 5.9.3861 Local Buffer Overrun Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="5.9.3861" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0630" published="2006-02-10" name="CVE-2006-0630" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.ritlabs.com/bt/bug_view_advanced_page.php?bug_id=0003029" source="CONFIRM">https://www.ritlabs.com/bt/bug_view_advanced_page.php?bug_id=0003029</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424129/100/0/threaded" source="BUGTRAQ" adv="1">20060206 SECURITY.NNOV: The Bat! 2.x message headers spoofing</ref>
      <ref url="http://www.security.nnov.ru/advisories/thebatspoof.asp" source="MISC" adv="1">http://www.security.nnov.ru/advisories/thebatspoof.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24535" source="XF">thebat-message-header-spoofing(24535)</ref>
      <ref url="http://www.securityfocus.com/bid/16515" source="BID">16515</ref>
      <ref url="http://secunia.com/advisories/18713" source="SECUNIA">18713</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041973.html" source="FULLDISC">20060206 SECURITY.NNOV: The Bat! 2.x message headers spoofing</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ritlabs" name="the_bat">
        <vers num="3.0" />
        <vers num="3.0.0.10" />
        <vers num="3.0.0.11" />
        <vers num="3.0.0.12" />
        <vers num="3.0.0.14" />
        <vers num="3.0.0.7" />
        <vers num="3.0.0.8" />
        <vers num="3.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0631" published="2006-02-10" name="CVE-2006-0631" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "spam proxy" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22955" source="OSVDB" patch="1">22955</ref>
      <ref url="http://secunia.com/advisories/18748" source="SECUNIA" patch="1" adv="1">18748</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24540" source="XF">mailback-mail-relay(24540)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0459" source="VUPEN">ADV-2006-0459</ref>
      <ref url="http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log" source="CONFIRM">http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log</ref>
      <ref url="http://seclists.org/lists/bugtraq/2006/Feb/0154.html" source="BUGTRAQ">20060210 Re: mailback script exploit</ref>
      <ref url="http://seclists.org/lists/bugtraq/2006/Feb/0094.html" source="BUGTRAQ">20060205 mailback script exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="erik_c._thauvin" name="mailback">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0632" published="2006-02-10" name="CVE-2006-0632" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0461" source="VUPEN">ADV-2006-0461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424074/100/0/threaded" source="BUGTRAQ" adv="1">20060205 Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under.</ref>
      <ref url="http://www.r-security.net/tutorials/view/readtutorial.php?id=4" source="MISC">http://www.r-security.net/tutorials/view/readtutorial.php?id=4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24573" source="XF">phpbb-weak-rnd(24573)</ref>
      <ref url="http://www.osvdb.org/22949" source="OSVDB">22949</ref>
      <ref url="http://secunia.com/advisories/18727" source="SECUNIA">18727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0633" published="2006-02-10" name="CVE-2006-0633" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.r-security.net/tutorials/view/readtutorial.php?id=4" source="MISC" patch="1">http://www.r-security.net/tutorials/view/readtutorial.php?id=4</ref>
      <ref url="http://forums.invisionpower.com/lofiversion/index.php/t200085.html" source="MISC">http://forums.invisionpower.com/lofiversion/index.php/t200085.html</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0634" published="2006-02-10" name="CVE-2006-0634" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Borland C++Builder 6 (BCB6) with Update Pack 4 Enterprise edition (ent_upd4) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24514" source="XF">bcb-compiler-integer-overflow(24514)</ref>
      <ref url="http://www.xfocus.net/releases/200602/a849.html" source="MISC">http://www.xfocus.net/releases/200602/a849.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424085/100/0/threaded" source="BUGTRAQ" adv="1">20060206 [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability</ref>
      <ref url="http://www.osvdb.org/22953" source="OSVDB">22953</ref>
      <ref url="http://securitytracker.com/id?1015588" source="SECTRACK" adv="1">1015588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="c++_builder">
        <vers num="6" edition="enterprise_update_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0635" published="2006-02-10" name="CVE-2006-0635" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424257/100/0/threaded" source="BUGTRAQ">20060207 Re: [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability</ref>
      <ref url="http://www.osvdb.org/22956" source="OSVDB">22956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabrice_bellard" name="tiny_c_compiler">
        <vers num="0.9.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0636" published="2006-02-10" name="CVE-2006-0636" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start function, which allows remote attackers to execute arbitrary PHP code and possibly conduct other attacks by modifying critical assumed-immutable variables, as demonstrated using PHP code in the _SESSION[apps][eyeOptions.eyeapp][wrapup] variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424329/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060207 eyeOS &lt;= 0.8.9 Remote Code Execution</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00096-02072006" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00096-02072006</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0466" source="VUPEN">ADV-2006-0466</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24569" source="XF">eyeos-desktop-file-include(24569)</ref>
      <ref url="http://www.securityfocus.com/bid/16537" source="BID">16537</ref>
      <ref url="http://securitytracker.com/id?1015609" source="SECTRACK">1015609</ref>
      <ref url="http://securityreason.com/securityalert/419" source="SREASON">419</ref>
      <ref url="http://secunia.com/advisories/18757" source="SECUNIA">18757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eyeos_project" name="eyeos">
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.1_r1" />
        <vers num="0.8.2" />
        <vers num="0.8.2_r1" />
        <vers num="0.8.2_r2" />
        <vers num="0.8.2_r3" />
        <vers num="0.8.3" />
        <vers num="0.8.3_r1" />
        <vers num="0.8.3_r2" />
        <vers num="0.8.4" />
        <vers num="0.8.4_r1" />
        <vers num="0.8.5" />
        <vers num="0.8.5_r1" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0637" published="2006-02-10" name="CVE-2006-0637" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424157/100/0/threaded" source="BUGTRAQ">20060204 (OLD) Eudora WorldMail 3.0 Windows 2000 Remote System Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora_worldmail">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0638" published="2006-02-10" name="CVE-2006-0638" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0475" source="VUPEN">ADV-2006-0475</ref>
      <ref url="http://www.securityfocus.com/bid/16538" source="BID">16538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424335/100/0/threaded" source="BUGTRAQ" adv="1">20060207 [myimei]MyBB1.0.3~moderation.php~SqlInject while merging posts</ref>
      <ref url="http://www.osvdb.org/22957" source="OSVDB">22957</ref>
      <ref url="http://secunia.com/advisories/18754" source="SECUNIA">18754</ref>
      <ref url="http://myimei.com/security/2006-02-07/mybb103moderationphpsqlinject-while-merging-posts.html" source="MISC" adv="1">http://myimei.com/security/2006-02-07/mybb103moderationphpsqlinject-while-merging-posts.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0639" published="2006-02-10" name="CVE-2006-0639" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://myimei.com/security/2006-01-14/mybb-102searchphpxss-attackandmore.html" source="MISC" patch="1" adv="1">http://myimei.com/security/2006-01-14/mybb-102searchphpxss-attackandmore.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424375/100/0/threaded" source="BUGTRAQ">20060208 Re: [myimei]MyBB 1.0.2 XSS attack in search.php</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424334/100/0/threaded" source="BUGTRAQ" adv="1">20060207 [myimei]MyBB 1.0.2 XSS attack in search.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24466" source="XF">mybb-search-xss(24466)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0640" published="2006-02-10" name="CVE-2006-0640" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423955/100/0/threaded" source="BUGTRAQ">20060202 Issues with security software: orbicule.com "Undercover"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbicule" name="undercover">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0641" published="2006-02-10" name="CVE-2006-0641" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of sensitive information to an unintended remote destination.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423955/100/0/threaded" source="BUGTRAQ">20060202 Issues with security software: orbicule.com "Undercover"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbicule" name="undercover">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0642" published="2006-02-10" name="CVE-2006-0642" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424172/100/0/threaded" source="BUGTRAQ" adv="1">20060205 RE: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423914/100/0/threaded" source="BUGTRAQ" adv="1">20060203 Re: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423913/100/0/threaded" source="BUGTRAQ" adv="1">20060203 Re: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423896/100/0/threaded" source="BUGTRAQ" adv="1">20060203 Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref>
      <ref url="http://www.packetstormsecurity.org/filedesc/Bypass.pdf.html" source="MISC" adv="1">http://www.packetstormsecurity.org/filedesc/Bypass.pdf.html</ref>
      <ref url="http://www.packetstormsecurity.org/0602-advisories/Bypass.pdf" source="MISC" adv="1">http://www.packetstormsecurity.org/0602-advisories/Bypass.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24658" source="XF">serverprotect-file-scanning-bypass(24658)</ref>
      <ref url="http://www.securityfocus.com/bid/16483" source="BID">16483</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424598/100/0/threaded" source="BUGTRAQ">20060206 Fwd: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_messaging_security_suite">
        <vers num="" />
      </prod>
      <prod vendor="trend_micro" name="interscan_web_security_suite">
        <vers num="" />
      </prod>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58" edition="" />
        <vers num="5.58" edition=":emc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0643" published="2006-02-10" name="CVE-2006-0643" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0505" source="VUPEN">ADV-2006-0505</ref>
      <ref url="http://www.securityfocus.com/bid/16542" source="BID">16542</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424419/100/0/threaded" source="BUGTRAQ" adv="1">20060208 WiredRed EPOP XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24609" source="XF">epop-topic-xss(24609)</ref>
      <ref url="http://www.osvdb.org/22997" source="OSVDB">22997</ref>
      <ref url="http://securityreason.com/securityalert/421" source="SREASON">421</ref>
      <ref url="http://secunia.com/advisories/18753" source="SECUNIA">18753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wiredred" name="e_pop_web_conferencing">
        <vers num="4.1.0.755" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0644" published="2006-02-10" name="CVE-2006-0644" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16546" source="BID">16546</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424439/100/0/threaded" source="BUGTRAQ" adv="1">20060208 CPGNuke Dragonfly 9.0.6.1 remote commands execution through arbitrary local inclusion</ref>
      <ref url="http://www.osvdb.org/23058" source="OSVDB">23058</ref>
      <ref url="http://securitytracker.com/id?1015601" source="SECTRACK">1015601</ref>
      <ref url="http://retrogod.altervista.org/dragonfly9.0.6.1_incl_xpl.html" source="MISC">http://retrogod.altervista.org/dragonfly9.0.6.1_incl_xpl.html</ref>
      <ref url="http://dragonflycms.org/Forums/viewtopic/p=98034.html#98034" source="CONFIRM">http://dragonflycms.org/Forums/viewtopic/p=98034.html#98034</ref>
      <ref url="http://dragonflycms.org/Forums/viewtopic/p=98034.html" source="CONFIRM">http://dragonflycms.org/Forums/viewtopic/p=98034.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24660" source="XF">cpg-dragonfly-file-include(24660)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpg-nuke" name="dragonfly_cms">
        <vers num="9.0.6_.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0645" published="2006-02-10" name="CVE-2006-0645" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0496" source="VUPEN">ADV-2006-0496</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424538/100/0/threaded" source="BUGTRAQ">20060209 ProtoVer SSL: GnuTLS</ref>
      <ref url="http://www.gleg.net/protover_ssl.shtml" source="MISC">http://www.gleg.net/protover_ssl.shtml</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10540" source="OVAL">oval:org.mitre.oval:def:10540</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001060.html" source="MLIST">[gnutls-dev] 20060209 GnuTLS 1.3.4 - Experimental - Security release</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001059.html" source="MLIST">[gnutls-dev] 20060209 GnuTLS 1.2.10 - Security release</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001058.html" source="MLIST">[gnutls-dev] 20060209 Libtasn1 0.2.18 - Tiny ASN.1 Library - Security release</ref>
      <ref url="http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch" source="MISC">http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch</ref>
      <ref url="http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&amp;view=markup" source="CONFIRM">http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&amp;view=markup</ref>
      <ref url="http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup" source="MISC">http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24606" source="XF">gnutls-libtasn1-der-dos(24606)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-251-1" source="UBUNTU">USN-251-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0008" source="TRUSTIX">2006-0008</ref>
      <ref url="http://www.securityfocus.com/bid/16568" source="BID">16568</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00043.html" source="FEDORA">FEDORA-2006-107</ref>
      <ref url="http://www.osvdb.org/23054" source="OSVDB">23054</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:039" source="MANDRIVA">MDKSA-2006:039</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-08.xml" source="GENTOO">GLSA-200602-08</ref>
      <ref url="http://www.debian.org/security/2006/dsa-986" source="DEBIAN">DSA-986</ref>
      <ref url="http://www.debian.org/security/2006/dsa-985" source="DEBIAN">DSA-985</ref>
      <ref url="http://securitytracker.com/id?1015612" source="SECTRACK">1015612</ref>
      <ref url="http://securityreason.com/securityalert/446" source="SREASON">446</ref>
      <ref url="http://secunia.com/advisories/19092" source="SECUNIA">19092</ref>
      <ref url="http://secunia.com/advisories/19080" source="SECUNIA">19080</ref>
      <ref url="http://secunia.com/advisories/18918" source="SECUNIA">18918</ref>
      <ref url="http://secunia.com/advisories/18898" source="SECUNIA">18898</ref>
      <ref url="http://secunia.com/advisories/18832" source="SECUNIA">18832</ref>
      <ref url="http://secunia.com/advisories/18830" source="SECUNIA">18830</ref>
      <ref url="http://secunia.com/advisories/18815" source="SECUNIA">18815</ref>
      <ref url="http://secunia.com/advisories/18794" source="SECUNIA">18794</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0207.html" source="REDHAT">RHSA-2006:0207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_software_foundation_inc." name="libtasn1">
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.10" />
        <vers num="0.2.11" />
        <vers num="0.2.12" />
        <vers num="0.2.13" />
        <vers num="0.2.14" />
        <vers num="0.2.15" />
        <vers num="0.2.16" />
        <vers num="0.2.17" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0646" published="2006-02-11" name="CVE-2006-0646" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0003.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:007</ref>
      <ref url="http://www.securityfocus.com/bid/16581" source="BID">16581</ref>
      <ref url="http://secunia.com/advisories/18811" source="SECUNIA">18811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":professional" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":personal" />
        <vers num="9.1" edition=":professional" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":professional" />
        <vers num="9.2" edition=":personal" />
        <vers num="9.2" edition=":x86_64" />
        <vers num="9.3" edition="" />
        <vers num="9.3" edition=":x86_64" />
        <vers num="9.3" edition=":personal" />
        <vers num="9.3" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0647" published="2006-02-13" name="CVE-2006-0647" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0492" source="VUPEN">ADV-2006-0492</ref>
      <ref url="http://secunia.com/advisories/18769" source="SECUNIA" adv="1">18769</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002916.html" source="MLIST">[Dailydave] 20060210 ??? Sun Directory Server 5.2 fun ???</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002914.html" source="MLIST">[Dailydave] 20060208 Sun Directory Server 5.2 fun</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24605" source="XF">sun-java-ldap-dos(24605)</ref>
      <ref url="http://www.securityfocus.com/bid/16550" source="BID">16550</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102294-1" source="SUNALERT">102294</ref>
      <ref url="http://securitytracker.com/id?1015604" source="SECTRACK">1015604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_directory_server">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0648" published="2006-02-13" name="CVE-2006-0648" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424424/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060208 [eVuln] PHP iCalendar File Inclusion Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18778" source="SECUNIA" patch="1" adv="1">18778</ref>
      <ref url="http://evuln.com/vulns/70/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/70/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0493" source="VUPEN">ADV-2006-0493</ref>
      <ref url="http://www.securityfocus.com/bid/16557" source="BID">16557</ref>
      <ref url="http://phpicalendar.net/forums/viewtopic.php?t=396" source="CONFIRM">http://phpicalendar.net/forums/viewtopic.php?t=396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24591" source="XF">phpicalendar-template-search-file-include(24591)</ref>
      <ref url="http://securityreason.com/securityalert/420" source="SREASON">420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_icalendar" name="php_icalendar">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0649" published="2006-02-13" name="CVE-2006-0649" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18751" source="SECUNIA" patch="1" adv="1">18751</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0488" source="VUPEN">ADV-2006-0488</ref>
      <ref url="http://www.dataparksearch.org/ChangeLog" source="CONFIRM">http://www.dataparksearch.org/ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24627" source="XF">dataparksearch-scripts-xss(24627)</ref>
      <ref url="http://www.securityfocus.com/bid/16572" source="BID">16572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dataparksearch" name="dataparksearch">
        <vers num="4.16" />
        <vers num="4.17" />
        <vers num="4.18" />
        <vers num="4.19" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.22" />
        <vers num="4.23" />
        <vers num="4.24" />
        <vers num="4.25" />
        <vers num="4.26" />
        <vers num="4.27" />
        <vers num="4.28" />
        <vers num="4.29" />
        <vers num="4.30" />
        <vers num="4.31" />
        <vers num="4.32" />
        <vers num="4.33" />
        <vers num="4.34" />
        <vers num="4.35" />
        <vers num="4.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0650" published="2006-02-13" name="CVE-2006-0650" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24594" source="XF" patch="1">cpaint-response-type-xss(24594)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424663/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060210 CPAINT AJAX Library Cross Site Scripting</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00097-02092006" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00097-02092006</ref>
      <ref url="http://secunia.com/advisories/18765" source="SECUNIA" patch="1" adv="1">18765</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0487" source="VUPEN">ADV-2006-0487</ref>
      <ref url="http://cpaint.booleansystems.com/forums/viewtopic.php?t=98" source="CONFIRM">http://cpaint.booleansystems.com/forums/viewtopic.php?t=98</ref>
      <ref url="http://www.securityfocus.com/bid/16559" source="BID">16559</ref>
      <ref url="http://securitytracker.com/id?1015608" source="SECTRACK">1015608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpaint" name="cpaint">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3_sp" />
        <vers num="1.3_sp1" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="pre1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0651" published="2006-02-13" name="CVE-2006-0651" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16547" source="BID">16547</ref>
      <ref url="http://securitytracker.com/id?1015594" source="SECTRACK">1015594</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24583" source="XF">vwdev-uid-sql-injection(24583)</ref>
      <ref url="http://www.osvdb.org/22991" source="OSVDB">22991</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vwdev" name="vwdev">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0652" published="2006-02-13" name="CVE-2006-0652" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information.  NOTE: this report is based on a vendor bug report that identified "incorrect permissions."  However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended.  If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16560" source="BID" patch="1">16560</ref>
      <ref url="http://www.whmcs.com/changelog.php" source="CONFIRM">http://www.whmcs.com/changelog.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0484" source="VUPEN">ADV-2006-0484</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24597" source="XF">whmcs-resellers-insecure-permissions(24597)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whmcompletesolution" name="whmcompletesolution">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0653" published="2006-02-13" name="CVE-2006-0653" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18782" source="SECUNIA" adv="1">18782</ref>
      <ref url="http://evuln.com/vulns/59/summary.html" source="MISC" adv="1">http://evuln.com/vulns/59/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16562" source="BID">16562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424741/100/0/threaded" source="BUGTRAQ">20060211 [eVuln] phpht Topsites Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phpht_topsites">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0654" published="2006-02-13" name="CVE-2006-0654" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18782" source="SECUNIA" adv="1">18782</ref>
      <ref url="http://evuln.com/vulns/59/summary.html" source="MISC" adv="1">http://evuln.com/vulns/59/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16562" source="BID">16562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424741/100/0/threaded" source="BUGTRAQ">20060211 [eVuln] phpht Topsites Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phpht_topsites">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0655" published="2006-02-13" name="CVE-2006-0655" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18782" source="SECUNIA" adv="1">18782</ref>
      <ref url="http://evuln.com/vulns/59/summary.html" source="MISC" adv="1">http://evuln.com/vulns/59/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16562" source="BID">16562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424741/100/0/threaded" source="BUGTRAQ">20060211 [eVuln] phpht Topsites Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phpht_topsites">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0656" published="2006-02-13" name="CVE-2006-0656" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967" source="HP">HPSBMA02096</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967" source="HP">SSRT061108</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0497" source="VUPEN">ADV-2006-0497</ref>
      <ref url="http://www.securityfocus.com/bid/16571" source="BID">16571</ref>
      <ref url="http://secunia.com/advisories/18789" source="SECUNIA" adv="1">18789</ref>
      <ref url="http://securitytracker.com/id?1015605" source="SECTRACK">1015605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="systems_insight_manager">
        <vers num="4.2" edition="sp1" />
        <vers num="4.2" edition="sp2" />
        <vers num="5.0" edition="sp1" />
        <vers num="5.0" edition="sp2" />
        <vers num="5.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0657" published="2006-02-13" name="CVE-2006-0657" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php.  NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0507" source="VUPEN">ADV-2006-0507</ref>
      <ref url="http://secunia.com/advisories/18792" source="SECUNIA" adv="1">18792</ref>
      <ref url="http://evuln.com/vulns/63/summary.html" source="MISC" adv="1">http://evuln.com/vulns/63/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24523" source="XF">phpeventcalendar-users-xss(24523)</ref>
      <ref url="http://www.securityfocus.com/bid/16588" source="BID">16588</ref>
      <ref url="http://www.osvdb.org/23072" source="OSVDB">23072</ref>
      <ref url="http://www.osvdb.org/23071" source="OSVDB">23071</ref>
      <ref url="http://securityreason.com/securityalert/442" source="SREASON">442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softcomplex" name="php_event_calendar">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0658" published="2006-02-13" name="CVE-2006-0658" modified="2011-10-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/184.html
'CWE-184: Incomplete Blacklist'</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0502" source="VUPEN" adv="1">ADV-2006-0502</ref>
      <ref url="http://www.securityfocus.com/archive/1/424708" source="BUGTRAQ">20060209 runCMS &lt;= 1.3a2 possible remote code execution through the integrated FCKEditor package</ref>
      <ref url="http://www.milw0rm.com/exploits/3702" source="MILW0RM">3702</ref>
      <ref url="http://secunia.com/advisories/18767" source="SECUNIA" adv="1">18767</ref>
      <ref url="http://retrogod.altervista.org/fckeditor_22_xpl.html" source="MISC">http://retrogod.altervista.org/fckeditor_22_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fckeditor" name="fckeditor">
        <vers num="2.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0659" published="2006-02-13" name="CVE-2006-0659" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that both "register_globals" and "allow_url_fopen" are enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16578" source="BID" patch="1">16578</ref>
      <ref url="http://secunia.com/advisories/18800" source="SECUNIA" patch="1" adv="1">18800</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0503" source="VUPEN" adv="1">ADV-2006-0503</ref>
      <ref url="http://www.securityfocus.com/archive/1/424708" source="BUGTRAQ">20060209 runCMS &lt;= 1.3a2 possible remote code execution through the integrated FCKEditor package</ref>
      <ref url="http://retrogod.altervista.org/runcms_13a_xpl.html" source="MISC">http://retrogod.altervista.org/runcms_13a_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0660" published="2006-02-13" name="CVE-2006-0660" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".."  or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18768" source="SECUNIA" patch="1" adv="1">18768</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0506" source="VUPEN">ADV-2006-0506</ref>
      <ref url="http://www.securityfocus.com/bid/16580" source="BID">16580</ref>
      <ref url="http://www.hamid.ir/security/farsinews2-5.txt" source="MISC" adv="1">http://www.hamid.ir/security/farsinews2-5.txt</ref>
      <ref url="http://forum.farsinewsteam.com/index.php?showtopic=76" source="MISC">http://forum.farsinewsteam.com/index.php?showtopic=76</ref>
      <ref url="http://forum.farsinewsteam.com/index.php?showtopic=71" source="MISC">http://forum.farsinewsteam.com/index.php?showtopic=71</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24602" source="XF">farsinews-index-directory-traversal(24602)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24598" source="XF">farsinews-showarchives-file-include(24598)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424720/100/0/threaded" source="BUGTRAQ">20060210 FarsiNews 2.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23022" source="OSVDB">23022</ref>
      <ref url="http://www.osvdb.org/23021" source="OSVDB">23021</ref>
      <ref url="http://www.osvdb.org/23020" source="OSVDB">23020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="farsinews" name="farsinews">
        <vers num="2.1" />
        <vers num="2.1_beta2" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0661" published="2006-02-13" name="CVE-2006-0661" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0504" source="VUPEN">ADV-2006-0504</ref>
      <ref url="http://www.securityfocus.com/bid/16585" source="BID">16585</ref>
      <ref url="http://secunia.com/advisories/18786" source="SECUNIA" adv="1">18786</ref>
      <ref url="http://evuln.com/vulns/65/summary.html" source="MISC" adv="1">http://evuln.com/vulns/65/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24543" source="XF">sme-bbcode-xss(24543)</ref>
      <ref url="http://securityreason.com/securityalert/447" source="SREASON">447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptme" name="sme_blog_host">
        <vers num="" />
      </prod>
      <prod vendor="scriptme" name="sme_gb_host">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0662" published="2006-02-13" name="CVE-2006-0662" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2005-38/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-38/advisory/</ref>
      <ref url="http://secunia.com/advisories/16340" source="SECUNIA" patch="1" adv="1">16340</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0499" source="VUPEN">ADV-2006-0499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24612" source="XF">domino-webaccess-subject-xss(24612)</ref>
      <ref url="http://www.securityfocus.com/bid/16577" source="BID">16577</ref>
      <ref url="http://www.osvdb.org/23077" source="OSVDB">23077</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919</ref>
      <ref url="http://securitytracker.com/id?1015610" source="SECTRACK">1015610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_inotes_client">
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0663" published="2006-02-13" name="CVE-2006-0663" modified="2012-01-18" discovered="2005-08-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java&amp;#13;script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
IBM, Lotus Domino iNotes Client, 6.5.5
IBM, Lotus Domino iNotes Client, 7.0.1</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24614" source="XF" patch="1">domino-webaccess-filename-xss(24614)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24613" source="XF" patch="1">domino-webaccess-javascript-xss(24613)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24611" source="XF" patch="1">domino-webaccess-attachment-xss(24611)</ref>
      <ref url="http://www.securityfocus.com/bid/16577" source="BID" patch="1">16577</ref>
      <ref url="http://www.osvdb.org/23079" source="OSVDB" patch="1">23079</ref>
      <ref url="http://www.osvdb.org/23078" source="OSVDB" patch="1">23078</ref>
      <ref url="http://www.osvdb.org/23077" source="OSVDB" patch="1">23077</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919</ref>
      <ref url="http://securitytracker.com/id?1015610" source="SECTRACK" patch="1">1015610</ref>
      <ref url="http://secunia.com/secunia_research/2005-38/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-38/advisory/</ref>
      <ref url="http://secunia.com/advisories/16340" source="SECUNIA" patch="1" adv="1">16340</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0499" source="VUPEN" adv="1">ADV-2006-0499</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_inotes_client">
        <vers num="6.5.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0664" published="2006-02-13" name="CVE-2006-0664" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  An original vendor bug report is referenced, but not accessible to the general public.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16561" source="BID" patch="1">16561</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0485" source="VUPEN">ADV-2006-0485</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24585" source="XF">mantis-configdefaultsinc-xss(24585)</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1133" source="DEBIAN">DSA-1133</ref>
      <ref url="http://secunia.com/advisories/21400" source="SECUNIA">21400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.17.1" />
        <vers num="0.17.2" />
        <vers num="0.17.3" />
        <vers num="0.17.4" />
        <vers num="0.17.4a" />
        <vers num="0.17.5" />
        <vers num="0.18" />
        <vers num="0.18.0_rc1" />
        <vers num="0.18.0a2" />
        <vers num="0.18.0a3" />
        <vers num="0.18.0a4" />
        <vers num="0.18.2" />
        <vers num="0.18.3" />
        <vers num="0.18a1" />
        <vers num="0.19.0" />
        <vers num="0.19.0_rc1" />
        <vers num="0.19.0a" />
        <vers num="0.19.0a1" />
        <vers num="0.19.0a2" />
        <vers num="0.19.1" />
        <vers num="0.19.2" />
        <vers num="0.19.3" />
        <vers num="0.19.4" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers num="1.0.0_rc4" />
        <vers num="1.0.0a1" />
        <vers num="1.0.0a2" />
        <vers num="1.0.0a3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0665" published="2006-02-13" name="CVE-2006-0665" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  An original vendor bug report is referenced, but not accessible to the general public.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16561" source="BID" patch="1">16561</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0485" source="VUPEN">ADV-2006-0485</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1133" source="DEBIAN">DSA-1133</ref>
      <ref url="http://secunia.com/advisories/21400" source="SECUNIA">21400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.17.1" />
        <vers num="0.17.2" />
        <vers num="0.17.3" />
        <vers num="0.17.4" />
        <vers num="0.17.4a" />
        <vers num="0.17.5" />
        <vers num="0.18" />
        <vers num="0.18.0_rc1" />
        <vers num="0.18.0a2" />
        <vers num="0.18.0a3" />
        <vers num="0.18.0a4" />
        <vers num="0.18.2" />
        <vers num="0.18.3" />
        <vers num="0.18a1" />
        <vers num="0.19.0" />
        <vers num="0.19.0_rc1" />
        <vers num="0.19.0a" />
        <vers num="0.19.0a1" />
        <vers num="0.19.0a2" />
        <vers num="0.19.1" />
        <vers num="0.19.2" />
        <vers num="0.19.3" />
        <vers num="0.19.4" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers num="1.0.0_rc4" />
        <vers num="1.0.0a1" />
        <vers num="1.0.0a2" />
        <vers num="1.0.0a3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0666" published="2006-02-15" name="CVE-2006-0666" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16624" source="BID" patch="1">16624</ref>
      <ref url="http://secunia.com/advisories/18795" source="SECUNIA" patch="1" adv="1">18795</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0573" source="VUPEN">ADV-2006-0573</ref>
      <ref url="http://www.osvdb.org/23127" source="OSVDB">23127</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY79595&amp;apar=only" source="AIXAPAR">IY79595</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24711" source="XF">aix-kernel-dos(24711)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0667" published="2006-03-09" name="CVE-2006-0667" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015622" source="SECTRACK" patch="1">1015622</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2096" source="VUPEN">ADV-2005-2096</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY77638" source="AIXAPAR">IY77638</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY77624" source="AIXAPAR">IY77624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0668" published="2006-02-13" name="CVE-2006-0668" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in message.php in the espace_membre module.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19023" source="SECUNIA" patch="1" adv="1">19023</ref>
      <ref url="http://www.securityfocus.com/bid/16567/exploit" source="MISC">http://www.securityfocus.com/bid/16567/exploit</ref>
      <ref url="http://www.securityfocus.com/bid/16567" source="BID">16567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0669" published="2006-02-13" name="CVE-2006-0669" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter.  NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database.  SecurityTracker's research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16563" source="BID">16563</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-February/000561.html" source="VIM">20060220 vendor dispute for CVE-2006-0669</ref>
      <ref url="http://securitytracker.com/id?1015600" source="SECTRACK">1015600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24616" source="XF">gasforumlight-archive-sql-injection(24616)</ref>
      <ref url="http://www.osvdb.org/23509" source="OSVDB">23509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gasoft" name="gas_forum_light">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0670" published="2006-02-13" name="CVE-2006-0670" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to caues a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24533" source="XF">hcidump-bluetooth-dos(24533)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0479" source="VUPEN">ADV-2006-0479</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424133/100/0/threaded" source="BUGTRAQ" adv="1">20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump 1.29 + PoC</ref>
      <ref url="http://www.secuobs.com/news/05022006-bluetooth9.shtml#english" source="MISC">http://www.secuobs.com/news/05022006-bluetooth9.shtml#english</ref>
      <ref url="http://secunia.com/advisories/18741" source="SECUNIA" adv="1">18741</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113924625825488&amp;w=2" source="FULLDISC" adv="1">20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump</ref>
      <ref url="http://www.ubuntu.com/usn/usn-256-1" source="UBUNTU">USN-256-1</ref>
      <ref url="http://www.osvdb.org/23056" source="OSVDB">23056</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:041" source="MANDRIVA">MDKSA-2006:041</ref>
      <ref url="http://www.debian.org/security/2006/dsa-990" source="DEBIAN">DSA-990</ref>
      <ref url="http://securityreason.com/securityalert/465" source="SREASON">465</ref>
      <ref url="http://secunia.com/advisories/19122" source="SECUNIA">19122</ref>
      <ref url="http://secunia.com/advisories/18971" source="SECUNIA">18971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluez_project" name="hcidump">
        <vers num="1.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0671" published="2006-02-13" name="CVE-2006-0671" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to caues a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24534" source="XF">sony-bluetooth-dos(24534)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0478" source="VUPEN">ADV-2006-0478</ref>
      <ref url="http://www.secuobs.com/news/05022006-bluetooth7.shtml#english" source="MISC">http://www.secuobs.com/news/05022006-bluetooth7.shtml#english</ref>
      <ref url="http://secunia.com/advisories/18747" source="SECUNIA" adv="1">18747</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113924661724270&amp;w=2" source="FULLDISC" adv="1">20060206 [Full-disclosure] [ Secuobs - Advisory ] Bluetooth : DoS on</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113926179907655&amp;w=2" source="BUGTRAQ" adv="1">20060206 [ Secuobs - Advisory ] Bluetooth : DoS on Sony/Ericsson cell phones</ref>
      <ref url="http://www.securityfocus.com/bid/16512" source="BID">16512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sony_ericsson" name="k600i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="t68i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="v600i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="w800i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0672" published="2006-02-13" name="CVE-2006-0672" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16583" source="BID" patch="1">16583</ref>
      <ref url="http://secunia.com/advisories/18770" source="SECUNIA" patch="1" adv="1">18770</ref>
      <ref url="http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?dlc=en&amp;lc=en&amp;os=228%20&amp;product=90764&amp;lang=en&amp;cc=us&amp;softwareitem=oj-37641-1" source="CONFIRM" patch="1">http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?dlc=en&amp;lc=en&amp;os=228%20&amp;product=90764&amp;lang=en&amp;cc=us&amp;softwareitem=oj-37641-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0498" source="VUPEN" adv="1">ADV-2006-0498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="psc_1210_all-in-one">
        <vers num="1.0" />
        <vers num="1.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0673" published="2006-02-13" name="CVE-2006-0673" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24588" source="XF">magiccalendar-index-sql-injection(24588)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0525" source="VUPEN">ADV-2006-0525</ref>
      <ref url="http://evuln.com/vulns/71/summary.html" source="MISC" adv="1">http://evuln.com/vulns/71/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16734" source="BID">16734</ref>
      <ref url="http://www.securityfocus.com/bid/16646" source="BID">16646</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425491/100/0/threaded" source="BUGTRAQ">20060220 [eVuln] Magic Calendar Lite Authentication Bypass</ref>
      <ref url="http://securitytracker.com/id?1015650" source="SECTRACK">1015650</ref>
      <ref url="http://securityreason.com/securityalert/459" source="SREASON">459</ref>
      <ref url="http://secunia.com/advisories/18855" source="SECUNIA">18855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_calendar_lite">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0674" published="2006-02-13" name="CVE-2006-0674" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16584" source="BID" patch="1">16584</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0531" source="VUPEN">ADV-2006-0531</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY81476" source="AIXAPAR">IY81476</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=0&amp;q1=IY81424&amp;uid=isg1IY81424&amp;loc=en_US&amp;cs=utf-8&amp;cc=us&amp;lang=en" source="AIXAPAR">IY81424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24628" source="XF">aix-arp-iftype-bo(24628)</ref>
      <ref url="http://secunia.com/advisories/18773" source="SECUNIA">18773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0675" published="2006-02-13" name="CVE-2006-0675" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0533" source="VUPEN">ADV-2006-0533</ref>
      <ref url="http://siteframe.org/p/xss_vulnerability_in_siteframe_501" source="CONFIRM">http://siteframe.org/p/xss_vulnerability_in_siteframe_501</ref>
      <ref url="http://secunia.com/advisories/18804" source="SECUNIA" adv="1">18804</ref>
      <ref url="http://kiki91.altervista.org/exploit/siteframe5.0.1a_xss.txt" source="MISC" adv="1">http://kiki91.altervista.org/exploit/siteframe5.0.1a_xss.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24649" source="XF">siteframe-search-request-xss(24649)</ref>
      <ref url="http://www.securityfocus.com/bid/16596" source="BID">16596</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424844/100/0/threaded" source="BUGTRAQ">20060212 Siteframe Beaumont 5.0.1a &lt;== Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glen_campbell" name="siteframe">
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0676" published="2006-02-13" name="CVE-2006-0676" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/advisory-44.html" source="MISC" adv="1">http://www.waraxe.us/advisory-44.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0542" source="VUPEN">ADV-2006-0542</ref>
      <ref url="http://secunia.com/advisories/18820" source="SECUNIA" adv="1">18820</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24650" source="XF">phpnuke-header-xss(24650)</ref>
      <ref url="http://www.securityfocus.com/bid/16608" source="BID">16608</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424956/100/0/threaded" source="BUGTRAQ">20060214 [waraxe-2006-SA#044] - XSS in phpNuke 7.8 and older versions</ref>
      <ref url="http://securityreason.com/securityalert/425" source="SREASON">425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers num="7.8" />
        <vers num="7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0677" published="2006-02-14" name="CVE-2006-0677" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html" source="MLIST" patch="1">[heimdal-discuss] 20060206 Heimdal 0.7.2 and 0.6.6</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0653" source="VUPEN">ADV-2006-0653</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0628" source="VUPEN">ADV-2006-0628</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0456" source="VUPEN">ADV-2006-0456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24763" source="XF">heimdal-telnetd-dos(24763)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-253-1" source="UBUNTU">USN-253-1</ref>
      <ref url="http://www.securityfocus.com/bid/16676" source="BID">16676</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426043/100/0/threaded" source="SUSE">SUSE-SA:2006:011</ref>
      <ref url="http://www.osvdb.org/23244" source="OSVDB">23244</ref>
      <ref url="http://www.debian.org/security/2006/dsa-977" source="DEBIAN">DSA-977</ref>
      <ref url="http://securityreason.com/securityalert/449" source="SREASON">449</ref>
      <ref url="http://secunia.com/advisories/19005" source="SECUNIA">19005</ref>
      <ref url="http://secunia.com/advisories/18961" source="SECUNIA">18961</ref>
      <ref url="http://secunia.com/advisories/18894" source="SECUNIA">18894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="heimdal">
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.7.1" />
        <vers num="0.7.1.1" />
        <vers num="0.7.1.2" />
        <vers num="0.7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0678" published="2006-02-14" name="CVE-2006-0678" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="1.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="2.7" CVSS_base_score="1.5">
    <desc>
      <descript source="cve">PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18890" source="SECUNIA" patch="1" adv="1">18890</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24719" source="XF">postgresql-setsessionauth-dos(24719)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0605" source="VUPEN">ADV-2006-0605</ref>
      <ref url="http://www.ubuntu.com/usn/usn-258-1" source="UBUNTU">USN-258-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0008" source="TRUSTIX">2006-0008</ref>
      <ref url="http://www.securityfocus.com/bid/16650" source="BID">16650</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425037/100/0/threaded" source="SECTRACK">1015636</ref>
      <ref url="http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3" source="CONFIRM">http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html" source="OPENPKG" adv="1">OpenPKG-SA-2006.004</ref>
      <ref url="http://securityreason.com/securityalert/498" source="SREASON">498</ref>
      <ref url="http://secunia.com/advisories/19035" source="SECUNIA">19035</ref>
      <ref url="http://secunia.com/advisories/19015" source="SECUNIA">19015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.10" />
        <vers num="7.3.11" />
        <vers num="7.3.12" />
        <vers num="7.3.13" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.10" />
        <vers num="7.4.11" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="7.4.8" />
        <vers num="7.4.9" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0679" published="2006-02-16" name="CVE-2006-0679" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0636" source="VUPEN">ADV-2006-0636</ref>
      <ref url="http://securityreason.com/securityalert/440" source="SREASON">440</ref>
      <ref url="http://securityreason.com/securityalert/440" source="SREASON" adv="1">440</ref>
      <ref url="http://securityreason.com/achievement_securityalert/32" source="SREASONRES" adv="1">20060216 Critical SQL Injection PHPNuke &lt;= 7.8 - Your_Account module</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0358.html" source="FULLDISC" adv="1">20060216 Critical SQL Injection PHPNuke &lt;= 7.8 - Your_Account module</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24769" source="XF">phpnuke-youraccount-sql-injection(24769)</ref>
      <ref url="http://www.securityfocus.com/bid/16691" source="BID">16691</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425173/100/0/threaded" source="BUGTRAQ">20060216 Critical SQL Injection PHPNuke &lt;= 7.8 - Your_Account module</ref>
      <ref url="http://www.osvdb.org/23259" source="OSVDB">23259</ref>
      <ref url="http://secunia.com/advisories/18931" source="SECUNIA">18931</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke_ev">
        <vers num="7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0680" published="2006-02-14" name="CVE-2006-0680" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18819" source="SECUNIA" patch="1" adv="1">18819</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0541" source="VUPEN">ADV-2006-0541</ref>
      <ref url="http://www.plainblack.com/getwebgui/advisories/webgui-6.8.6-gamma-released" source="CONFIRM">http://www.plainblack.com/getwebgui/advisories/webgui-6.8.6-gamma-released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24695" source="XF">webgui-anonymous-bypass-security(24695)</ref>
      <ref url="http://www.securityfocus.com/bid/16612" source="BID">16612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.2.0_beta" />
        <vers num="6.2.10_gamma" />
        <vers num="6.2.11_gamma" />
        <vers num="6.2.1_beta" />
        <vers num="6.2.2_beta" />
        <vers num="6.2.3_beta" />
        <vers num="6.2.4_beta" />
        <vers num="6.2.5_beta" />
        <vers num="6.2.6_gamma" />
        <vers num="6.2.7_gamma" />
        <vers num="6.2.8_gamma" />
        <vers num="6.2.9_gamma" />
        <vers num="6.3.0_beta" />
        <vers num="6.4.0_beta" />
        <vers num="6.5.0_beta" />
        <vers num="6.5.1_beta" />
        <vers num="6.5.2_beta" />
        <vers num="6.5.3_beta" />
        <vers num="6.5.4_gamma" />
        <vers num="6.5.5_gamma" />
        <vers num="6.5.6_gamma" />
        <vers num="6.6.0_beta" />
        <vers num="6.6.1_beta" />
        <vers num="6.6.2_gamma" />
        <vers num="6.6.3_gamma" />
        <vers num="6.6.4_gamma" />
        <vers num="6.6.5_gamma" />
        <vers num="6.7.0_beta" />
        <vers num="6.7.1_beta" />
        <vers num="6.7.2_beta" />
        <vers num="6.7.3_gamma" />
        <vers num="6.7.4_gamma" />
        <vers num="6.7.5_gamma" />
        <vers num="6.7.6_gamma" />
        <vers num="6.7.7_gamma" />
        <vers num="6.7.8_gamma" />
        <vers num="6.8.1_beta" />
        <vers num="6.8.2_beta" />
        <vers num="6.8.3_gamma" />
        <vers num="6.8.4_gamma" />
        <vers num="6.8.5_gamma" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0681" published="2006-02-14" name="CVE-2006-0681" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0545" source="VUPEN">ADV-2006-0545</ref>
      <ref url="http://secunia.com/advisories/18841" source="SECUNIA" adv="1">18841</ref>
      <ref url="http://gotfault.net/research/advisory/gadv-powerd.txt" source="MISC">http://gotfault.net/research/advisory/gadv-powerd.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24713" source="XF">powerdaemon-syslog-format-string(24713)</ref>
      <ref url="http://www.securityfocus.com/bid/16582" source="BID">16582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="power_daemon" name="power_daemon">
        <vers num="2.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.1" />
        <vers num="2.0.1.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0682" published="2006-02-14" name="CVE-2006-0682" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18816" source="SECUNIA" patch="1" adv="1">18816</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0540" source="VUPEN">ADV-2006-0540</ref>
      <ref url="http://e107.org/comment.php?comment.news.776" source="CONFIRM">http://e107.org/comment.php?comment.news.776</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24625" source="XF">e107-bbcode-xss(24625)</ref>
      <ref url="http://www.securityfocus.com/bid/16614" source="BID">16614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.547_beta" />
        <vers num="0.548_beta" />
        <vers num="0.549_beta" />
        <vers num="0.551_beta" />
        <vers num="0.552_beta" />
        <vers num="0.553_beta" />
        <vers num="0.554_beta" />
        <vers num="0.555_beta" />
        <vers num="0.600" />
        <vers num="0.601" />
        <vers num="0.602" />
        <vers num="0.603" />
        <vers num="0.604" />
        <vers num="0.605" />
        <vers num="0.606" />
        <vers num="0.607" />
        <vers num="0.608" />
        <vers num="0.609" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615" />
        <vers num="0.615a" />
        <vers num="0.616" />
        <vers num="0.617" />
        <vers num="0.6171" />
        <vers num="0.6172" />
        <vers num="0.6173" />
        <vers num="0.6174" />
        <vers num="0.6175" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3_beta" />
        <vers num="5.3_beta2" />
        <vers num="5.4_beta1" />
        <vers num="5.4_beta3" />
        <vers num="5.4_beta4" />
        <vers num="5.4_beta5" />
        <vers num="5.4_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0683" published="2006-02-14" name="CVE-2006-0683" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18799" source="SECUNIA" patch="1" adv="1">18799</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0534" source="VUPEN">ADV-2006-0534</ref>
      <ref url="http://www.securityfocus.com/bid/16600" source="BID">16600</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded" source="BUGTRAQ">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24664" source="XF">vhcs-admin-xss(24664)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_hosting_control_system" name="virtual_hosting_control_system">
        <vers prev="1" num="2.4.6.2" />
        <vers num="2.4.7.1_patch_v.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0684" published="2006-02-14" name="CVE-2006-0684" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18799" source="SECUNIA" patch="1" adv="1">18799</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0534" source="VUPEN">ADV-2006-0534</ref>
      <ref url="http://www.securityfocus.com/bid/16600" source="BID">16600</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded" source="BUGTRAQ">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24665" source="XF">vhcs-change-password-weakness(24665)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_hosting_control_system" name="virtual_hosting_control_system">
        <vers prev="1" num="2.4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0685" published="2006-02-14" name="CVE-2006-0685" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18799" source="SECUNIA" patch="1" adv="1">18799</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0534" source="VUPEN">ADV-2006-0534</ref>
      <ref url="http://www.securityfocus.com/bid/16600" source="BID">16600</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded" source="BUGTRAQ">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24666" source="XF">vhcs-checklogin-auth-bypass(24666)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_hosting_control_system" name="virtual_hosting_control_system">
        <vers prev="1" num="2.4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0686" published="2006-02-14" name="CVE-2006-0686" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18799" source="SECUNIA" patch="1" adv="1">18799</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0534" source="VUPEN">ADV-2006-0534</ref>
      <ref url="http://www.securityfocus.com/bid/16600" source="BID">16600</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded" source="BUGTRAQ">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24667" source="XF">vhcs-adduser-privilege-escalation(24667)</ref>
      <ref url="http://securityreason.com/securityalert/430" source="SREASON">430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_hosting_control_system" name="virtual_hosting_control_system">
        <vers prev="1" num="2.4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0687" published="2006-02-14" name="CVE-2006-0687" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0544" source="VUPEN">ADV-2006-0544</ref>
      <ref url="http://secunia.com/advisories/18803" source="SECUNIA" adv="1">18803</ref>
      <ref url="http://retrogod.altervista.org/docmgr_0542_incl_xpl.html" source="MISC">http://retrogod.altervista.org/docmgr_0542_incl_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24694" source="XF">docmgr-process-file-include(24694)</ref>
      <ref url="http://www.securityfocus.com/bid/16601" source="BID">16601</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424818/100/0/threaded" source="BUGTRAQ">20060212 DocMGR &lt;= 0.54.2 arbitrary remote inclusion</ref>
      <ref url="http://securityreason.com/securityalert/428" source="SREASON">428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docmgr" name="docmgr">
        <vers num="0.54.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0688" published="2006-02-15" name="CVE-2006-0688" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24603" source="XF">indexu-application-file-include(24603)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0494" source="VUPEN">ADV-2006-0494</ref>
      <ref url="http://www.securityfocus.com/bid/16565" source="BID">16565</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424549/100/0/threaded" source="BUGTRAQ" adv="1">20060209 [ECHO_ADV_27$2006] Indexu &lt;= 5.0.1 Remote File Inclusion</ref>
      <ref url="http://www.osvdb.org/22989" source="OSVDB">22989</ref>
      <ref url="http://securitytracker.com/id?1015607" source="SECTRACK">1015607</ref>
      <ref url="http://secunia.com/advisories/18752" source="SECUNIA" adv="1">18752</ref>
      <ref url="http://echo.or.id/adv/adv27-K-159-2006.txt" source="MISC">http://echo.or.id/adv/adv27-K-159-2006.txt</ref>
      <ref url="http://echo.or.id/adv/adv26-K-159-2006.txt" source="MISC">http://echo.or.id/adv/adv26-K-159-2006.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicecoder" name="indexu">
        <vers num="5.0.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0689" published="2006-02-15" name="CVE-2006-0689" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24572" source="XF">timetracking-registration-xss(24572)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0524" source="VUPEN">ADV-2006-0524</ref>
      <ref url="http://www.evuln.com/vulns/69/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/69/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16630" source="BID">16630</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425505/100/0/threaded" source="BUGTRAQ">20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18854" source="SECUNIA">18854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scheduling_management.com" name="time_tracking_software">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0690" published="2006-02-15" name="CVE-2006-0690" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24571" source="XF">timetracking-multiple-sql-injection(24571)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0524" source="VUPEN">ADV-2006-0524</ref>
      <ref url="http://www.evuln.com/vulns/69/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/69/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16630" source="BID">16630</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425505/100/0/threaded" source="BUGTRAQ">20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18854" source="SECUNIA">18854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scheduling_management.com" name="time_tracking_software">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0691" published="2006-02-15" name="CVE-2006-0691" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24570" source="XF">timetracking-edituser-auth-bypass(24570)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0524" source="VUPEN">ADV-2006-0524</ref>
      <ref url="http://www.evuln.com/vulns/69/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/69/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16731" source="BID">16731</ref>
      <ref url="http://www.securityfocus.com/bid/16630" source="BID">16630</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425505/100/0/threaded" source="BUGTRAQ">20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18854" source="SECUNIA">18854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scheduling_management.com" name="time_tracking_software">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0692" published="2006-02-15" name="CVE-2006-0692" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has supplied a patch which is available at:
http://www.hotscripts.com/Detailed/51138.html</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24567" source="XF">phpmysqltimesheet-multiple-sql-injection(24567)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0522" source="VUPEN">ADV-2006-0522</ref>
      <ref url="http://www.securityfocus.com/bid/16620" source="BID">16620</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425316/100/0/threaded" source="BUGTRAQ">20060217 [eVuln] PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.evuln.com/vulns/67/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/67/summary.html</ref>
      <ref url="http://secunia.com/advisories/18822" source="SECUNIA">18822</ref>
      <ref url="http://securityreason.com/securityalert/451" source="SREASON">451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carey_briggs" name="php_mysql_timesheet">
        <vers num="1" />
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0693" published="2006-02-15" name="CVE-2006-0693" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24578" source="XF">calimba-rbauth-sql-injection(24578)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0523" source="VUPEN">ADV-2006-0523</ref>
      <ref url="http://www.evuln.com/vulns/68/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/68/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16632" source="BID">16632</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425364/100/0/threaded" source="BUGTRAQ">20060217 [eVuln] CALimba Authentication Bypass Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/453" source="SREASON">453</ref>
      <ref url="http://secunia.com/advisories/18856" source="SECUNIA">18856</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roberto_butti" name="calimba">
        <vers num="0.99.1" />
        <vers num="0.99.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0694" published="2006-02-15" name="CVE-2006-0694" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=392826" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=392826</ref>
      <ref url="http://secunia.com/advisories/18810" source="SECUNIA" patch="1" adv="1">18810</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0536" source="VUPEN">ADV-2006-0536</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24681" source="XF">ansilove-load-information-disclosure(24681)</ref>
      <ref url="http://www.securityfocus.com/bid/16603" source="BID">16603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ansilove" name="ansilove">
        <vers num="1.01" />
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0695" published="2006-02-15" name="CVE-2006-0695" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=392826" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=392826</ref>
      <ref url="http://secunia.com/advisories/18810" source="SECUNIA" patch="1" adv="1">18810</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0536" source="VUPEN">ADV-2006-0536</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24684" source="XF">ansilove-filename-code-execution(24684)</ref>
      <ref url="http://www.securityfocus.com/bid/16603" source="BID">16603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ansilove" name="ansilove">
        <vers num="1.01" />
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0696" published="2006-02-15" name="CVE-2006-0696" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=392886" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=392886</ref>
      <ref url="http://secunia.com/advisories/18801" source="SECUNIA" patch="1" adv="1">18801</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0546" source="VUPEN">ADV-2006-0546</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24701" source="XF">zencart-multiple-sql-injection(24701)</ref>
      <ref url="http://www.osvdb.org/23110" source="OSVDB">23110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zen_cart" name="zen_cart">
        <vers num="1.1.0" />
        <vers num="1.1.1d" />
        <vers num="1.1.2d" />
        <vers num="1.1.3d" />
        <vers num="1.1.4d" />
        <vers num="1.2.0d" />
        <vers num="1.2.1_patch1" />
        <vers num="1.2.1d" />
        <vers num="1.2.2d" />
        <vers num="1.2.3d" />
        <vers num="1.2.4.1" />
        <vers num="1.2.4d" />
        <vers num="1.2.5d" />
        <vers num="1.2.6d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0697" published="2006-02-15" name="CVE-2006-0697" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=392886" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=392886</ref>
      <ref url="http://secunia.com/advisories/18801" source="SECUNIA" patch="1" adv="1">18801</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0546" source="VUPEN">ADV-2006-0546</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0698" published="2006-02-15" name="CVE-2006-0698" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18801" source="SECUNIA" patch="1" adv="1">18801</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0546" source="VUPEN">ADV-2006-0546</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=392886" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=392886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24701" source="XF">zencart-multiple-sql-injection(24701)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zen_cart" name="zen_cart">
        <vers num="1.1.0" />
        <vers num="1.1.1d" />
        <vers num="1.1.2d" />
        <vers num="1.1.3d" />
        <vers num="1.1.4d" />
        <vers num="1.2.0d" />
        <vers num="1.2.1_patch1" />
        <vers num="1.2.1d" />
        <vers num="1.2.2d" />
        <vers num="1.2.3d" />
        <vers num="1.2.4.1" />
        <vers num="1.2.4d" />
        <vers num="1.2.5d" />
        <vers num="1.2.6d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0699" published="2006-02-15" name="CVE-2006-0699" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24669" source="XF">qwikiwiki-search-xss(24669)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0562" source="VUPEN">ADV-2006-0562</ref>
      <ref url="http://www.securityfocus.com/bid/16638" source="BID">16638</ref>
      <ref url="http://secunia.com/advisories/18814" source="SECUNIA" adv="1">18814</ref>
      <ref url="http://insecurity.altervista.org/index.php?m=02&amp;y=06&amp;entry=entry060213-221217" source="MISC">http://insecurity.altervista.org/index.php?m=02&amp;y=06&amp;entry=entry060213-221217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_barrett" name="qwikiwiki">
        <vers num="1.0" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0700" published="2006-02-15" name="CVE-2006-0700" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24641" source="XF">imagevue-multiple-information-disclosure(24641)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0570" source="VUPEN" adv="1">ADV-2006-0570</ref>
      <ref url="http://www.securityfocus.com/bid/16594" source="BID">16594</ref>
      <ref url="http://www.securityfocus.com/archive/1/424745/30/0/threaded" source="BUGTRAQ" adv="1">20060211 imageVue16.1 upload vulnerability</ref>
      <ref url="http://secunia.com/advisories/18802" source="SECUNIA" adv="1">18802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagevue" name="imagevue">
        <vers num="0.16.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0701" published="2006-02-15" name="CVE-2006-0701" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0570" source="VUPEN">ADV-2006-0570</ref>
      <ref url="http://www.securityfocus.com/bid/16594" source="BID">16594</ref>
      <ref url="http://www.securityfocus.com/archive/1/424745/30/0/threaded" source="BUGTRAQ" adv="1">20060211 imageVue16.1 upload vulnerability</ref>
      <ref url="http://secunia.com/advisories/18802" source="SECUNIA" adv="1">18802</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24641" source="XF">imagevue-multiple-information-disclosure(24641)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagevue" name="imagevue">
        <vers num="0.16.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0702" published="2006-02-15" name="CVE-2006-0702" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter.  NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0570" source="VUPEN">ADV-2006-0570</ref>
      <ref url="http://www.securityfocus.com/bid/16594" source="BID">16594</ref>
      <ref url="http://www.securityfocus.com/archive/1/424745/30/0/threaded" source="BUGTRAQ" adv="1">20060211 imageVue16.1 upload vulnerability</ref>
      <ref url="http://secunia.com/advisories/18802" source="SECUNIA" adv="1">18802</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24633" source="XF">imagevue-upload-file-upload(24633)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagevue" name="imagevue">
        <vers num="0.16.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0703" published="2006-02-15" name="CVE-2006-0703" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0570" source="VUPEN">ADV-2006-0570</ref>
      <ref url="http://www.securityfocus.com/bid/16594" source="BID">16594</ref>
      <ref url="http://www.securityfocus.com/archive/1/424745/30/0/threaded" source="BUGTRAQ" adv="1">20060211 imageVue16.1 upload vulnerability</ref>
      <ref url="http://secunia.com/advisories/18802" source="SECUNIA" adv="1">18802</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24642" source="XF">imagevue-index-sql-injection(24642)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/450047/100/100/threaded" source="BUGTRAQ">20061029 Re: imageVue16.1 upload vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440586/100/100/threaded" source="BUGTRAQ">20060719 Re: imageVue16.1 upload vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/429" source="SREASON">429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagevue" name="imagevue">
        <vers num="0.16.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0704" published="2006-02-15" name="CVE-2006-0704" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0568" source="VUPEN">ADV-2006-0568</ref>
      <ref url="http://www.irmplc.com/advisory016.htm" source="MISC" adv="1">http://www.irmplc.com/advisory016.htm</ref>
      <ref url="http://secunia.com/advisories/18813" source="SECUNIA" adv="1">18813</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24714" source="XF">ieintegrator-error-information-disclosure(24714)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ie" name="ie_integrator">
        <vers num="4.4.220114" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0705" published="2006-02-15" name="CVE-2006-0705" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/419241" source="CERT-VN" patch="1">VU#419241</ref>
      <ref url="http://www.securityfocus.com/bid/16625" source="BID" patch="1">16625</ref>
      <ref url="http://support.wrq.com/techdocs/1882.html" source="CONFIRM" patch="1">http://support.wrq.com/techdocs/1882.html</ref>
      <ref url="http://securitytracker.com/id?1015619" source="SECTRACK" patch="1">1015619</ref>
      <ref url="http://secunia.com/advisories/18843" source="SECUNIA" patch="1" adv="1">18843</ref>
      <ref url="http://secunia.com/advisories/18828" source="SECUNIA" patch="1" adv="1">18828</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24651" source="XF">sftp-logging-format-string(24651)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1008/references" source="VUPEN" adv="1">ADV-2008-1008</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0555" source="VUPEN" adv="1">ADV-2006-0555</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0554" source="VUPEN" adv="1">ADV-2006-0554</ref>
      <ref url="http://www.securityfocus.com/bid/16640" source="BID">16640</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-13.xml" source="GENTOO">GLSA-200703-13</ref>
      <ref url="http://secunia.com/advisories/29552" source="SECUNIA" adv="1">29552</ref>
      <ref url="http://secunia.com/advisories/24516" source="SECUNIA" adv="1">24516</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120654385125315&amp;w=2" source="HP">SSRT080011</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120654385125315&amp;w=2" source="HP">SSRT080011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="attachmatewrq" name="reflection_for_secure_it_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win" />
        <vers num="6.0" edition=":unix" />
      </prod>
      <prod vendor="f-secure" name="f-secure_ssh_server">
        <vers num="3.0.0" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":unix" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1.0" edition="" />
        <vers num="3.1.0" edition=":unix" />
        <vers num="3.1.0_build9" />
        <vers num="3.2.0" edition="" />
        <vers num="3.2.0" edition=":unix" />
        <vers num="3.2.3" edition="" />
        <vers num="3.2.3" edition=":unix" />
        <vers num="5.0" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":win" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":win" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":win" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0706" published="2006-02-15" name="CVE-2006-0706" modified="2011-03-07" discovered="2006-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Gastebuch, Gastebuch, 1.3.3</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24670" source="XF" patch="1">gastebuch-homepage-xss(24670)</ref>
      <ref url="http://www.securityfocus.com/bid/16615" source="BID" patch="1">16615</ref>
      <ref url="http://secunia.com/advisories/18849" source="SECUNIA" patch="1" adv="1">18849</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20060213 XSS vulnerability in guestbook-php-script</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0566" source="VUPEN">ADV-2006-0566</ref>
      <ref url="http://www.php4scripte.de/index.php" source="CONFIRM">http://www.php4scripte.de/index.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gastebuch" name="gastebuch">
        <vers prev="1" num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0707" published="2006-02-15" name="CVE-2006-0707" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=391800" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=391800</ref>
      <ref url="http://secunia.com/advisories/18858" source="SECUNIA" patch="1" adv="1">18858</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0571" source="VUPEN">ADV-2006-0571</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24730" source="XF">pyblosxom-pathinfo-information-disclosure(24730)</ref>
      <ref url="http://www.securityfocus.com/bid/16641" source="BID">16641</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0708" published="2006-02-15" name="CVE-2006-0708" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0613" source="VUPEN">ADV-2006-0613</ref>
      <ref url="http://www.securityfocus.com/bid/16623" source="BID">16623</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424903/100/0/threaded" source="BUGTRAQ">20060213 New winamp m3u/pls .WMA &amp; .M3U Extension overflows</ref>
      <ref url="http://securitytracker.com/id?1015621" source="SECTRACK">1015621</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24741" source="XF">winamp-m3u-filename-bo(24741)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24740" source="XF">winamp-m3u-wma-bo(24740)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24739" source="XF">winamp-pls-file1-bo(24739)</ref>
      <ref url="http://securityreason.com/securityalert/492" source="SREASON">492</ref>
      <ref url="http://securityreason.com/securityalert/444" source="SREASON">444</ref>
      <ref url="http://forums.winamp.com/showthread.php?s=&amp;threadid=238648" source="MISC">http://forums.winamp.com/showthread.php?s=&amp;threadid=238648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.03" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.06" />
        <vers num="5.07" />
        <vers num="5.08c" />
        <vers num="5.08d" />
        <vers num="5.08e" />
        <vers num="5.09" />
        <vers num="5.091" />
        <vers num="5.093" />
        <vers num="5.094" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0709" published="2006-02-15" name="CVE-2006-0709" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:047" source="MANDRIVA" patch="1" adv="1">MDKSA-2006:047</ref>
      <ref url="http://www.securityfocus.com/bid/16611" source="BID" patch="1">16611</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0217.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0217</ref>
      <ref url="http://secunia.com/advisories/19000" source="SECUNIA" patch="1" adv="1">19000</ref>
      <ref url="http://secunia.com/advisories/18987" source="SECUNIA" patch="1" adv="1">18987</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0565" source="VUPEN">ADV-2006-0565</ref>
      <ref url="http://securitytracker.com/id?1015654" source="SECTRACK">1015654</ref>
      <ref url="http://secunia.com/advisories/18796" source="SECUNIA" adv="1">18796</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=352482" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=352482</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24702" source="XF">metamail-boundary-bo(24702)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-16.xml" source="GENTOO">GLSA-200603-16</ref>
      <ref url="http://www.debian.org/security/2006/dsa-995" source="DEBIAN">DSA-995</ref>
      <ref url="http://secunia.com/advisories/19304" source="SECUNIA">19304</ref>
      <ref url="http://secunia.com/advisories/19226" source="SECUNIA">19226</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers num="2.7.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0710" published="2006-02-15" name="CVE-2006-0710" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24700" source="XF">isode-mvault-ldap-dos(24700)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0567" source="VUPEN">ADV-2006-0567</ref>
      <ref url="http://www.securityfocus.com/bid/16635" source="BID">16635</ref>
      <ref url="http://secunia.com/advisories/18818" source="SECUNIA" adv="1">18818</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002925.html" source="MLIST">[Dailydave] 20060213 eddy 0day</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isode" name="m-vault_server">
        <vers num="11.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0711" published="2006-02-15" name="CVE-2006-0711" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=392562&amp;group_id=2874" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=392562&amp;group_id=2874</ref>
      <ref url="http://secunia.com/advisories/18785" source="SECUNIA" patch="1" adv="1">18785</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0564" source="VUPEN">ADV-2006-0564</ref>
      <ref url="http://secunia.com/secunia_research/2006-3/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2006-3/advisory/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24737" source="XF">neomail-neomailprefs-bypass-security(24737)</ref>
      <ref url="http://www.securityfocus.com/bid/16651" source="BID">16651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neomail" name="neomail">
        <vers prev="1" num="1.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0712" published="2006-02-15" name="CVE-2006-0712" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0551" source="VUPEN">ADV-2006-0551</ref>
      <ref url="http://www.squishdot.org/1139510883" source="CONFIRM">http://www.squishdot.org/1139510883</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24659" source="XF">squishdot-mailhtml-header-injection(24659)</ref>
      <ref url="http://www.securityfocus.com/bid/16667" source="BID">16667</ref>
      <ref url="http://secunia.com/advisories/18868" source="SECUNIA">18868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squishdot" name="squishdot">
        <vers num="0.7.2" />
        <vers num="1.0.0" />
        <vers num="1.1.0" />
        <vers num="1.2.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0713" published="2006-02-15" name="CVE-2006-0713" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4) install/third_stage_install.php, and (5) install/forth_stage_install.php.  NOTE: direct static code injection is resultant from this issue, as demonstrated by inserting PHP code into the username, which is inserted into linpha.log, which is accessible from the directory traversal.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0535" source="VUPEN">ADV-2006-0535</ref>
      <ref url="http://www.securityfocus.com/bid/16592" source="BID">16592</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424729/100/0/threaded" source="BUGTRAQ">20060211 Linpha &lt;= 1.0 multiple arbitrary local inclusion</ref>
      <ref url="http://secunia.com/advisories/18808" source="SECUNIA" adv="1">18808</ref>
      <ref url="http://retrogod.altervista.org/linpha_10_local.html" source="MISC">http://retrogod.altervista.org/linpha_10_local.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24663" source="XF">linpha-index-file-include(24663)</ref>
      <ref url="http://securityreason.com/securityalert/426" source="SREASON">426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linpha" name="linpha">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0714" published="2006-02-15" name="CVE-2006-0714" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18847" source="SECUNIA" patch="1" adv="1">18847</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0569" source="VUPEN">ADV-2006-0569</ref>
      <ref url="http://www.securityfocus.com/bid/16618" source="BID">16618</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424902/100/0/threaded" source="BUGTRAQ">20060213 EGS Enterprise Groupware System 1.0 rc4 remote commands execution &amp; FlySpray 0.9.7 remote commands execution</ref>
      <ref url="http://retrogod.altervista.org/egs_10rc4_php5_incl_xpl.html" source="MISC">http://retrogod.altervista.org/egs_10rc4_php5_incl_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24735" source="XF">flyspray-adodbpath-file-include(24735)</ref>
      <ref url="http://securityreason.com/securityalert/432" source="SREASON">432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flyspray" name="flyspray">
        <vers num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0715" published="2006-02-15" name="CVE-2006-0715" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16647" source="BID">16647</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424958/100/0/threaded" source="BUGTRAQ">20060214 XSS bugs and SQL injection in sNews</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24674" source="XF">snews-comment-xss(24674)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0297.html" source="FULLDISC">20060214 XSS and SQL injection in sNews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solucija" name="snews">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0716" published="2006-02-15" name="CVE-2006-0716" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16647" source="BID">16647</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424958/100/0/threaded" source="BUGTRAQ">20060214 XSS bugs and SQL injection in sNews</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24675" source="XF">snews-index-sql-injection(24675)</ref>
      <ref url="http://securityreason.com/securityalert/431" source="SREASON">431</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0297.html" source="FULLDISC">20060214 XSS and SQL injection in sNews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solucija" name="snews">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0717" published="2006-02-15" name="CVE-2006-0717" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24619" source="XF">tivoli-directory-ldap-dos(24619)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0537" source="VUPEN">ADV-2006-0537</ref>
      <ref url="http://www.securityfocus.com/bid/16593" source="BID">16593</ref>
      <ref url="http://secunia.com/advisories/18779" source="SECUNIA" adv="1">18779</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002921.html" source="MLIST">[Dailydave] 20060211 IBM Tivoli Directory Server 0day</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21230820" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21230820</ref>
      <ref url="http://securitytracker.com/id?1015653" source="SECTRACK">1015653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_directory_server">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0718" published="2006-02-15" name="CVE-2006-0718" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/226364" source="CERT-VN" adv="1">VU#226364</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-043.htm" source="CONFIRM" patch="1">http://support.avaya.com/elmodocs2/security/ASA-2006-043.htm</ref>
      <ref url="http://www.securityfocus.com/bid/16613" source="BID">16613</ref>
      <ref url="http://secunia.com/advisories/18836" source="SECUNIA">18836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="vsu_100">
        <vers num="3.2.40" />
      </prod>
      <prod vendor="avaya" name="vsu_10000">
        <vers num="3.2.40" />
      </prod>
      <prod vendor="avaya" name="vsu_2000">
        <vers num="3.2.40" />
      </prod>
      <prod vendor="avaya" name="vsu_7500">
        <vers num="3.2.40" />
      </prod>
      <prod vendor="avaya" name="csu_5000">
        <vers num="3.2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0719" published="2006-02-15" name="CVE-2006-0719" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0600" source="VUPEN">ADV-2006-0600</ref>
      <ref url="http://www.securityfocus.com/bid/16642" source="BID">16642</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424955/100/0/threaded" source="BUGTRAQ" adv="1">20060214 SQL injection in PHP Classifieds 6.20</ref>
      <ref url="http://www.deltascripts.com/board/viewtopic.php?id=7234" source="CONFIRM">http://www.deltascripts.com/board/viewtopic.php?id=7234</ref>
      <ref url="http://securityreason.com/securityalert/424" source="SREASON">424</ref>
      <ref url="http://secunia.com/advisories/18881" source="SECUNIA">18881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deltascripts" name="php_classifieds">
        <vers num="6.18" />
        <vers num="6.19" />
        <vers num="6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0720" published="2006-02-23" name="CVE-2006-0720" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16785" source="BID" patch="1">16785</ref>
      <ref url="http://securitytracker.com/id?1015675" source="SECTRACK" patch="1">1015675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425888/100/0/threaded" source="BUGTRAQ">20060223 NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0601.htm" source="MISC">http://www.nsfocus.com/english/homepage/research/0601.htm</ref>
      <ref url="http://forums.winamp.com/showthread.php?threadid=238648" source="CONFIRM">http://forums.winamp.com/showthread.php?threadid=238648</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24740" source="XF">winamp-m3u-wma-bo(24740)</ref>
      <ref url="http://securityreason.com/securityalert/476" source="SREASON">476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.12" />
        <vers num="5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0721" published="2006-02-16" name="CVE-2006-0721" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18831" source="SECUNIA" patch="1" adv="1">18831</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24676" source="XF">runcms-pmlite-sql-injection(24676)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0572" source="VUPEN">ADV-2006-0572</ref>
      <ref url="http://www.securityfocus.com/bid/16652" source="BID">16652</ref>
      <ref url="http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&amp;forum=18" source="CONFIRM">http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&amp;forum=18</ref>
      <ref url="http://hamid.ir/security/runcms.txt" source="MISC" adv="1">http://hamid.ir/security/runcms.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24676" source="XF">runcms-pmlite-sql-injection(24676)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425293/100/0/threaded" source="BUGTRAQ">20060216 RUNCMS 1.3a SQL injection</ref>
      <ref url="http://securitytracker.com/id?1015626" source="SECTRACK">1015626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runcms" name="runcms">
        <vers num="1.2" />
        <vers num="1.3a" />
        <vers num="1.3a2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0722" published="2006-02-16" name="CVE-2006-0722" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0602" source="VUPEN">ADV-2006-0602</ref>
      <ref url="http://secunia.com/advisories/18877" source="SECUNIA" adv="1">18877</ref>
      <ref url="http://evuln.com/vulns/73/summary.html" source="MISC" adv="1">http://evuln.com/vulns/73/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24615" source="XF">magicdownloads-settings-access(24615)</ref>
      <ref url="http://www.securityfocus.com/bid/16665" source="BID">16665</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425601/30/6830/threaded" source="BUGTRAQ">20060221 [eVuln] Magic Downloads Unauthorized Data Modification</ref>
      <ref url="http://securityreason.com/securityalert/468" source="SREASON">468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_downloads">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0723" published="2006-02-16" name="CVE-2006-0723" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24608" source="XF">magicnewslite-preview-file-include(24608)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0603" source="VUPEN" adv="1">ADV-2006-0603</ref>
      <ref url="http://www.securityfocus.com/bid/16665" source="BID">16665</ref>
      <ref url="http://www.securityfocus.com/bid/16660" source="BID">16660</ref>
      <ref url="http://secunia.com/advisories/18878" source="SECUNIA" adv="1">18878</ref>
      <ref url="http://evuln.com/vulns/72/summary.html" source="MISC" adv="1">http://evuln.com/vulns/72/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_news_lite">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0724" published="2006-02-16" name="CVE-2006-0724" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0603" source="VUPEN">ADV-2006-0603</ref>
      <ref url="http://secunia.com/advisories/18878" source="SECUNIA" adv="1">18878</ref>
      <ref url="http://evuln.com/vulns/72/summary.html" source="MISC" adv="1">http://evuln.com/vulns/72/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24610" source="XF">magicnewslite-profile-access(24610)</ref>
      <ref url="http://www.securityfocus.com/bid/16665" source="BID">16665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_news_lite">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0725" published="2006-02-16" name="CVE-2006-0725" modified="2011-11-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter.  NOTE: this is a different executable and affected version than CVE-2006-2645.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/27699" source="XF">plumecms-frontinc-prepend-file-include(27699)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24697" source="XF">plumecms-prepend-file-include(24697)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0599" source="VUPEN" adv="1">ADV-2006-0599</ref>
      <ref url="http://www.securityfocus.com/bid/16662" source="BID">16662</ref>
      <ref url="http://www.osvdb.org/23204" source="OSVDB">23204</ref>
      <ref url="http://securitytracker.com/id?1015624" source="SECTRACK">1015624</ref>
      <ref url="http://secunia.com/advisories/18883" source="SECUNIA" adv="1">18883</ref>
      <ref url="http://plume-cms.net/news/77-Security-Notice-Please-Update-Your-Prependphp-File" source="CONFIRM">http://plume-cms.net/news/77-Security-Notice-Please-Update-Your-Prependphp-File</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plume-cms" name="plume_cms">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0726" published="2006-02-16" name="CVE-2006-0726" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0688" source="VUPEN">ADV-2006-0688</ref>
      <ref url="http://www.securityfocus.com/bid/16781" source="BID">16781</ref>
      <ref url="http://www.osvdb.org/23060" source="OSVDB">23060</ref>
      <ref url="http://secunia.com/advisories/18919" source="SECUNIA">18919</ref>
      <ref url="http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html" source="CONFIRM">http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html</ref>
      <ref url="http://dragonflycms.org/Forums/viewtopic/t=14751.html" source="CONFIRM">http://dragonflycms.org/Forums/viewtopic/t=14751.html</ref>
      <ref url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22" source="CONFIRM">http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22</ref>
      <ref url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2" source="CONFIRM">http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24842" source="XF">cpg-dragonfly-linking-xss(24842)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpg-nuke" name="dragonfly_cms">
        <vers num="9.0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0727" published="2006-02-16" name="CVE-2006-0727" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query data, probably involving the profile name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0688" source="VUPEN">ADV-2006-0688</ref>
      <ref url="http://www.osvdb.org/23060" source="OSVDB">23060</ref>
      <ref url="http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html" source="CONFIRM">http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html</ref>
      <ref url="http://dragonflycms.org/Forums/viewtopic/t=14751.html" source="CONFIRM">http://dragonflycms.org/Forums/viewtopic/t=14751.html</ref>
      <ref url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22" source="CONFIRM">http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22</ref>
      <ref url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2" source="CONFIRM">http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2</ref>
      <ref url="http://www.securityfocus.com/bid/16783" source="BID">16783</ref>
      <ref url="http://www.osvdb.org/23250" source="OSVDB">23250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musox" name="df_msanalysis">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0728" published="2006-02-16" name="CVE-2006-0728" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.webspell.org/index.php?site=news_comments&amp;newsID=49&amp;lang=en" source="CONFIRM" patch="1">http://www.webspell.org/index.php?site=news_comments&amp;newsID=49&amp;lang=en</ref>
      <ref url="http://secunia.com/advisories/18885" source="SECUNIA" patch="1" adv="1">18885</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0606" source="VUPEN">ADV-2006-0606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24708" source="XF">webspell-search-sql-injection(24708)</ref>
      <ref url="http://www.securityfocus.com/bid/16673" source="BID">16673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers prev="1" num="4.01.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0729" published="2006-02-16" name="CVE-2006-0729" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24643" source="XF">tecadiary-functions-sql-injection(24643)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0615" source="VUPEN">ADV-2006-0615</ref>
      <ref url="http://www.evuln.com/vulns/75/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/75/summary.html</ref>
      <ref url="http://securitytracker.com/id?1015674" source="SECTRACK">1015674</ref>
      <ref url="http://secunia.com/advisories/18876" source="SECUNIA">18876</ref>
      <ref url="http://www.securityfocus.com/bid/16686" source="BID">16686</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425892/30/6800/threaded" source="BUGTRAQ">20060223 [eVuln] Teca Diary PE SQL Injection Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/477" source="SREASON">477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teca_scripts" name="teca_diary">
        <vers num="personal_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0730" published="2006-02-16" name="CVE-2006-0730" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login.  NOTE: vector 2 might be related to a double free vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24709" source="XF">dovecot-append-dos(24709)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0549" source="VUPEN" adv="1">ADV-2006-0549</ref>
      <ref url="http://www.securityfocus.com/bid/16672" source="BID">16672</ref>
      <ref url="http://www.dovecot.org/list/dovecot/2006-February/011367.html" source="MLIST">[Dovecot] 20060208 1.0beta3 released</ref>
      <ref url="http://secunia.com/advisories/18870" source="SECUNIA" adv="1">18870</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timo_sirainen" name="dovecot">
        <vers prev="1" num="1.0beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0731" published="2006-02-16" name="CVE-2006-0731" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24751" source="XF">sapbc-admin-spoofing(24751)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0611" source="VUPEN" adv="1">ADV-2006-0611</ref>
      <ref url="http://www.securityfocus.com/bid/16671" source="BID">16671</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434012/30/4980/threaded" source="BUGTRAQ">20060515 CYBSEC - Security Advisory: Phishing Vector in SAP BC (BusinessConnector)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425056/100/0/threaded" source="BUGTRAQ" adv="1">20060215 CYBSEC - Security Pre-Advisory: Phishing Vector in SAP BC</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Phishing_Vector_in_SAP_BC.pdf" source="MISC" adv="1">http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Phishing_Vector_in_SAP_BC.pdf</ref>
      <ref url="http://securitytracker.com/id?1015639" source="SECTRACK">1015639</ref>
      <ref url="http://secunia.com/advisories/18880" source="SECUNIA" adv="1">18880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="business_connector">
        <vers prev="1" num="core_fix_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0732" published="2006-02-16" name="CVE-2006-0732" modified="2011-03-07" discovered="2006-02-15" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle.  Details will be updated after the grace period has ended.  NOTE: SAP Business Connector is an OEM version of webMethods Integration Server.  webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port; however, both are discouraged in the documentation.  In addition, the attacker must already have acquired administrative privileges through other means.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patches (see SAP note 906401 and 908349).</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0611" source="VUPEN">ADV-2006-0611</ref>
      <ref url="http://www.securityfocus.com/bid/16668" source="BID">16668</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425048/100/0/threaded" source="BUGTRAQ" adv="1">20060215 CYBSEC - Security Pre-Advisory: Arbitrary File Read/Delete in SAPBC</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf" source="MISC" adv="1">http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf</ref>
      <ref url="http://securitytracker.com/id?1016122" source="SECTRACK">1016122</ref>
      <ref url="http://securitytracker.com/id?1015639" source="SECTRACK">1015639</ref>
      <ref url="http://secunia.com/advisories/18880" source="SECUNIA" adv="1">18880</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434014/30/4980/threaded" source="BUGTRAQ">20060515 CYBSEC - Security Advisory: Arbitrary File Read/Delete in SAP BC(Business Connector)</ref>
      <ref url="http://securitytracker.com/id?1016090" source="SECTRACK">1016090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="business_connector">
        <vers num="4.6" />
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0733" published="2006-02-16" name="CVE-2006-0733" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field.  NOTE: followup comments to the researcher's web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16656" source="BID">16656</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425043/100/0/threaded" source="BUGTRAQ" adv="1">20060214 [myimei]WordPress2.0.0~autors?website~XSS attack</ref>
      <ref url="http://myimei.com/security/2006-02-15/wordpress200autors-websitexss-attack.html" source="MISC" adv="1">http://myimei.com/security/2006-02-15/wordpress200autors-websitexss-attack.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24736" source="XF">wordpress-authorswebsite-xss(24736)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0734" published="2006-02-16" name="CVE-2006-0734" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33505" source="XF">halflife-svcheckforduplicatenames-dos(33505)</ref>
      <ref url="http://www.securityfocus.com/bid/16619" source="BID">16619</ref>
      <ref url="http://aluigi.altervista.org/adv/csdos.txt" source="MISC">http://aluigi.altervista.org/adv/csdos.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valve_software" name="half-life_cstrike_dedicated_server">
        <vers prev="1" num="1.6_linux" />
        <vers prev="1" num="1.6_windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0735" published="2006-02-16" name="CVE-2006-0735" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16659" source="BID" patch="1">16659</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425113/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060215 [eVuln] M. Blom HTML::BBCode perl module XSS Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425087/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060215 [eVuln] My Blog BBCode XSS Vulnerabilities</ref>
      <ref url="http://www.evuln.com/vulns/80/summary.html" source="MISC" patch="1" adv="1">http://www.evuln.com/vulns/80/summary.html</ref>
      <ref url="http://secunia.com/advisories/18905" source="SECUNIA" patch="1" adv="1">18905</ref>
      <ref url="http://fuzzymonkey.net/forum/viewtopic.php?t=856" source="CONFIRM" patch="1">http://fuzzymonkey.net/forum/viewtopic.php?t=856</ref>
      <ref url="http://evuln.com/vulns/80/summary.html" source="MISC" patch="1" adv="1">http://www.evuln.com/vulns/80/summary.html</ref>
      <ref url="http://evuln.com/vulns/79/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/79/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24668" source="XF">myblog-bbcode-xss(24668)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0642" source="VUPEN">ADV-2006-0642</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0614" source="VUPEN">ADV-2006-0614</ref>
      <ref url="http://secunia.com/advisories/18925" source="SECUNIA" adv="1">18925</ref>
      <ref url="http://menno.b10m.net/perl/HTML-BBCode/Changes" source="CONFIRM">http://menno.b10m.net/perl/HTML-BBCode/Changes</ref>
      <ref url="http://menno.b10m.net/perl/HTML-BBCode/Changes" source="MISC">http://menno.b10m.net/perl/HTML-BBCode/Changes</ref>
      <ref url="http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz" source="CONFIRM">http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuzzymonkey" name="my_blog">
        <vers num="1.0" />
        <vers num="1.2" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.23" />
        <vers num="1.3" />
        <vers num="1.31" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.6" />
        <vers num="1.61" />
        <vers num="1.62" />
        <vers num="1.63" />
        <vers num="1.64" />
      </prod>
      <prod vendor="m_blom" name="html-bbcode">
        <vers num="1.03" />
        <vers num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0736" published="2006-02-27" name="CVE-2006-0736" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0693" source="VUPEN">ADV-2006-0693</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_10_casa.html" source="SUSE">SUSE-SA:2006:010</ref>
      <ref url="http://www.securityfocus.com/bid/16779" source="BID">16779</ref>
      <ref url="http://secunia.com/advisories/18995" source="SECUNIA">18995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="1" />
      </prod>
      <prod vendor="novell" name="linux_desktop">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0737" published="2006-02-16" name="CVE-2006-0737" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0607" source="VUPEN">ADV-2006-0607</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424943/100/0/threaded" source="BUGTRAQ">20060214 eStara SIP softphone several message-processing vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18872" source="SECUNIA" adv="1">18872</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24677" source="XF">estara-neg-integer-dos(24677)</ref>
      <ref url="http://www.securityfocus.com/bid/16629" source="BID">16629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estara" name="softphone">
        <vers prev="1" num="3.0.1.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0738" published="2006-02-16" name="CVE-2006-0738" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0607" source="VUPEN">ADV-2006-0607</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424943/100/0/threaded" source="BUGTRAQ" adv="1">20060214 eStara SIP softphone several message-processing vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18872" source="SECUNIA" adv="1">18872</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24678" source="XF">estara-sdp-format-string(24678)</ref>
      <ref url="http://www.securityfocus.com/bid/16629" source="BID">16629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estara" name="softphone">
        <vers prev="1" num="3.0.1.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0739" published="2006-02-16" name="CVE-2006-0739" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24679" source="XF">estara-content-length-dos(24679)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0607" source="VUPEN">ADV-2006-0607</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424943/100/0/threaded" source="BUGTRAQ">20060214 eStara SIP softphone several message-processing vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18872" source="SECUNIA" adv="1">18872</ref>
      <ref url="http://www.securityfocus.com/bid/16629" source="BID">16629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estara" name="softphone">
        <vers prev="1" num="3.0.1.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0741" published="2006-03-06" name="CVE-2006-0741" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0804" source="VUPEN">ADV-2006-0804</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10518" source="OVAL">oval:org.mitre.oval:def:10518</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25001" source="XF">kernel-elf-dos(25001)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1" source="UBUNTU">USN-263-1</ref>
      <ref url="http://www.securityfocus.com/bid/16925" source="BID">16925</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0437.html" source="REDHAT">RHSA-2006:0437</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00003.html" source="FEDORA">FEDORA-2006-131</ref>
      <ref url="http://www.osvdb.org/23607" source="OSVDB">23607</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:025" source="MANDRIVA">MDKSA-2007:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://securitytracker.com/id?1015724" source="SECTRACK">1015724</ref>
      <ref url="http://secunia.com/advisories/21983" source="SECUNIA">21983</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/21136" source="SECUNIA">21136</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
      <ref url="http://secunia.com/advisories/19220" source="SECUNIA">19220</ref>
      <ref url="http://secunia.com/advisories/19108" source="SECUNIA">19108</ref>
      <ref url="http://secunia.com/advisories/19083" source="SECUNIA">19083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0742" published="2006-03-09" name="CVE-2006-0742" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the "noreturn" attribute set, which allows local users to cause a denial of service by causing user faults on Itanium systems.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all verison of Linux kernel 2.6.x before 2.6.15.6, and may be exclusive to Itanium systems.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19078" source="SECUNIA" patch="1" adv="1">19078</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0856" source="VUPEN">ADV-2006-0856</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.6</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10742" source="OVAL">oval:org.mitre.oval:def:10742</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25068" source="XF">kernel-dieifkernel-dos(25068)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1" source="UBUNTU">USN-263-1</ref>
      <ref url="http://www.securityfocus.com/bid/16993" source="BID">16993</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0437.html" source="REDHAT">RHSA-2006:0437</ref>
      <ref url="http://www.osvdb.org/23660" source="OSVDB">23660</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21983" source="SECUNIA">21983</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/21136" source="SECUNIA">21136</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="http://secunia.com/advisories/19220" source="SECUNIA">19220</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="" />
        <vers num="2.6.0" edition=":64-bit_x86" />
        <vers num="2.6.0" edition=":itanium_ia64_montecito" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0743" published="2006-03-09" name="CVE-2006-0743" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19241" source="SECUNIA" patch="1" adv="1">19241</ref>
      <ref url="http://issues.apache.org/jira/browse/LOG4NET-67" source="CONFIRM" patch="1" adv="1">http://issues.apache.org/jira/browse/LOG4NET-67</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25196" source="XF">log4net-localsyslogappender-dos(25196)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0955" source="VUPEN" adv="1">ADV-2006-0955</ref>
      <ref url="http://www.securityfocus.com/bid/17095" source="BID">17095</ref>
      <ref url="http://www.osvdb.org/23905" source="OSVDB">23905</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_26_sr.html" source="SUSE">SUSE-SR:2006:026</ref>
      <ref url="http://secunia.com/advisories/22932" source="SECUNIA" adv="1">22932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="log4net">
        <vers num="1.2.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0744" published="2006-04-18" name="CVE-2006-0744" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25869" source="XF">linux-uncanonical-addr-dos(25869)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1475" source="VUPEN">ADV-2006-1475</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1390" source="VUPEN">ADV-2006-1390</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/bid/17541" source="BID">17541</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0437.html" source="REDHAT">RHSA-2006:0437</ref>
      <ref url="http://www.osvdb.org/24639" source="OSVDB">24639</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html" source="SUSE">SUSE-SA:2006:047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086" source="MANDRIVA">MDKSA-2006:086</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/21983" source="SECUNIA" adv="1">21983</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA" adv="1">21745</ref>
      <ref url="http://secunia.com/advisories/21498" source="SECUNIA" adv="1">21498</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA" adv="1">21179</ref>
      <ref url="http://secunia.com/advisories/21136" source="SECUNIA" adv="1">21136</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA" adv="1">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA" adv="1">20716</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA" adv="1">20237</ref>
      <ref url="http://secunia.com/advisories/20157" source="SECUNIA" adv="1">20157</ref>
      <ref url="http://secunia.com/advisories/19735" source="SECUNIA" adv="1">19735</ref>
      <ref url="http://secunia.com/advisories/19639" source="SECUNIA" adv="1">19639</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9732" source="OVAL">oval:org.mitre.oval:def:9732</ref>
      <ref url="http://lwn.net/Alerts/180820/" source="FEDORA">FEDORA-2006-423</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16_rc7" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="final" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0745" published="2006-03-20" name="CVE-2006-0745" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17169" source="BID" patch="1">17169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428183/100/0/threaded" source="BUGTRAQ" patch="1">20060320 [CVE-2006-0745] X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1028" source="VUPEN">ADV-2006-1028</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1017" source="VUPEN">ADV-2006-1017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428230/100/0/threaded" source="BUGTRAQ">20060320 Re: [CVE-2006-0745] X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25341" source="XF">xorg-geteuid-privilege-escalation(25341)</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00026.html" source="FEDORA">FEDORA-2006-172</ref>
      <ref url="http://www.osvdb.org/24001" source="OSVDB">24001</ref>
      <ref url="http://www.osvdb.org/24000" source="OSVDB">24000</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_16_xorgx11server.html" source="SUSE">SUSE-SA:2006:016</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:056" source="MANDRIVA">MDKSA-2006:056</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102252-1" source="SUNALERT">102252</ref>
      <ref url="http://securitytracker.com/id?1015793" source="SECTRACK">1015793</ref>
      <ref url="http://securityreason.com/securityalert/606" source="SREASON">606</ref>
      <ref url="http://secunia.com/advisories/19676" source="SECUNIA">19676</ref>
      <ref url="http://secunia.com/advisories/19316" source="SECUNIA">19316</ref>
      <ref url="http://secunia.com/advisories/19311" source="SECUNIA">19311</ref>
      <ref url="http://secunia.com/advisories/19307" source="SECUNIA">19307</ref>
      <ref url="http://secunia.com/advisories/19256" source="SECUNIA">19256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1697" source="OVAL" sig="1">oval:org.mitre.oval:def:1697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.9" />
      </prod>
      <prod vendor="x.org" name="x11r7">
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="2006" edition="" />
        <vers num="2006" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_5.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":x86" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":oss" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0746" published="2006-03-08" name="CVE-2006-0746" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25146" source="XF">kde-kpdf-patch-bo(25146)</ref>
      <ref url="http://www.securityfocus.com/bid/17039" source="BID">17039</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427299/100/0/threaded" source="BUGTRAQ">20060310 [KDE Security Advisory] kpdf of KDE 3.3.x heap based buffer overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0262.html" source="REDHAT">RHSA-2006:0262</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:054" source="MANDRIVA">MDKSA-2006:054</ref>
      <ref url="http://www.kde.org/info/security/advisory-20060202-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20060202-1.txt</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1008" source="DEBIAN">DSA-1008</ref>
      <ref url="http://securitytracker.com/id?1015751" source="SECTRACK">1015751</ref>
      <ref url="http://securityreason.com/securityalert/566" source="SREASON">566</ref>
      <ref url="http://secunia.com/advisories/19264" source="SECUNIA" adv="1">19264</ref>
      <ref url="http://secunia.com/advisories/19190" source="SECUNIA" adv="1">19190</ref>
      <ref url="http://secunia.com/advisories/19189" source="SECUNIA" adv="1">19189</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11441" source="OVAL">oval:org.mitre.oval:def:11441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0747" published="2006-05-23" name="CVE-2006-0747" modified="2011-10-11" discovered="2006-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676</ref>
      <ref url="https://issues.rpath.com/browse/RPL-429" source="CONFIRM">https://issues.rpath.com/browse/RPL-429</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0381" source="VUPEN" adv="1">ADV-2007-0381</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-291-1" source="UBUNTU">USN-291-1</ref>
      <ref url="http://www.securityfocus.com/bid/18326" source="BID">18326</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436836/100/0/threaded" source="BUGTRAQ">20060612 rPSA-2006-0100-1 freetype</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0500.html" source="REDHAT">RHSA-2006:0500</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:099" source="MANDRIVA">MDKSA-2006:099</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1095" source="DEBIAN">DSA-1095</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102705-1" source="SUNALERT">102705</ref>
      <ref url="http://securitytracker.com/id?1016522" source="SECTRACK">1016522</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/23939" source="SECUNIA" adv="1">23939</ref>
      <ref url="http://secunia.com/advisories/21701" source="SECUNIA" adv="1">21701</ref>
      <ref url="http://secunia.com/advisories/21385" source="SECUNIA" adv="1">21385</ref>
      <ref url="http://secunia.com/advisories/21135" source="SECUNIA" adv="1">21135</ref>
      <ref url="http://secunia.com/advisories/21062" source="SECUNIA" adv="1">21062</ref>
      <ref url="http://secunia.com/advisories/20791" source="SECUNIA" adv="1">20791</ref>
      <ref url="http://secunia.com/advisories/20638" source="SECUNIA" adv="1">20638</ref>
      <ref url="http://secunia.com/advisories/20591" source="SECUNIA" adv="1">20591</ref>
      <ref url="http://secunia.com/advisories/20525" source="SECUNIA" adv="1">20525</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9508" source="OVAL">oval:org.mitre.oval:def:9508</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html" source="SUSE">SUSE-SA:2006:037</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U" source="SGI">20060701-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freetype" name="freetype">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0748" published="2006-04-14" name="CVE-2006-0748" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability also affects Mozilla Suite before 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25985" source="XF">mozilla-table-rebuilding-code-execution(25985)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-011/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-011/</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432103/100/0/threaded" source="BUGTRAQ">20060426 ZDI-06-011: Mozilla Firefox Table Rebuilding Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11164" source="OVAL">oval:org.mitre.oval:def:11164</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1189" source="OVAL" sig="1">oval:org.mitre.oval:def:1189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="preview_release" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0749" published="2006-04-14" name="CVE-2006-0749" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/736934" source="CERT-VN">VU#736934</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-009.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-009.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431126/100/0/threaded" source="BUGTRAQ">20060417 ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT" adv="1">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT" adv="1">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT" adv="1">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-18.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-18.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA" adv="1">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA" adv="1">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA" adv="1">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA" adv="1">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11704" source="OVAL">oval:org.mitre.oval:def:11704</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25819" source="XF">mozilla-nshtmlcontentsink-memory-corruption(25819)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://securityreason.com/securityalert/729" source="SREASON">729</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1848" source="OVAL" sig="1">oval:org.mitre.oval:def:1848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0750" published="2006-02-17" name="CVE-2006-0750" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24654" source="XF">ipb-armysystem-sql-injection(24654)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0561" source="VUPEN" adv="1">ADV-2006-0561</ref>
      <ref url="http://www.securityfocus.com/bid/16606" source="BID">16606</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424846/100/0/threaded" source="BUGTRAQ" adv="1">20060212 Invision Power Board Army System Mod &lt;= 2.1 SQL Injection Exploit</ref>
      <ref url="http://secunia.com/advisories/18840" source="SECUNIA" adv="1">18840</ref>
      <ref url="http://secubox.shadock.net/Invision_Power_Board_Army_System_Mod_2.1_and_prior_SQL_Injection_Exploit.html" source="MISC" adv="1">http://secubox.shadock.net/Invision_Power_Board_Army_System_Mod_2.1_and_prior_SQL_Injection_Exploit.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="supersmashbrothers" name="army_system">
        <vers num="2.1.0_for_ipb" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0751" published="2006-02-17" name="CVE-2006-0751" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23053" source="OSVDB">23053</ref>
      <ref url="http://www.osvdb.org/23052" source="OSVDB">23052</ref>
      <ref url="http://freshmeat.net/projects/noofs/?branch_id=60557&amp;release_id=218852" source="CONFIRM">http://freshmeat.net/projects/noofs/?branch_id=60557&amp;release_id=218852</ref>
      <ref url="http://archives.neohapsis.com/archives/apps/freshmeat/2006-02/0003.html" source="MLIST">[fm-news] 20060204 Newsletter for Friday, February 03rd 2006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noofs_team" name="network_object_oriented_file_system">
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0752" published="2006-02-17" name="CVE-2006-0752" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16595" source="BID" patch="1">16595</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0552" source="VUPEN">ADV-2006-0552</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425112/100/0/threaded" source="BUGTRAQ">20060212 honeyd security advisory: remote detection</ref>
      <ref url="http://www.honeyd.org/phpBB2/viewtopic.php?t=106" source="CONFIRM">http://www.honeyd.org/phpBB2/viewtopic.php?t=106</ref>
      <ref url="http://www.honeyd.org/adv.2006-01" source="CONFIRM">http://www.honeyd.org/adv.2006-01</ref>
      <ref url="http://secunia.com/advisories/18867" source="SECUNIA" adv="1">18867</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24728" source="XF">honeyd-ipfrag-obtain-information(24728)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niels_provos" name="honeyd">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6a" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.8" />
        <vers num="0.8a" />
        <vers num="0.8b" />
        <vers num="1.0" />
        <vers num="1.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0753" published="2006-02-17" name="CVE-2006-0753" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24846" source="XF">ie-windowstatus-dos(24846)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424959/100/0/threaded" source="BUGTRAQ">20060214 memory leak in IE?</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24846" source="XF">ie-windowsstatus-dos(24846)</ref>
      <ref url="http://www.osvdb.org/23307" source="OSVDB">23307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_xp_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0754" published="2006-02-17" name="CVE-2006-0754" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message.  NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0604" source="VUPEN">ADV-2006-0604</ref>
      <ref url="http://www.securityfocus.com/bid/16648" source="BID">16648</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded" source="BUGTRAQ">20060214 dotproject &lt;= 2.0.1 remote code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/425285/100/0/threaded" source="BUGTRAQ">20060215 Re: dotproject &lt;= 2.0.1 remote code execution</ref>
      <ref url="http://www.osvdb.org/23206" source="OSVDB">23206</ref>
      <ref url="http://secunia.com/advisories/18879" source="SECUNIA" adv="1">18879</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24745" source="XF">dotproject-phpinfo-check-obtain-info(24745)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotproject" name="dotproject">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0755" published="2006-02-17" name="CVE-2006-0755" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php.  NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting.  Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24738" source="XF">dotproject-multiple-basedir-file-include(24738)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0604" source="VUPEN">ADV-2006-0604</ref>
      <ref url="http://www.securityfocus.com/bid/16648" source="BID">16648</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded" source="BUGTRAQ">20060214 dotproject &lt;= 2.0.1 remote code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/425285/100/0/threaded" source="BUGTRAQ">20060215 Re: dotproject &lt;= 2.0.1 remote code execution</ref>
      <ref url="http://www.osvdb.org/23219" source="OSVDB">23219</ref>
      <ref url="http://www.osvdb.org/23218" source="OSVDB">23218</ref>
      <ref url="http://www.osvdb.org/23217" source="OSVDB">23217</ref>
      <ref url="http://www.osvdb.org/23216" source="OSVDB">23216</ref>
      <ref url="http://www.osvdb.org/23215" source="OSVDB">23215</ref>
      <ref url="http://www.osvdb.org/23214" source="OSVDB">23214</ref>
      <ref url="http://www.osvdb.org/23213" source="OSVDB">23213</ref>
      <ref url="http://www.osvdb.org/23212" source="OSVDB">23212</ref>
      <ref url="http://www.osvdb.org/23211" source="OSVDB">23211</ref>
      <ref url="http://www.osvdb.org/23210" source="OSVDB">23210</ref>
      <ref url="http://www.osvdb.org/23209" source="OSVDB">23209</ref>
      <ref url="http://secunia.com/advisories/18879" source="SECUNIA" adv="1">18879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotproject" name="dotproject">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0756" published="2006-02-17" name="CVE-2006-0756" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information.  NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0604" source="VUPEN">ADV-2006-0604</ref>
      <ref url="http://www.securityfocus.com/bid/16648" source="BID">16648</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded" source="BUGTRAQ">20060214 dotproject &lt;= 2.0.1 remote code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/425285/100/0/threaded" source="BUGTRAQ">20060215 Re: dotproject &lt;= 2.0.1 remote code execution</ref>
      <ref url="http://www.osvdb.org/23208" source="OSVDB">23208</ref>
      <ref url="http://www.osvdb.org/23207" source="OSVDB">23207</ref>
      <ref url="http://secunia.com/advisories/18879" source="SECUNIA" adv="1">18879</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24745" source="XF">dotproject-phpinfo-check-obtain-info(24745)</ref>
      <ref url="http://securityreason.com/securityalert/434" source="SREASON">434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotproject" name="dotproject">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0757" published="2006-02-17" name="CVE-2006-0757" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24618" source="XF">hivemail-multiple-file-include(24618)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0527" source="VUPEN">ADV-2006-0527</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00098-02102006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00098-02102006</ref>
      <ref url="http://forum.hivemail.com/showthread.php?p=26745" source="MISC">http://forum.hivemail.com/showthread.php?p=26745</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html" source="BUGTRAQ" adv="1">20060210 HiveMail &lt;= 1.3 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16591" source="BID">16591</ref>
      <ref url="http://secunia.com/advisories/18807" source="SECUNIA">18807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hivemail" name="hivemail">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1_beta1" />
        <vers num="1.2.1_rc" />
        <vers num="1.2.2" />
        <vers num="1.2_sp1" />
        <vers num="1.3" />
        <vers num="1.3_beta1" />
        <vers num="1.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0758" published="2006-02-17" name="CVE-2006-0758" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the $_SERVER['PHP_SELF'] variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24622" source="XF">hivemail-index-xss(24622)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0527" source="VUPEN">ADV-2006-0527</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00098-02102006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00098-02102006</ref>
      <ref url="http://forum.hivemail.com/showthread.php?p=26745" source="MISC">http://forum.hivemail.com/showthread.php?p=26745</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html" source="BUGTRAQ" adv="1">20060210 HiveMail &lt;= 1.3 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16591" source="BID">16591</ref>
      <ref url="http://secunia.com/advisories/18807" source="SECUNIA">18807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hivemail" name="hivemail">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1_beta1" />
        <vers num="1.2.1_rc" />
        <vers num="1.2.2" />
        <vers num="1.2_sp1" />
        <vers num="1.3" />
        <vers num="1.3_beta1" />
        <vers num="1.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0759" published="2006-02-17" name="CVE-2006-0759" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts, because $_SERVER['PHP_SELF'] is improperly handled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24623" source="XF">hivemail-index-sql-injection(24623)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0527" source="VUPEN">ADV-2006-0527</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00098-02102006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00098-02102006</ref>
      <ref url="http://forum.hivemail.com/showthread.php?p=26745" source="MISC">http://forum.hivemail.com/showthread.php?p=26745</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html" source="BUGTRAQ" adv="1">20060210 HiveMail &lt;= 1.3 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16591" source="BID">16591</ref>
      <ref url="http://securityreason.com/securityalert/422" source="SREASON">422</ref>
      <ref url="http://secunia.com/advisories/18807" source="SECUNIA">18807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hivemail" name="hivemail">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1_beta1" />
        <vers num="1.2.1_rc" />
        <vers num="1.2.2" />
        <vers num="1.2_sp1" />
        <vers num="1.3" />
        <vers num="1.3_beta1" />
        <vers num="1.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0760" published="2006-02-17" name="CVE-2006-0760" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18869" source="SECUNIA" patch="1" adv="1">18869</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0550" source="VUPEN">ADV-2006-0550</ref>
      <ref url="http://www.lighttpd.net/news/" source="CONFIRM">http://lighttpd.net/news/</ref>
      <ref url="http://lighttpd.net/news/" source="CONFIRM">http://lighttpd.net/news/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24699" source="XF">lighttpd-ext-source-disclosure(24699)</ref>
      <ref url="http://www.osvdb.org/23229" source="OSVDB">23229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0761" published="2006-02-17" name="CVE-2006-0761" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24629" source="XF">blackberry-attachment-word-bo(24629)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0530" source="VUPEN">ADV-2006-0530</ref>
      <ref url="http://www.securityfocus.com/bid/16590" source="BID">16590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424728/100/0/threaded" source="BUGTRAQ">20060210 Corrupt Word file may cause buffer overflow in the Blackberry Attachment Service</ref>
      <ref url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/8149/8052/Support_-_Corrupt_Word_file_may_cause_buffer_overflow_in_the_BlackBerry_Attachment_Service.html?nodeid=1181753&amp;vernum=2" source="CONFIRM">http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/8149/8052/Support_-_Corrupt_Word_file_may_cause_buffer_overflow_in_the_BlackBerry_Attachment_Service.html?nodeid=1181753&amp;vernum=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="2.2" />
        <vers num="2.2_sp2" />
        <vers num="2.2_sp2a" />
        <vers num="2.2_sp3a" />
        <vers num="2.2_sp4" />
        <vers num="2.2_sp4_hotfix2" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":exchange" />
        <vers num="3.6.1" edition="" />
        <vers num="3.6.1" edition=":exchange" />
        <vers num="3.6_sp1a" edition="" />
        <vers num="3.6_sp1a" edition=":exchange" />
        <vers num="3.6_sp4_hotfix2" edition="" />
        <vers num="3.6_sp4_hotfix2" edition=":exchange" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":novell_groupwise" />
        <vers num="4.0" edition=":domino" />
        <vers num="4.0_sp1" edition="" />
        <vers num="4.0_sp1" edition=":novell_groupwise" />
        <vers num="4.0_sp1" edition=":domino" />
        <vers num="4.0_sp2" edition="" />
        <vers num="4.0_sp2" edition=":novell_groupwise" />
        <vers num="4.0_sp2" edition=":domino" />
        <vers num="4.0_sp3" edition="" />
        <vers num="4.0_sp3" edition=":novell_groupwise" />
        <vers num="4.0_sp3" edition=":domino" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0762" published="2006-02-17" name="CVE-2006-0762" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424905/100/0/threaded" source="BUGTRAQ">20060213 Re: Folder Guard password protection bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424855/100/0/threaded" source="BUGTRAQ">20060213 Folder Guard password protection bypass</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24725" source="XF">folderguard-fguard-bypass-authentication(24725)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winability" name="folder_guard">
        <vers num="4.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0763" published="2006-02-17" name="CVE-2006-0763" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22971" source="OSVDB">22971</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0129.html" source="FULLDISC">20060207 Re: cPanel Multiple Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24839" source="XF">cpanel-dowebmailforward-xss(24839)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0764" published="2006-02-17" name="CVE-2006-0764" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24689" source="XF">cisco-tacacs-auth-bypass(24689)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0612" source="VUPEN">ADV-2006-0612</ref>
      <ref url="http://www.securityfocus.com/bid/16661" source="BID">16661</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008060519a.shtml" source="CISCO" adv="1">20060215 TACACS+ Authentication Bypass in Cisco Anomaly Detection and Mitigation Products</ref>
      <ref url="http://www.osvdb.org/23237" source="OSVDB">23237</ref>
      <ref url="http://securitytracker.com/id?1015638" source="SECTRACK">1015638</ref>
      <ref url="http://securitytracker.com/id?1015637" source="SECTRACK">1015637</ref>
      <ref url="http://securityreason.com/securityalert/435" source="SREASON">435</ref>
      <ref url="http://secunia.com/advisories/18904" source="SECUNIA">18904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="anomaly_guard_module">
        <vers num="5.0(1)" />
        <vers num="5.0(3)" />
      </prod>
      <prod vendor="cisco" name="guard">
        <vers num="5.0(1)" />
        <vers num="5.0(3)" />
      </prod>
      <prod vendor="cisco" name="traffic_anomaly_detector_module">
        <vers num="5.0(1)" />
        <vers num="5.0(3)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0765" published="2006-02-17" name="CVE-2006-0765" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16655" source="BID">16655</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425078/100/0/threaded" source="BUGTRAQ">20060215 Mirabiliz ICQ 2002/2003/ LITE 4.0/4.1 LONG (DIRECTORY + FILENAME) EXPLOIT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2003a" />
        <vers num="2003b" />
      </prod>
      <prod vendor="mirabilis" name="icq_lite">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0766" published="2006-02-17" name="CVE-2006-0766" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16655" source="BID">16655</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425078/100/0/threaded" source="BUGTRAQ">20060215 Mirabiliz ICQ 2002/2003/ LITE 4.0/4.1 LONG (DIRECTORY + FILENAME) EXPLOIT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2003a" />
        <vers num="2003b" />
      </prod>
      <prod vendor="mirabilis" name="icq_lite">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0767" published="2006-02-18" name="CVE-2006-0767" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=393274&amp;group_id=8209" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=393274&amp;group_id=8209</ref>
      <ref url="http://secunia.com/advisories/18797" source="SECUNIA" patch="1" adv="1">18797</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0601" source="VUPEN">ADV-2006-0601</ref>
      <ref url="http://sourceforge.net/project/showfiles.php?group_id=8209" source="MISC">http://sourceforge.net/project/showfiles.php?group_id=8209</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24717" source="XF">cgiwrap-error-information-disclosure(24717)</ref>
      <ref url="http://www.securityfocus.com/bid/16669" source="BID">16669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nathan_neulinger" name="cgiwrap">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.11" />
        <vers num="3.2" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.23" />
        <vers num="3.24" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5_beta" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6_beta1" />
        <vers num="3.6_beta2" />
        <vers num="3.6_beta3" />
        <vers num="3.6_beta4" />
        <vers num="3.6_beta5" />
        <vers num="3.6_beta6" />
        <vers num="3.6_beta7" />
        <vers num="3.6_beta8" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.8_rc1" />
        <vers num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0768" published="2006-02-18" name="CVE-2006-0768" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kadu 0.4.3 allows remote attackers to cause a denial of service (application crash) via a large number of image send requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0609" source="VUPEN">ADV-2006-0609</ref>
      <ref url="http://www.piotrbania.com/all/adv/kadu-fun.txt" source="MISC" adv="1">http://www.piotrbania.com/all/adv/kadu-fun.txt</ref>
      <ref url="http://secunia.com/advisories/18824" source="SECUNIA" adv="1">18824</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114000770431441&amp;w=2" source="FULLDISC">20060215 Kadu Remote Denial Of Service Fun</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24720" source="XF">kadu-image-request-dos(24720)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425134/100/0/threaded" source="BUGTRAQ">20060215 Kadu Remote Denial Of Service Fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kadu" name="kadu">
        <vers num="0.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0769" published="2006-02-18" name="CVE-2006-0769" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18891" source="SECUNIA" patch="1" adv="1">18891</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0608" source="VUPEN">ADV-2006-0608</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102186-1" source="SUNALERT">102186</ref>
      <ref url="http://securitytracker.com/id?1015635" source="SECTRACK">1015635</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24680" source="XF">solaris-kerberos-command-execution(24680)</ref>
      <ref url="http://www.securityfocus.com/bid/16658" source="BID">16658</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-126.shtml" source="CIAC">Q-126</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1580" source="OVAL" sig="1">oval:org.mitre.oval:def:1580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0770" published="2006-02-18" name="CVE-2006-0770" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in "advanced details".  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24748" source="XF">mybb-advanceddetails-xss(24748)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0635" source="VUPEN">ADV-2006-0635</ref>
      <ref url="http://www.osvdb.org/23264" source="OSVDB">23264</ref>
      <ref url="http://secunia.com/advisories/18866" source="SECUNIA" adv="1">18866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="1.0_preview_release_2" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0771" published="2006-02-18" name="CVE-2006-0771" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the server kicks the player and records the reason.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24792" source="XF">punkbuster-cvars-format-string(24792)</ref>
      <ref url="http://www.securityfocus.com/bid/16703" source="BID">16703</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425286/100/0/threaded" source="BUGTRAQ">20060216 Soldier of Fortune II format string through PunkBuster 1.180</ref>
      <ref url="http://securityreason.com/securityalert/448" source="SREASON">448</ref>
      <ref url="http://secunia.com/advisories/18917" source="SECUNIA" adv="1">18917</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0372.html" source="FULLDISC">20060216 Soldier of Fortune II format string through PunkBuster 1.180</ref>
      <ref url="http://aluigi.altervista.org/adv/sof2pbfs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/sof2pbfs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="even_balance" name="punkbuster">
        <vers prev="1" num="1.180" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0772" published="2006-02-18" name="CVE-2006-0772" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitrary SQL commands via unspecified vectors in the extended receiving box function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18817" source="SECUNIA" patch="1" adv="1">18817</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24621" source="XF">hitachi-businesslogic-recbox-sql-injection(24621)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23877" source="XF">hitachi-businesslogic-input-sql-injection(23877)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0532" source="VUPEN" adv="1">ADV-2006-0532</ref>
      <ref url="http://www.securityfocus.com/bid/16602" source="BID">16602</ref>
      <ref url="http://www.osvdb.org/23099" source="OSVDB">23099</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="business_logic">
        <vers num="02_03" edition="" />
        <vers num="02_03" edition=":windows" />
        <vers num="03_00" edition="" />
        <vers num="03_00" edition=":linux" />
        <vers prev="1" num="03_00_b" edition="" />
        <vers prev="1" num="03_00_b" edition=":windows" />
        <vers prev="1" num="03_00_b" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0773" published="2006-02-18" name="CVE-2006-0773" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the extended receiving box function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18817" source="SECUNIA" patch="1" adv="1">18817</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24620" source="XF">hitachi-businesslogic-recbox-xss(24620)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0532" source="VUPEN">ADV-2006-0532</ref>
      <ref url="http://www.securityfocus.com/bid/16602" source="BID">16602</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="business_logic">
        <vers num="02_03" edition="" />
        <vers num="02_03" edition=":windows" />
        <vers num="03_00" edition="" />
        <vers num="03_00" edition=":linux" />
        <vers prev="1" num="03_00_b" edition="" />
        <vers prev="1" num="03_00_b" edition=":windows" />
        <vers prev="1" num="03_00_b" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0774" published="2006-02-18" name="CVE-2006-0774" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0528" source="VUPEN">ADV-2006-0528</ref>
      <ref url="http://www.securityfocus.com/bid/16598" source="BID">16598</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424819/100/0/threaded" source="BUGTRAQ" adv="1">20060211 DB_eSession deleteSession() SQL injection</ref>
      <ref url="http://www.osvdb.org/23104" source="OSVDB">23104</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00099-02112006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00099-02112006</ref>
      <ref url="http://secunia.com/advisories/18805" source="SECUNIA" adv="1">18805</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24673" source="XF">dbesession-deletesession-sql-injection(24673)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433132/30/5160/threaded" source="BUGTRAQ">20060501 Re: DB_eSession deleteSession() SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lawrence_osiris" name="db_esession">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0775" published="2006-02-18" name="CVE-2006-0775" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable.  NOTE: a vector regarding the $date parameter and data.php (date.php) was originally reported, but this appears to be in error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24617" source="XF">birthsys-show-date-sql-injection(24617)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0621" source="VUPEN">ADV-2006-0621</ref>
      <ref url="http://www.evuln.com/vulns/74/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/74/summary.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000549.html" source="VIM">20060215 EV0074 BirthSys 3.1 SQL injection (fwd)</ref>
      <ref url="http://www.securityfocus.com/bid/16684" source="BID">16684</ref>
      <ref url="http://www.osvdb.org/23185" source="OSVDB">23185</ref>
      <ref url="http://securityreason.com/securityalert/467" source="SREASON">467</ref>
      <ref url="http://secunia.com/advisories/18893" source="SECUNIA">18893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ridder_roeland" name="birthsys">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0776" published="2006-02-18" name="CVE-2006-0776" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24644" source="XF">guestex-script-xss(24644)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0640" source="VUPEN">ADV-2006-0640</ref>
      <ref url="http://www.osvdb.org/23182" source="OSVDB">23182</ref>
      <ref url="http://www.evuln.com/vulns/77/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/77/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16711" source="BID">16711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426034/100/0/threaded" source="BUGTRAQ">20060224 [eVuln] Guestex XSS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015678" source="SECTRACK">1015678</ref>
      <ref url="http://securityreason.com/securityalert/490" source="SREASON">490</ref>
      <ref url="http://secunia.com/advisories/18927" source="SECUNIA">18927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teca_scripts" name="guestex">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0777" published="2006-02-18" name="CVE-2006-0777" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to execute arbitrary shell commands via the email parameter, possibly involving shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24645" source="XF">guestex-script-execute-code(24645)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0640" source="VUPEN">ADV-2006-0640</ref>
      <ref url="http://www.osvdb.org/23183" source="OSVDB">23183</ref>
      <ref url="http://www.evuln.com/vulns/76/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/76/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16711" source="BID">16711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425970/100/0/threaded" source="BUGTRAQ">20060224 [eVuln] Guestex Shell Command Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/489" source="SREASON">489</ref>
      <ref url="http://secunia.com/advisories/18927" source="SECUNIA">18927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teca_scripts" name="guestex">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0778" published="2006-02-18" name="CVE-2006-0778" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in XMB Forums 1.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) $u2u_select array parameter to u2u.inc.php and (2) $val variable (fidpw0 cookie value) in today.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xmbforum.com/" source="MISC">http://www.xmbforum.com/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0529" source="VUPEN">ADV-2006-0529</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425084/100/0/threaded" source="BUGTRAQ" adv="1">20060212 XMB Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23118" source="OSVDB">23118</ref>
      <ref url="http://www.osvdb.org/23117" source="OSVDB">23117</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00100-02122006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00100-02122006</ref>
      <ref url="http://secunia.com/advisories/18821" source="SECUNIA" adv="1">18821</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24646" source="XF">xmbforum-multiple-sql-injection(24646)</ref>
      <ref url="http://www.securityfocus.com/bid/16604" source="BID">16604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers prev="1" num="1.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0779" published="2006-02-18" name="CVE-2006-0779" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24647" source="XF">xmbforum-u2u-xss(24647)</ref>
      <ref url="http://www.xmbforum.com/" source="MISC">http://www.xmbforum.com/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0529" source="VUPEN">ADV-2006-0529</ref>
      <ref url="http://www.securityfocus.com/bid/16604" source="BID">16604</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425084/100/0/threaded" source="BUGTRAQ" adv="1">20060212 XMB Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23119" source="OSVDB">23119</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00100-02122006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00100-02122006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers prev="1" num="1.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0780" published="2006-02-19" name="CVE-2006-0780" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24691" source="XF">perlblog-weblog-xss(24691)</ref>
      <ref url="http://evuln.com/vulns/81/summary.html" source="MISC" adv="1">http://evuln.com/vulns/81/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16707" source="BID">16707</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426260/100/0/threaded" source="BUGTRAQ">20060227 [eVuln] PerlBlog Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/508" source="SREASON">508</ref>
      <ref url="http://secunia.com/advisories/18924" source="SECUNIA">18924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perlblog" name="perlblog">
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.09b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0781" published="2006-02-19" name="CVE-2006-0781" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24690" source="XF">perlblog-weblog-directory-traversal(24690)</ref>
      <ref url="http://evuln.com/vulns/81/summary.html" source="MISC" adv="1">http://evuln.com/vulns/81/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16707" source="BID">16707</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426260/100/0/threaded" source="BUGTRAQ">20060227 [eVuln] PerlBlog Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/508" source="SREASON">508</ref>
      <ref url="http://secunia.com/advisories/18924" source="SECUNIA">18924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perlblog" name="perlblog">
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.09b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0782" published="2006-02-19" name="CVE-2006-0782" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24692" source="XF">perlblog-weblog-command-execution(24692)</ref>
      <ref url="http://evuln.com/vulns/81/summary.html" source="MISC" adv="1">http://evuln.com/vulns/81/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16707" source="BID">16707</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426260/100/0/threaded" source="BUGTRAQ">20060227 [eVuln] PerlBlog Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/508" source="SREASON">508</ref>
      <ref url="http://secunia.com/advisories/18924" source="SECUNIA">18924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perlblog" name="perlblog">
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.09b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0783" published="2006-02-19" name="CVE-2006-0783" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16695" source="BID">16695</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425180/100/0/threaded" source="BUGTRAQ">20060216 Siteframe Beaumont 5.0.2 &lt;== User Comment Cross-Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24836" source="XF">siteframe-comment-xss(24836)</ref>
      <ref url="http://www.osvdb.org/23267" source="OSVDB">23267</ref>
      <ref url="http://securityreason.com/securityalert/443" source="SREASON">443</ref>
      <ref url="http://secunia.com/advisories/18892" source="SECUNIA">18892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteframe" name="siteframe_beaumont">
        <vers num="5.0.1" />
        <vers num="5.0.1a" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0784" published="2006-02-19" name="CVE-2006-0784" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0637" source="VUPEN">ADV-2006-0637</ref>
      <ref url="http://www.securityfocus.com/bid/16690" source="BID">16690</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425169/100/0/threaded" source="BUGTRAQ" adv="1">20060216 D-Link DWL-G700AP httpd DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24762" source="XF">dlink-admin-interface-dos(24762)</ref>
      <ref url="http://securityreason.com/securityalert/441" source="SREASON">441</ref>
      <ref url="http://secunia.com/advisories/18932" source="SECUNIA">18932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dwl-g700ap">
        <vers num="2.00" />
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0785" published="2006-02-19" name="CVE-2006-0785" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425196/100/0/threaded" source="BUGTRAQ">20060216 PHPKIT >= 1.6.1r2 arbitrary local/remote inclusion (unproperly patched in previous versions)</ref>
      <ref url="http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html" source="MISC">http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html</ref>
      <ref url="http://securitytracker.com/id?1015640" source="SECTRACK">1015640</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers prev="1" num="1.6.1" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0786" published="2006-02-19" name="CVE-2006-0786" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for "http://", "ftp://", and "https://" URLs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425196/100/0/threaded" source="BUGTRAQ">20060216 PHPKIT >= 1.6.1r2 arbitrary local/remote inclusion (unproperly patched in previous versions)</ref>
      <ref url="http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html" source="MISC">http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html</ref>
      <ref url="http://securitytracker.com/id?1015640" source="SECTRACK">1015640</ref>
      <ref url="http://securityreason.com/securityalert/445" source="SREASON">445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers prev="1" num="1.6.1" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0787" published="2006-02-19" name="CVE-2006-0787" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability.  NOTE: since this issue, as described by the original researcher, is entirely dependent on the presence of another vulnerability, it could be argued that Wimpy cannot be responsible for how its data file is processed by applications outside of its control. Since this issue might only be useful as a facilitator manipulation in another vulnerability, perhaps it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xorcrew.net/xpa/XPA-WimpyMP3Player.txt" source="MISC" adv="1">http://www.xorcrew.net/xpa/XPA-WimpyMP3Player.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16696" source="BID">16696</ref>
      <ref url="http://secunia.com/advisories/18900" source="SECUNIA" adv="1">18900</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24770" source="XF">wimpy-wimpytrackplays-no-auth(24770)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plaino" name="wimpy_mp3">
        <vers prev="1" num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0788" published="2006-02-19" name="CVE-2006-0788" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with "!R!SIOP0", as demonstrated using (1) a connection to to TCP port 9100 or (2) the UNIX lp command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0620" source="VUPEN">ADV-2006-0620</ref>
      <ref url="http://www.securityfocus.com/bid/16685" source="BID">16685</ref>
      <ref url="http://secunia.com/advisories/18896" source="SECUNIA" adv="1">18896</ref>
      <ref url="http://evader.wordpress.com/2006/02/16/kyocera-printers/" source="MISC">http://evader.wordpress.com/2006/02/16/kyocera-printers/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24772" source="XF">kyocera-fs3830n-no-auth(24772)</ref>
      <ref url="http://www.osvdb.org/23245" source="OSVDB">23245</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0344.html" source="FULLDISC">20060215 Kyocera Network Printers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kyocera" name="fs-3830n">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0789" published="2006-02-19" name="CVE-2006-0789" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Certain unspecified Kyocera printers have a default "admin" account with a blank password, which allows remote attackers to access an administrative menu via a telnet session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0620" source="VUPEN">ADV-2006-0620</ref>
      <ref url="http://secunia.com/advisories/18896" source="SECUNIA" adv="1">18896</ref>
      <ref url="http://evader.wordpress.com/2006/02/16/kyocera-printers/" source="MISC">http://evader.wordpress.com/2006/02/16/kyocera-printers/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24774" source="XF">kyocera-fs3830n-blank-password(24774)</ref>
      <ref url="http://www.osvdb.org/23246" source="OSVDB">23246</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0344.html" source="FULLDISC">20060215 Kyocera Network Printers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kyocera" name="fs-3830n">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0790" published="2006-02-19" name="CVE-2006-0790" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Rockliffe MailSite 7.0 and earlier allows remote attackers to cause a denial of service by sending crafted LDAP packets to port 389/TCP, as demonstrated by the ProtoVer LDAP testsuite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24686" source="XF">mailsite-ldap-dos(24686)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0598" source="VUPEN">ADV-2006-0598</ref>
      <ref url="http://www.securityfocus.com/bid/16675" source="BID">16675</ref>
      <ref url="http://secunia.com/advisories/18888" source="SECUNIA" adv="1">18888</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002926.html" source="MLIST">[Dailydave] 20060214 MailSite (WorldMail) fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers num="4.2.10" />
        <vers num="5" />
        <vers num="5.3.4" />
        <vers num="6.1.22" />
        <vers num="7.0.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0791" published="2006-02-19" name="CVE-2006-0791" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xorcrew.net/xpa/XPA-HostAdmin.txt" source="MISC" adv="1">http://www.xorcrew.net/xpa/XPA-HostAdmin.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0618" source="VUPEN">ADV-2006-0618</ref>
      <ref url="http://www.securityfocus.com/bid/16682" source="BID">16682</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/497133/100/0/threaded" source="BUGTRAQ">20081007 Re: HostAdmin 3.* Remote File Include Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/497093/100/0/threaded" source="BUGTRAQ">20081007 HostAdmin 3.* Remote File Include Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18901" source="SECUNIA" adv="1">18901</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24723" source="XF">hostadmin-path-file-include(24723)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435993/30/4650/threaded" source="BUGTRAQ">20060605 [MajorSecurity #9]HostAdmin &lt;= 3.1 - Remote File Include Vulnerability</ref>
      <ref url="http://www.osvdb.org/23241" source="OSVDB">23241</ref>
      <ref url="http://securitytracker.com/id?1016273" source="SECTRACK">1016273</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0340.html" source="FULLDISC">20060215 HostAdmin - Remote Command Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dreamcost" name="hostadmin">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0792" published="2006-02-19" name="CVE-2006-0792" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0639" source="VUPEN">ADV-2006-0639</ref>
      <ref url="http://secunia.com/advisories/18776" source="SECUNIA" adv="1">18776</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24749" source="XF">vwebmail-preferencespersonal-xss(24749)</ref>
      <ref url="http://www.securityfocus.com/bid/16706" source="BID">16706</ref>
      <ref url="http://www.osvdb.org/23260" source="OSVDB">23260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="v-webmail" name="v-webmail">
        <vers num="1.6.1" />
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0793" published="2006-02-19" name="CVE-2006-0793" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0639" source="VUPEN">ADV-2006-0639</ref>
      <ref url="http://secunia.com/advisories/18776" source="SECUNIA" adv="1">18776</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24753" source="XF">vwebmail-frameset-spoofing(24753)</ref>
      <ref url="http://www.securityfocus.com/bid/16706" source="BID">16706</ref>
      <ref url="http://www.osvdb.org/23261" source="OSVDB">23261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="v-webmail" name="v-webmail">
        <vers num="1.6.1" />
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0794" published="2006-02-19" name="CVE-2006-0794" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0639" source="VUPEN">ADV-2006-0639</ref>
      <ref url="http://secunia.com/advisories/18776" source="SECUNIA" adv="1">18776</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24754" source="XF">vwebmail-help-path-disclosure(24754)</ref>
      <ref url="http://www.osvdb.org/23262" source="OSVDB">23262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="v-webmail" name="v-webmail">
        <vers num="1.6.1" />
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0795" published="2006-02-19" name="CVE-2006-0795" modified="2011-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24672" source="XF">quirex-convert-information-disclosure(24672)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0641" source="VUPEN" adv="1">ADV-2006-0641</ref>
      <ref url="http://www.securityfocus.com/bid/16709" source="BID">16709</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426188/100/0/threaded" source="BUGTRAQ">20060226 [eVuln] Quirex Arbitrary File Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18926" source="SECUNIA" adv="1">18926</ref>
      <ref url="http://evuln.com/vulns/78/summary.html" source="MISC" adv="1">http://evuln.com/vulns/78/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomastsoi" name="quirex">
        <vers num="2.0" />
        <vers prev="1" num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0796" published="2006-02-19" name="CVE-2006-0796" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0616" source="VUPEN">ADV-2006-0616</ref>
      <ref url="http://www.securityfocus.com/bid/16681" source="BID">16681</ref>
      <ref url="http://www.osvdb.org/23235" source="OSVDB">23235</ref>
      <ref url="http://secunia.com/advisories/18873" source="SECUNIA" adv="1">18873</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24747" source="XF">clevercopy-subject-xss(24747)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0797" published="2006-02-19" name="CVE-2006-0797" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Nokia N70 cell phone allows remote attackers to caues a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24688" source="XF">nokia-bluetooth-l2cap-dos(24688)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0538" source="VUPEN">ADV-2006-0538</ref>
      <ref url="http://www.securityfocus.com/bid/16666" source="BID">16666</ref>
      <ref url="http://www.secuobs.com/news/15022006-nokia_n70.shtml#english" source="MISC">http://www.secuobs.com/news/15022006-nokia_n70.shtml#english</ref>
      <ref url="http://www.osvdb.org/23061" source="OSVDB">23061</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0316.html" source="FULLDISC" adv="1">20060215 [ Secuobs - Advisory ] Another kind of DoS on Nokia cell phones</ref>
      <ref url="http://secunia.com/advisories/18724" source="SECUNIA">18724</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="n70">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0798" published="2006-02-19" name="CVE-2006-0798" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16704" source="BID" patch="1">16704</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0644" source="VUPEN">ADV-2006-0644</ref>
      <ref url="http://secunia.com/secunia_research/2006-4/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2006-4/advisory/</ref>
      <ref url="http://secunia.com/advisories/18775" source="SECUNIA" adv="1">18775</ref>
      <ref url="http://macallan.club.fr/MMS/index.html" source="MISC">http://macallan.club.fr/MMS/index.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24761" source="XF">macallan-imap-directory-traversal(24761)</ref>
      <ref url="http://www.osvdb.org/23269" source="OSVDB">23269</ref>
      <ref url="http://securitytracker.com/id?1015647" source="SECTRACK">1015647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macallan" name="mail_solution">
        <vers prev="1" num="4.8.03.025" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0799" published="2006-02-19" name="CVE-2006-0799" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.  NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425883/100/0/threaded" source="BUGTRAQ">20060223 Re: Internet Explorer Phishing mouseover issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425386/100/0/threaded" source="BUGTRAQ">20060218 Re: Internet Explorer Phishing mouseover issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425298/100/0/threaded" source="BUGTRAQ">20060216 Internet Explorer Phishing mouseover issue</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17938" source="XF">ie-ahref-status-spoofing(17938)</ref>
      <ref url="http://www.osvdb.org/23609" source="OSVDB">23609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0800" published="2006-02-20" name="CVE-2006-0800" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "&lt;" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24823" source="XF" patch="1">postnuke-user-nslanguages-xss(24823)</ref>
      <ref url="http://www.securityfocus.com/bid/16752" source="BID" patch="1">16752</ref>
      <ref url="http://secunia.com/advisories/18937" source="SECUNIA" patch="1" adv="1">18937</ref>
      <ref url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754" source="CONFIRM" patch="1">http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0673" source="VUPEN" adv="1">ADV-2006-0673</ref>
      <ref url="http://securityreason.com/securityalert/454" source="SREASON">454</ref>
      <ref url="http://securityreason.com/securityalert/454" source="MISC" adv="1">http://securityreason.com/securityalert/454</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html" source="FULLDISC">20060219 Multiple vulnerabilities in PostNuke &lt;= 0.761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.7" />
        <vers num="0.70" />
        <vers num="0.703" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.721" />
        <vers num="0.726.3" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75_rc3" />
        <vers num="0.761" />
        <vers num="0.761a" />
        <vers num="0.76_rc4" />
        <vers num="0.76_rc4a" />
        <vers num="0.76_rc4b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0801" published="2006-02-20" name="CVE-2006-0801" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16752" source="BID" patch="1">16752</ref>
      <ref url="http://secunia.com/advisories/18937" source="SECUNIA" patch="1" adv="1">18937</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24827" source="XF">postnuke-nslanguages-sql-injection(24827)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0673" source="VUPEN">ADV-2006-0673</ref>
      <ref url="http://securityreason.com/securityalert/454" source="SREASON">454</ref>
      <ref url="http://securityreason.com/securityalert/454" source="SREASON" adv="1">454</ref>
      <ref url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754" source="CONFIRM">http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html" source="FULLDISC">20060219 Multiple vulnerabilities in PostNuke &lt;= 0.761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers prev="1" num="0.761" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0802" published="2006-02-20" name="CVE-2006-0802" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation operation.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24823" source="XF">postnuke-user-nslanguages-xss(24823)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0673" source="VUPEN">ADV-2006-0673</ref>
      <ref url="http://www.securityfocus.com/bid/16752" source="BID">16752</ref>
      <ref url="http://securityreason.com/securityalert/454" source="SREASON" adv="1">454</ref>
      <ref url="http://securityreason.com/securityalert/454" source="SREASON">454</ref>
      <ref url="http://secunia.com/advisories/18937" source="SECUNIA" adv="1">18937</ref>
      <ref url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754" source="CONFIRM">http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html" source="FULLDISC">20060219 Multiple vulnerabilities in PostNuke &lt;= 0.761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers prev="1" num="0.761" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0803" published="2006-02-23" name="CVE-2006-0803" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2006_09_gpg.html" source="SUSE" adv="1">SUSE-SA:2006:009</ref>
      <ref url="http://www.securityfocus.com/bid/16889" source="BID">16889</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_13_gpg.html" source="SUSE">SUSE-SA:2006:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="10.0" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0804" published="2006-02-20" name="CVE-2006-0804" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0702" source="VUPEN">ADV-2006-0702</ref>
      <ref url="http://www.securityfocus.com/bid/16728" source="BID">16728</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.005-tin.html" source="OPENPKG" adv="1">OpenPKG-SA-2006.005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24841" source="XF">tin-offbyone-bo(24841)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200611-18.xml" source="GENTOO">GLSA-200611-18</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tin" name="tin">
        <vers num="1.0_pl0" />
        <vers num="1.0_pl1" />
        <vers num="1.0_pl2" />
        <vers num="1.0_pl3" />
        <vers num="1.0_pl4" />
        <vers num="1.0_pl5" />
        <vers num="1.1_pl0" />
        <vers num="1.1_pl1" />
        <vers num="1.1_pl2" />
        <vers num="1.1_pl3" />
        <vers num="1.1_pl4" />
        <vers num="1.1_pl5" />
        <vers num="1.1_pl6" />
        <vers num="1.1_pl7" />
        <vers num="1.1_pl8" />
        <vers num="1.1_pl9" />
        <vers num="1.2_pl0" />
        <vers num="1.2_pl1" />
        <vers num="1.2_pl2" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0805" published="2006-02-20" name="CVE-2006-0805" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/advisory-45.html" source="MISC" adv="1">http://www.waraxe.us/advisory-45.html</ref>
      <ref url="http://www.securityfocus.com/bid/16722" source="BID">16722</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425394/100/0/threaded" source="BUGTRAQ" adv="1">20060218 [waraxe-2006-SA#045] - Bypassing CAPTCHA in phpNuke 6.x-7.9</ref>
      <ref url="http://securityreason.com/securityalert/455" source="SREASON">455</ref>
      <ref url="http://secunia.com/advisories/18936" source="SECUNIA">18936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers num="7.8" />
        <vers num="7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0806" published="2006-02-20" name="CVE-2006-0806" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/2021" source="VUPEN" adv="1">ADV-2006-2021</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0664" source="VUPEN" adv="1">ADV-2006-0664</ref>
      <ref url="http://www.securityfocus.com/bid/16720" source="BID">16720</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425393/100/0/threaded" source="BUGTRAQ">20060218 ADOdb Library Cross Site Scripting</ref>
      <ref url="http://www.osvdb.org/23362" source="OSVDB">23362</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00101-02182006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00101-02182006</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO">GLSA-200604-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN">DSA-1031</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN">DSA-1029</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=419843&amp;group_id=8956" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=419843&amp;group_id=8956</ref>
      <ref url="http://securityreason.com/securityalert/452" source="SREASON">452</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA" adv="1">19691</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA" adv="1">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA" adv="1">19590</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA" adv="1">19555</ref>
      <ref url="http://secunia.com/advisories/18928" source="SECUNIA" adv="1">18928</ref>
      <ref url="http://phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.php?r1=1.1&amp;r2=1.2" source="MISC">http://phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.php?r1=1.1&amp;r2=1.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66" />
        <vers num="4.68" />
        <vers num="4.70" />
        <vers num="4.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0807" published="2006-02-20" name="CVE-2006-0807" modified="2011-08-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425498/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060220 Secunia Research: NJStar Word Processor Font Name Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2006-5/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-5/advisory/</ref>
      <ref url="http://secunia.com/advisories/18702" source="SECUNIA" patch="1" adv="1">18702</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24773" source="XF">njstar-font-name-bo(24773)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0670" source="VUPEN" adv="1">ADV-2006-0670</ref>
      <ref url="http://www.securityfocus.com/bid/16737" source="BID">16737</ref>
      <ref url="http://www.osvdb.org/23354" source="OSVDB">23354</ref>
      <ref url="http://www.njstar.com/njstar/japanese/" source="CONFIRM">http://www.njstar.com/njstar/japanese/</ref>
      <ref url="http://www.njstar.com/njstar/chinese/" source="CONFIRM">http://www.njstar.com/njstar/chinese/</ref>
      <ref url="http://securitytracker.com/id?1015649" source="SECTRACK">1015649</ref>
      <ref url="http://securityreason.com/securityalert/461" source="SREASON">461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="njstar" name="chinese_word_processor">
        <vers prev="1" num="5.01.41108" />
      </prod>
      <prod vendor="njstar" name="japanese_word_processor">
        <vers prev="1" num="5.01.41108" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0808" published="2006-02-20" name="CVE-2006-0808" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" nodes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23336" source="OSVDB">23336</ref>
      <ref url="http://secunia.com/advisories/18980" source="SECUNIA">18980</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/mute-net/MUTE/doc/notes/notes.txt?view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/mute-net/MUTE/doc/notes/notes.txt?view=markup</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24931" source="XF">mute-mwebcache-security-bypass(24931)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mute" name="mute">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0809" published="2006-02-20" name="CVE-2006-0809" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23303" source="OSVDB">23303</ref>
      <ref url="http://www.osvdb.org/23302" source="OSVDB">23302</ref>
      <ref url="http://www.osvdb.org/23301" source="OSVDB">23301</ref>
      <ref url="http://evuln.com/vulns/84/summary.html" source="MISC" adv="1">http://evuln.com/vulns/84/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24779" source="XF">skateboard-authentication-bypass(24779)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24778" source="XF">skateboard-sendpass-sql-injection(24778)</ref>
      <ref url="http://www.securityfocus.com/bid/16936" source="BID">16936</ref>
      <ref url="http://www.securityfocus.com/archive/1/426658/30/0/threaded" source="BUGTRAQ">20060303 [eVuln] Skate Board Multimple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/540" source="SREASON">540</ref>
      <ref url="http://secunia.com/advisories/18978" source="SECUNIA">18978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skate_board" name="skate_board">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0810" published="2006-02-20" name="CVE-2006-0810" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24780" source="XF">skateboard-config-file-include(24780)</ref>
      <ref url="http://www.securityfocus.com/bid/16936" source="BID">16936</ref>
      <ref url="http://www.securityfocus.com/archive/1/426658/30/0/threaded" source="BUGTRAQ">20060303 [eVuln] Skate Board Multimple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23304" source="OSVDB">23304</ref>
      <ref url="http://secunia.com/advisories/18978" source="SECUNIA">18978</ref>
      <ref url="http://evuln.com/vulns/84/summary.html" source="MISC" adv="1">http://evuln.com/vulns/84/summary.html</ref>
      <ref url="http://securityreason.com/securityalert/540" source="SREASON">540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skate_board" name="skate_board">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0811" published="2006-02-20" name="CVE-2006-0811" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23305" source="OSVDB">23305</ref>
      <ref url="http://evuln.com/vulns/84/summary.html" source="MISC" adv="1">http://evuln.com/vulns/84/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24781" source="XF">skateboard-registration-xss(24781)</ref>
      <ref url="http://www.securityfocus.com/bid/16936" source="BID">16936</ref>
      <ref url="http://www.securityfocus.com/archive/1/426658/30/0/threaded" source="BUGTRAQ">20060303 [eVuln] Skate Board Multimple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/540" source="SREASON">540</ref>
      <ref url="http://secunia.com/advisories/18978" source="SECUNIA">18978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skate_board" name="skate_board">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0812" published="2006-02-23" name="CVE-2006-0812" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16583" source="SECUNIA" patch="1" adv="1">16583</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0701" source="VUPEN">ADV-2006-0701</ref>
      <ref url="http://www.securityfocus.com/bid/16788" source="BID">16788</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425890/100/0/threaded" source="BUGTRAQ">20060223 Secunia Research: Visnetic AntiVirus Plug-in for MailServerPrivilege Escalation</ref>
      <ref url="http://securitytracker.com/id?1015670" source="SECTRACK">1015670</ref>
      <ref url="http://secunia.com/secunia_research/2005-65/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-65/advisory/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24928" source="XF">visnetic-av-plugin-privilege-elevation(24928)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visnetic" name="visnetic_antivirus_plug-in_for_mail_server">
        <vers num="4.6.0.4" />
        <vers num="4.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0813" published="2006-02-24" name="CVE-2006-0813" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24872" source="XF">winace-arj-header-bo(24872)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0709" source="VUPEN" adv="1">ADV-2006-0709</ref>
      <ref url="http://www.securityfocus.com/bid/16786" source="BID">16786</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425894/100/0/threaded" source="BUGTRAQ">20060223 Secunia Research: WinACE ARJ Archive Handling Buffer Overflow</ref>
      <ref url="http://www.osvdb.org/23383" source="OSVDB">23383</ref>
      <ref url="http://securitytracker.com/id?1015672" source="SECTRACK">1015672</ref>
      <ref url="http://securityreason.com/securityalert/479" source="SREASON">479</ref>
      <ref url="http://secunia.com/secunia_research/2005-67/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-67/advisory/</ref>
      <ref url="http://secunia.com/advisories/17251" source="SECUNIA" adv="1">17251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winace" name="winace">
        <vers num="2.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0814" published="2006-03-06" name="CVE-2006-0814" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426446/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060301 Secunia Research: Lighttpd Script Source Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2006-9/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-9/advisory/</ref>
      <ref url="http://secunia.com/advisories/18886" source="SECUNIA" patch="1" adv="1">18886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24976" source="XF">lighttpd-source-code-disclosure(24976)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0782" source="VUPEN">ADV-2006-0782</ref>
      <ref url="http://www.osvdb.org/23542" source="OSVDB">23542</ref>
      <ref url="http://trac.lighttpd.net/trac/changeset/1005" source="CONFIRM">http://trac.lighttpd.net/trac/changeset/1005</ref>
      <ref url="http://www.securityfocus.com/bid/16893" source="BID">16893</ref>
      <ref url="http://securitytracker.com/id?1015703" source="SECTRACK">1015703</ref>
      <ref url="http://securityreason.com/securityalert/523" source="SREASON">523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0815" published="2006-03-06" name="CVE-2006-0815" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426461/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060301 Secunia Research: NetworkActiv Web Server Script Source DisclosureVulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2006-10/advisory" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-10/advisory</ref>
      <ref url="http://secunia.com/advisories/18947" source="SECUNIA" patch="1" adv="1">18947</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24979" source="XF">networkactiv-script-source-disclosure(24979)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0783" source="VUPEN">ADV-2006-0783</ref>
      <ref url="http://www.securityfocus.com/bid/16895" source="BID">16895</ref>
      <ref url="http://www.networkactiv.com/WebServer.html" source="CONFIRM">http://www.networkactiv.com/WebServer.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="networkactiv" name="networkactiv_web_server">
        <vers num="3.5.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0816" published="2006-03-24" name="CVE-2006-0816" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 2.0.7 or contact the vendor for a patch.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1055" source="VUPEN">ADV-2006-1055</ref>
      <ref url="http://secunia.com/secunia_research/2006-11/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2006-11/advisory/</ref>
      <ref url="http://secunia.com/advisories/18950" source="SECUNIA" adv="1">18950</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25405" source="XF">orion-jsp-source-disclosure(25405)</ref>
      <ref url="http://www.securityfocus.com/bid/17204" source="BID">17204</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428601/100/0/threaded" source="BUGTRAQ">20060323 Secunia Research: Orion Application Server JSP Source DisclosureVulnerability</ref>
      <ref url="http://www.osvdb.org/24053" source="OSVDB">24053</ref>
      <ref url="http://securitytracker.com/id?1015823" source="SECTRACK">1015823</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1455.html" source="FULLDISC">20060323 Secunia Research: Orion Application Server JSP Source Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orion*" name="orion_application_server">
        <vers prev="1" num="2.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0817" published="2006-07-21" name="CVE-2006-0817" modified="2011-03-07" discovered="2006-02-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/19002" source="BID" patch="1">19002</ref>
      <ref url="http://secunia.com/advisories/18966" source="SECUNIA" patch="1" adv="1">18966</ref>
      <ref url="http://secunia.com/advisories/18953" source="SECUNIA" patch="1" adv="1">18953</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2825" source="VUPEN">ADV-2006-2825</ref>
      <ref url="http://secunia.com/secunia_research/2006-14/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2006-14/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2006-12/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2006-12/advisory/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27773" source="XF">visnetic-include-file-include(27773)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440302/100/0/threaded" source="BUGTRAQ">20060717 Secunia Research: VisNetic Mail Server Two File InclusionVulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440297/100/0/threaded" source="BUGTRAQ">20060717 Secunia Research: IceWarp Web Mail Two File InclusionVulnerabilities</ref>
      <ref url="http://www.osvdb.org/27328" source="OSVDB">27328</ref>
      <ref url="http://securitytracker.com/id?1016514" source="SECTRACK">1016514</ref>
      <ref url="http://securitytracker.com/id?1016513" source="SECTRACK">1016513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="visnetic_mail_server">
        <vers num="8.3.5" />
      </prod>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.6.0" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="8.3.8r" edition="" />
        <vers num="8.3.8r" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0818" published="2006-07-21" name="CVE-2006-0818" modified="2011-03-07" discovered="2006-02-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the lang_settings parameter to mail/index.html, which is not properly sanitized by the validatefolder PHP function, possibly due to an incomplete fix for CVE-2005-4558.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/19002" source="BID" patch="1">19002</ref>
      <ref url="http://secunia.com/secunia_research/2006-14/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-14/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2006-12/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-12/advisory/</ref>
      <ref url="http://secunia.com/advisories/18966" source="SECUNIA" patch="1" adv="1">18966</ref>
      <ref url="http://secunia.com/advisories/18953" source="SECUNIA" patch="1" adv="1">18953</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2825" source="VUPEN">ADV-2006-2825</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27780" source="XF">visnetic-language-file-include(27780)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440302/100/0/threaded" source="BUGTRAQ">20060717 Secunia Research: VisNetic Mail Server Two File InclusionVulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440297/100/0/threaded" source="BUGTRAQ">20060717 Secunia Research: IceWarp Web Mail Two File InclusionVulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016514" source="SECTRACK">1016514</ref>
      <ref url="http://securitytracker.com/id?1016513" source="SECTRACK">1016513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="visnetic_mail_server">
        <vers num="8.3.5" />
      </prod>
      <prod vendor="icewarp" name="web_mail">
        <vers num="5.6.0" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="8.3.8r" edition="" />
        <vers num="8.3.8r" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0819" published="2006-03-13" name="CVE-2006-0819" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427478/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting</ref>
      <ref url="http://secunia.com/secunia_research/2006-13/advisory" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-13/advisory</ref>
      <ref url="http://secunia.com/advisories/18962" source="SECUNIA" patch="1" adv="1">18962</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0937" source="VUPEN">ADV-2006-0937</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25178" source="XF">dwarfhttp-extension-information-disclosure(25178)</ref>
      <ref url="http://www.securityfocus.com/bid/17123" source="BID">17123</ref>
      <ref url="http://www.osvdb.org/23836" source="OSVDB">23836</ref>
      <ref url="http://securitytracker.com/id?1015779" source="SECTRACK">1015779</ref>
      <ref url="http://securityreason.com/securityalert/576" source="SREASON">576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="dwarf_http_server">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0820" published="2006-03-13" name="CVE-2006-0820" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427478/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting</ref>
      <ref url="http://secunia.com/secunia_research/2006-13/advisory" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-13/advisory</ref>
      <ref url="http://secunia.com/advisories/18962" source="SECUNIA" patch="1" adv="1">18962</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0937" source="VUPEN">ADV-2006-0937</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25179" source="XF">dwarfhttp-url-xss(25179)</ref>
      <ref url="http://www.securityfocus.com/bid/17123" source="BID">17123</ref>
      <ref url="http://www.osvdb.org/23837" source="OSVDB">23837</ref>
      <ref url="http://securitytracker.com/id?1015779" source="SECTRACK">1015779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="dwarf_http_server">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0821" published="2006-02-21" name="CVE-2006-0821" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0660" source="VUPEN">ADV-2006-0660</ref>
      <ref url="http://secunia.com/advisories/18929" source="SECUNIA" adv="1">18929</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24783" source="XF">bxcp-tid-sql-injection(24783)</ref>
      <ref url="http://milw0rm.com/exploits/1513" source="MILW0RM">1513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bxcp" name="bxcp">
        <vers num="0.299" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0822" published="2006-02-21" name="CVE-2006-0822" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in EmuLinker Kaillera Server before 0.99.17 allows remote attackers to cause a denial of service (probably resource consumption) via a crafted packet that causes a "ghost game" to be left on the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=394690&amp;group_id=127754" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=394690&amp;group_id=127754</ref>
      <ref url="http://secunia.com/advisories/18938" source="SECUNIA" patch="1" adv="1">18938</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0665" source="VUPEN">ADV-2006-0665</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24784" source="XF">emulinker-packet-handling-dos(24784)</ref>
      <ref url="http://www.securityfocus.com/bid/16733" source="BID">16733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emulinker_kaillera_server" name="emulinker_kaillera_server">
        <vers num="0.97.6" />
        <vers num="0.98.2" />
        <vers num="0.98.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0823" published="2006-02-21" name="CVE-2006-0823" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18920" source="SECUNIA" patch="1" adv="1">18920</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0661" source="VUPEN">ADV-2006-0661</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00102-02192006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00102-02192006</ref>
      <ref url="http://www.geeklog.net/article.php/geeklog-1.4.0sr1" source="CONFIRM">http://www.geeklog.net/article.php/geeklog-1.4.0sr1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24775" source="XF">geeklog-users-sessions-sql-injection(24775)</ref>
      <ref url="http://www.securityfocus.com/bid/16755" source="BID">16755</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425506/100/0/threaded" source="BUGTRAQ">20060219 Geeklog Remote Code Execution</ref>
      <ref url="http://www.osvdb.org/23348" source="OSVDB">23348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geeklog" name="geeklog">
        <vers num="1.3.11" />
        <vers num="1.3.11_sr1" />
        <vers num="1.3.11_sr2" />
        <vers num="1.3.11_sr3" />
        <vers num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0824" published="2006-02-21" name="CVE-2006-0824" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.geeklog.net/article.php/geeklog-1.4.0sr1" source="CONFIRM" patch="1">http://www.geeklog.net/article.php/geeklog-1.4.0sr1</ref>
      <ref url="http://secunia.com/advisories/18920" source="SECUNIA" patch="1" adv="1">18920</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0661" source="VUPEN">ADV-2006-0661</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00102-02192006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00102-02192006</ref>
      <ref url="http://www.securityfocus.com/bid/16755" source="BID">16755</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425506/100/0/threaded" source="BUGTRAQ">20060219 Geeklog Remote Code Execution</ref>
      <ref url="http://www.osvdb.org/23349" source="OSVDB">23349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geeklog" name="geeklog">
        <vers num="1.3.11" />
        <vers num="1.3.11_sr1" />
        <vers num="1.3.11_sr2" />
        <vers num="1.3.11_sr3" />
        <vers num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0825" published="2006-02-21" name="CVE-2006-0825" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain "unauthorized network access" via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24804" source="XF">xerox-workcentre-auth-bypass(24804)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0668" source="VUPEN">ADV-2006-0668</ref>
      <ref url="http://www.securityfocus.com/bid/16726" source="BID">16726</ref>
      <ref url="http://www.osvdb.org/23359" source="OSVDB">23359</ref>
      <ref url="http://securitytracker.com/id?1015648" source="SECTRACK">1015648</ref>
      <ref url="http://secunia.com/advisories/18952" source="SECUNIA" adv="1">18952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_232">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_238">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_245">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_255">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_265">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_275">
        <vers num="" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0826" published="2006-02-21" name="CVE-2006-0826" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to cause a denial of service via a crafted Postscript request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24805" source="XF">xerox-workcentre-postscript-dos(24805)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0668" source="VUPEN">ADV-2006-0668</ref>
      <ref url="http://www.securityfocus.com/bid/16723" source="BID">16723</ref>
      <ref url="http://securitytracker.com/id?1015648" source="SECTRACK">1015648</ref>
      <ref url="http://secunia.com/advisories/18952" source="SECUNIA" adv="1">18952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_232">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_238">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_245">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_255">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_265">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_275">
        <vers num="" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0827" published="2006-02-21" name="CVE-2006-0827" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24806" source="XF">xerox-workcentre-xss(24806)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0668" source="VUPEN">ADV-2006-0668</ref>
      <ref url="http://www.securityfocus.com/bid/16727" source="BID">16727</ref>
      <ref url="http://secunia.com/advisories/18952" source="SECUNIA" adv="1">18952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_232">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_238">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_245">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_255">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_265">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_275">
        <vers num="" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0828" published="2006-02-21" name="CVE-2006-0828" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to "reduce effectiveness of security features" via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0668" source="VUPEN">ADV-2006-0668</ref>
      <ref url="http://securitytracker.com/id?1015648" source="SECTRACK">1015648</ref>
      <ref url="http://secunia.com/advisories/18952" source="SECUNIA" adv="1">18952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_232">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_238">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_245">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_255">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_265">
        <vers num="" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_275">
        <vers num="" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0829" published="2006-02-21" name="CVE-2006-0829" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using "Click Log".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.eblah.com/forum/m-1140116897/" source="CONFIRM" patch="1">http://www.eblah.com/forum/m-1140116897/</ref>
      <ref url="http://evuln.com/vulns/83/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/83/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0638" source="VUPEN">ADV-2006-0638</ref>
      <ref url="http://www.securityfocus.com/bid/16713" source="BID">16713</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24777" source="XF">eblah-httpreferer-xss(24777)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426582/100/0/threaded" source="BUGTRAQ">20060302 [eVuln] E-Blah Platinum 'Referer' XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/23299" source="OSVDB">23299</ref>
      <ref url="http://securityreason.com/securityalert/528" source="SREASON">528</ref>
      <ref url="http://secunia.com/advisories/18992" source="SECUNIA">18992</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-blah" name="platinum">
        <vers num="9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0830" published="2006-02-21" name="CVE-2006-0830" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425283/100/0/threaded" source="BUGTRAQ">20060216 Stack overflow vulnerability in Internet Explorer exploitable trough VBScript and JScript scripting engines.</ref>
      <ref url="http://www.securityfocus.com/archive/1/425378/100/0/threaded" source="BUGTRAQ">20060218 Re: Stack overflow vulnerability in Internet Explorer exploitable trough VBScript and JScript scripting engines.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24788" source="XF">ie-script-engine-stack-dos(24788)</ref>
      <ref url="http://www.securityfocus.com/bid/16687" source="BID">16687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0831" published="2006-02-21" name="CVE-2006-0831" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php in Tasarim Rehberi allows remote attackers to execute arbitrary PHP code via a URL in the (1) sayfaadi or (2) sayfa parameter.  NOTE: this might be a site-specific issue.  If so, it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425389/100/0/threaded" source="BUGTRAQ">20060218 Tasarim Rehberi Index.PHP Remote Command Exucetion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tasarim_rehberi" name="tasarim_rehberi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0832" published="2006-02-21" name="CVE-2006-0832" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0662" source="VUPEN">ADV-2006-0662</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425395/100/0/threaded" source="BUGTRAQ">20060218 SLQ Injection vulnerability in WPCeasy</ref>
      <ref url="http://secunia.com/advisories/18945" source="SECUNIA" adv="1">18945</ref>
      <ref url="http://www.securityfocus.com/bid/16721" source="BID">16721</ref>
      <ref url="http://securityreason.com/securityalert/456" source="SREASON">456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wpc.easy" name="wpc.easy">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0833" published="2006-02-21" name="CVE-2006-0833" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0674" source="VUPEN">ADV-2006-0674</ref>
      <ref url="http://secunia.com/advisories/18965" source="SECUNIA" adv="1">18965</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24807" source="XF">barracuda-multiple-xss(24807)</ref>
      <ref url="http://www.securityfocus.com/bid/16746" source="BID">16746</ref>
      <ref url="http://www.osvdb.org/23372" source="OSVDB">23372</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boonex" name="barracuda_directory">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0834" published="2006-02-21" name="CVE-2006-0834" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Uniden UIP1868P VoIP Telephone and Router has a default password of admin for the web-based configuration utility, which allows remote attackers to obtain sensitive information on the device such as telephone numbers called, and possibly connect to other hosts.  NOTE: it is possible that this password was configured by a reseller, not the original vendor; if so, then this is not a vulnerability in the product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425362/100/0/threaded" source="BUGTRAQ">20060216 Uniden UIP1868P (VoIP phone/gateway) default easy-to-guess password vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24786" source="XF">uniden-uip1868p-default-account(24786)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uniden" name="uip1868p">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0835" published="2006-02-21" name="CVE-2006-0835" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24729" source="XF">webcalendarpro-dropbase-sql-injection(24729)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0700" source="VUPEN">ADV-2006-0700</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0340.html" source="FULLDISC">20060215 Web Calendar Pro - Denial of Service SQL Injection Vulnerability</ref>
      <ref url="http://www.xorcrew.net/xpa/XPA-WebCalendarPro.txt" source="MISC">http://www.xorcrew.net/xpa/XPA-WebCalendarPro.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16789" source="BID">16789</ref>
      <ref url="http://secunia.com/advisories/18902" source="SECUNIA">18902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mitridat" name="web_calendar_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0836" published="2006-02-21" name="CVE-2006-0836" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePhone field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16716" source="BID">16716</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425602/100/0/threaded" source="BUGTRAQ">20060221 Mozila Thunderbird 1.5 Address Book DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0399.html" source="FULLDISC">20060217 Mozila Thunderbird 1.5 Address Book DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24810" source="XF">thunderbird-address-book-dos(24810)</ref>
      <ref url="http://securityreason.com/securityalert/469" source="SREASON">469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0837" published="2006-02-21" name="CVE-2006-0837" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf, (2) /opt/NeuSecure/etc/cms-3.0.236.buildconf, and (3) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to read sensitive information such as passwords.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16700" source="BID">16700</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425304/100/0/threaded" source="BUGTRAQ">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref>
      <ref url="http://www.osvdb.org/23270" source="OSVDB">23270</ref>
      <ref url="http://securitytracker.com/id?1015642" source="SECTRACK">1015642</ref>
      <ref url="http://secunia.com/advisories/18922" source="SECUNIA" adv="1">18922</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0364.html" source="FULLDISC">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24785" source="XF">netcool-neosecure-config-weak-permission(24785)</ref>
      <ref url="http://www.securityfocus.com/bid/16693" source="BID">16693</ref>
      <ref url="http://www.osvdb.org/23914" source="OSVDB">23914</ref>
      <ref url="http://www.osvdb.org/23271" source="OSVDB">23271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micromuse" name="netcool_neusecure">
        <vers num="3.0.236" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0838" published="2006-02-21" name="CVE-2006-0838" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 stores cleartext passwords in the (1) CMS_DBPASS, (2) CMSM_DBPASS, and (3) RPT_DBPASS fields in /etc/neusecure.conf, and in (4) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to gain privileges.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16698" source="BID">16698</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425304/100/0/threaded" source="BUGTRAQ">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref>
      <ref url="http://www.osvdb.org/23271" source="OSVDB">23271</ref>
      <ref url="http://www.osvdb.org/23270" source="OSVDB">23270</ref>
      <ref url="http://securitytracker.com/id?1015642" source="SECTRACK">1015642</ref>
      <ref url="http://secunia.com/advisories/18922" source="SECUNIA" adv="1">18922</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0364.html" source="FULLDISC">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24787" source="XF">netcool-neosecure-plaintext-password(24787)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24785" source="XF">netcool-neosecure-config-weak-permission(24785)</ref>
      <ref url="http://www.securityfocus.com/bid/16693" source="BID">16693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micromuse" name="netcool_neusecure">
        <vers num="3.0.236" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0839" published="2006-02-21" name="CVE-2006-0839" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16705" source="BID">16705</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425290/100/0/threaded" source="BUGTRAQ">20060217 SNORT Incorrect fragmented packet reassembly</ref>
      <ref url="http://secunia.com/advisories/18959" source="SECUNIA">18959</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24811" source="XF">snort-frag3-detection-bypass(24811)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourcefire" name="snort">
        <vers num="2.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0840" published="2006-02-21" name="CVE-2006-0840" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie.  NOTE: this issue might be the same as vector 2 in CVE-2005-4519.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425046/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=386059&amp;group_id=14963" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=386059&amp;group_id=14963</ref>
      <ref url="http://sourceforge.net/project/showfiles.php?group_id=14963&amp;package_id=12175&amp;release_id=386059" source="MISC" patch="1">http://sourceforge.net/project/showfiles.php?group_id=14963&amp;package_id=12175&amp;release_id=386059</ref>
      <ref url="http://morph3us.org/advisories/20060214-mantis-100rc4.txt" source="MISC" patch="1" adv="1">http://morph3us.org/advisories/20060214-mantis-100rc4.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24726" source="XF">mantis-manageuserpagesql-injection(24726)</ref>
      <ref url="http://www.securityfocus.com/bid/16657" source="BID">16657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.11" />
        <vers num="0.11.0" />
        <vers num="0.11.1" />
        <vers num="0.12" />
        <vers num="0.12.0" />
        <vers num="0.13" />
        <vers num="0.13.0" />
        <vers num="0.13.1" />
        <vers num="0.14" />
        <vers num="0.14.0" />
        <vers num="0.14.1" />
        <vers num="0.14.2" />
        <vers num="0.14.3" />
        <vers num="0.14.4" />
        <vers num="0.14.5" />
        <vers num="0.14.6" />
        <vers num="0.14.7" />
        <vers num="0.14.8" />
        <vers num="0.15" />
        <vers num="0.15.0" />
        <vers num="0.15.1" />
        <vers num="0.15.2" />
        <vers num="0.16" />
        <vers num="0.16.0" />
        <vers num="0.17" />
        <vers num="0.17.0" />
        <vers num="0.17.4a" />
        <vers num="0.18" />
        <vers num="0.18.0" />
        <vers num="0.18.0_rc1" />
        <vers num="0.18.0a1" />
        <vers num="0.18.0a2" />
        <vers num="0.18.0a3" />
        <vers num="0.18.0a4" />
        <vers num="0.18.1" />
        <vers num="0.18.2" />
        <vers num="0.18.3" />
        <vers num="0.18a1" />
        <vers num="0.19.0" />
        <vers num="0.19.0_rc1" />
        <vers num="0.19.0a" />
        <vers num="0.19.0a1" />
        <vers num="0.19.0a2" />
        <vers num="0.19.1" />
        <vers num="0.19.2" />
        <vers num="0.19.3" />
        <vers num="0.19.4" />
        <vers num="0.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers prev="1" num="1.0.0_rc4" />
        <vers num="1.0.0a1" />
        <vers num="1.0.0a2" />
        <vers num="1.0.0a3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0841" published="2006-02-21" name="CVE-2006-0841" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php.  NOTE: item 17 might be subsumed by CVE-2005-4522.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425046/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=386059&amp;group_id=14963" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=386059&amp;group_id=14963</ref>
      <ref url="http://morph3us.org/advisories/20060214-mantis-100rc4.txt" source="MISC" patch="1" adv="1">http://morph3us.org/advisories/20060214-mantis-100rc4.txt</ref>
      <ref url="http://www.osvdb.org/23248" source="OSVDB">23248</ref>
      <ref url="http://sourceforge.net/project/showfiles.php?group_id=14963&amp;package_id=12175&amp;release_id=386059" source="MISC">http://sourceforge.net/project/showfiles.php?group_id=14963&amp;package_id=12175&amp;release_id=386059</ref>
      <ref url="http://www.securityfocus.com/bid/16657" source="BID">16657</ref>
      <ref url="http://www.osvdb.org/22487" source="OSVDB">22487</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1133" source="DEBIAN">DSA-1133</ref>
      <ref url="http://secunia.com/advisories/21400" source="SECUNIA">21400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.11" />
        <vers num="0.11.0" />
        <vers num="0.11.1" />
        <vers num="0.12" />
        <vers num="0.12.0" />
        <vers num="0.13" />
        <vers num="0.13.0" />
        <vers num="0.13.1" />
        <vers num="0.14" />
        <vers num="0.14.0" />
        <vers num="0.14.1" />
        <vers num="0.14.2" />
        <vers num="0.14.3" />
        <vers num="0.14.4" />
        <vers num="0.14.5" />
        <vers num="0.14.6" />
        <vers num="0.14.7" />
        <vers num="0.14.8" />
        <vers num="0.15" />
        <vers num="0.15.0" />
        <vers num="0.15.1" />
        <vers num="0.15.2" />
        <vers num="0.16" />
        <vers num="0.16.0" />
        <vers num="0.17" />
        <vers num="0.17.0" />
        <vers num="0.17.4a" />
        <vers num="0.18" />
        <vers num="0.18.0" />
        <vers num="0.18.0_rc1" />
        <vers num="0.18.0a1" />
        <vers num="0.18.0a2" />
        <vers num="0.18.0a3" />
        <vers num="0.18.0a4" />
        <vers num="0.18.1" />
        <vers num="0.18.2" />
        <vers num="0.18.3" />
        <vers num="0.18a1" />
        <vers num="0.19.0" />
        <vers num="0.19.0_rc1" />
        <vers num="0.19.0a" />
        <vers num="0.19.0a1" />
        <vers num="0.19.0a2" />
        <vers num="0.19.1" />
        <vers num="0.19.2" />
        <vers num="0.19.3" />
        <vers num="0.19.4" />
        <vers num="0.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers num="1.0.0_rc4" />
        <vers num="1.0.0a1" />
        <vers num="1.0.0a2" />
        <vers num="1.0.0a3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0842" published="2006-02-21" name="CVE-2006-0842" modified="2011-03-07" discovered="2006-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element in an e-mail message, as demonstrated by "java&amp;#09;script:."  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation of this issue requires a victim user has @Mail configured to display images in email messages.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24742" source="XF">@mail-html-image-xss(24742)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0617" source="VUPEN">ADV-2006-0617</ref>
      <ref url="http://www.securityfocus.com/bid/16683" source="BID">16683</ref>
      <ref url="http://www.osvdb.org/23236" source="OSVDB">23236</ref>
      <ref url="http://secunia.com/advisories/18874" source="SECUNIA" adv="1">18874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calacode" name="atmail_webmail_system">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0843" published="2006-02-21" name="CVE-2006-0843" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16712" source="BID">16712</ref>
      <ref url="http://www.evuln.com/vulns/82/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/82/summary.html</ref>
      <ref url="http://secunia.com/advisories/18923" source="SECUNIA" adv="1">18923</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24752" source="XF">webblog-txt-obtain-information(24752)</ref>
      <ref url="http://securityreason.com/securityalert/522" source="SREASON">522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="web_blog">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0844" published="2006-02-21" name="CVE-2006-0844" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16714" source="BID">16714</ref>
      <ref url="http://www.evuln.com/vulns/82/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/82/summary.html</ref>
      <ref url="http://secunia.com/advisories/18923" source="SECUNIA" adv="1">18923</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24755" source="XF">webblog-cookie-auth-bypass(24755)</ref>
      <ref url="http://securityreason.com/securityalert/522" source="SREASON">522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="web_blog">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0845" published="2006-02-21" name="CVE-2006-0845" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.evuln.com/vulns/82/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/82/summary.html</ref>
      <ref url="http://secunia.com/advisories/18923" source="SECUNIA" adv="1">18923</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24757" source="XF">webblog-sendmail-command-execution(24757)</ref>
      <ref url="http://securityreason.com/securityalert/522" source="SREASON">522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="web_blog">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0846" published="2006-02-21" name="CVE-2006-0846" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the ViewCommentsLog function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16715" source="BID">16715</ref>
      <ref url="http://www.evuln.com/vulns/82/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/82/summary.html</ref>
      <ref url="http://secunia.com/advisories/18923" source="SECUNIA" adv="1">18923</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24758" source="XF">webblog-headers-xss(24758)</ref>
      <ref url="http://securityreason.com/securityalert/522" source="SREASON">522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="web_blog">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0847" published="2006-02-21" name="CVE-2006-0847" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24809" source="XF" patch="1">cherrypy-staticfilter-directory-traversal(24809)</ref>
      <ref url="http://www.securityfocus.com/bid/16760" source="BID" patch="1">16760</ref>
      <ref url="http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306" source="CONFIRM" patch="1">http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0677" source="VUPEN">ADV-2006-0677</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=384316&amp;group_id=56099" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=384316&amp;group_id=56099</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml" source="GENTOO">GLSA-200605-16</ref>
      <ref url="http://www.cherrypy.org/" source="CONFIRM">http://www.cherrypy.org/</ref>
      <ref url="http://secunia.com/advisories/20344" source="SECUNIA">20344</ref>
      <ref url="http://secunia.com/advisories/18944" source="SECUNIA">18944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cherrypy" name="cherrypy">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10_beta" />
        <vers num="0.10_rc1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.8_beta" />
        <vers num="0.9" />
        <vers num="0.9_beta" />
        <vers num="0.9_gamma" />
        <vers num="0.9_rc1" />
        <vers num="2.0.0" />
        <vers num="2.0.0a1" />
        <vers num="2.1.0" />
        <vers num="2.1.0_beta" />
        <vers num="2.1.0_rc1" />
        <vers num="2.1.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0848" published="2006-02-22" name="CVE-2006-0848" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-053A.html" source="CERT" adv="1">TA06-053A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/999708" source="CERT-VN" adv="1">VU#999708</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24808" source="XF">macosx-zip-command-execution(24808)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0671" source="VUPEN" adv="1">ADV-2006-0671</ref>
      <ref url="http://www.securityfocus.com/bid/16736" source="BID">16736</ref>
      <ref url="http://www.osvdb.org/23510" source="OSVDB">23510</ref>
      <ref url="http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html" source="MISC">http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html</ref>
      <ref url="http://www.heise.de/english/newsticker/news/69862" source="MISC">http://www.heise.de/english/newsticker/news/69862</ref>
      <ref url="http://www.frsirt.com/exploits/20060222.safari_safefiles_exec.pm.php" source="MISC" adv="1">http://www.frsirt.com/exploits/20060222.safari_safefiles_exec.pm.php</ref>
      <ref url="http://securitytracker.com/id?1015652" source="SECTRACK">1015652</ref>
      <ref url="http://secunia.com/advisories/18963" source="SECUNIA" adv="1">18963</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0850" published="2006-02-22" name="CVE-2006-0850" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0676" source="VUPEN">ADV-2006-0676</ref>
      <ref url="http://www.ilch.de/news-134.html" source="CONFIRM">http://www.ilch.de/news-134.html</ref>
      <ref url="http://secunia.com/advisories/18951" source="SECUNIA" adv="1">18951</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24830" source="XF">ilchclan-login-sql-injection(24830)</ref>
      <ref url="http://www.osvdb.org/23370" source="OSVDB">23370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ilch.de" name="ilchclan">
        <vers num="0.0.1" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0851" published="2006-02-22" name="CVE-2006-0851" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0672" source="VUPEN">ADV-2006-0672</ref>
      <ref url="http://secunia.com/advisories/18951" source="SECUNIA" adv="1">18951</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24829" source="XF">ilchclan-index-sql-injection(24829)</ref>
      <ref url="http://www.securityfocus.com/bid/16735" source="BID">16735</ref>
      <ref url="http://www.osvdb.org/23369" source="OSVDB">23369</ref>
      <ref url="http://milw0rm.com/exploits/1516" source="MILW0RM">1516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ilch.de" name="ilchclan">
        <vers num="0.0.1" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0852" published="2006-02-22" name="CVE-2006-0852" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-Forwarded-For HTTP header field, which is inserted into content-data.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24771" source="XF">admbook-index-command-execution(24771)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0663" source="VUPEN">ADV-2006-0663</ref>
      <ref url="http://secunia.com/advisories/18930" source="SECUNIA" adv="1">18930</ref>
      <ref url="http://www.securityfocus.com/bid/16753" source="BID">16753</ref>
      <ref url="http://milw0rm.com/exploits/1512" source="MILW0RM">1512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devscripts" name="admbook">
        <vers prev="1" num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0853" published="2006-02-22" name="CVE-2006-0853" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long SEARCH argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24812" source="XF">ia-emailserver-imap-bo(24812)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0686" source="VUPEN">ADV-2006-0686</ref>
      <ref url="http://www.securityfocus.com/bid/16744" source="BID">16744</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425586/100/0/threaded" source="BUGTRAQ" adv="1">20060220 [AJECT] TrueNorth IA eMailserver 5.3.4 buffer overflow vulnerability</ref>
      <ref url="http://www.osvdb.org/23377" source="OSVDB">23377</ref>
      <ref url="http://securitytracker.com/id?1015664" source="SECTRACK">1015664</ref>
      <ref url="http://secunia.com/advisories/18986" source="SECUNIA" adv="1">18986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truenorth_software" name="ia_emailserver">
        <vers num="corporate_5.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0854" published="2006-02-22" name="CVE-2006-0854" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24724" source="XF">iuser-ecommerce-file-include(24724)</ref>
      <ref url="http://www.xorcrew.net/xpa/XPA-iUser.txt" source="MISC">http://www.xorcrew.net/xpa/XPA-iUser.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0699" source="VUPEN" adv="1">ADV-2006-0699</ref>
      <ref url="http://www.securityfocus.com/bid/16787" source="BID">16787</ref>
      <ref url="http://www.osvdb.org/23429" source="OSVDB">23429</ref>
      <ref url="http://secunia.com/advisories/18903" source="SECUNIA" adv="1">18903</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0339.html" source="FULLDISC" adv="1">20060215 iUser Ecommerce - Remote Command Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intensive_point" name="iuser_ecommerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0855" published="2006-02-23" name="CVE-2006-0855" modified="2011-08-01" discovered="2006-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda Spam Firewall, allows user-assisted attackers to execute arbitrary code via a crafted ZOO file that causes the combine function to return a longer string than expected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-05</ref>
      <ref url="http://www.debian.org/security/2006/dsa-991" source="DEBIAN" patch="1" adv="1">DSA-991</ref>
      <ref url="http://securitytracker.com/id?1015866" source="SECTRACK" patch="1">1015866</ref>
      <ref url="http://secunia.com/advisories/19514" source="SECUNIA" patch="1" adv="1">19514</ref>
      <ref url="http://secunia.com/advisories/19166" source="SECUNIA" patch="1" adv="1">19166</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24904" source="XF">zoo-misc-bo(24904)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1220" source="VUPEN" adv="1">ADV-2006-1220</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0705" source="VUPEN" adv="1">ADV-2006-0705</ref>
      <ref url="http://www.securityfocus.com/bid/16790" source="BID">16790</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425887/100/0/threaded" source="BUGTRAQ" adv="1">20060223 zoo contains exploitable buffer overflows</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_06_sr.html" source="SUSE" adv="1">SUSE-SR:2006:006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE" adv="1">SUSE-SR:2006:005</ref>
      <ref url="http://www.guay-leroux.com/projects/zoo-advisory.txt" source="MISC" adv="1">http://www.guay-leroux.com/projects/zoo-advisory.txt</ref>
      <ref url="http://www.guay-leroux.com/projects/barracuda-advisory-ZOO.txt" source="MISC" adv="1">http://www.guay-leroux.com/projects/barracuda-advisory-ZOO.txt</ref>
      <ref url="http://securitytracker.com/id?1015668" source="SECTRACK">1015668</ref>
      <ref url="http://securityreason.com/securityalert/546" source="SREASON">546</ref>
      <ref url="http://secunia.com/advisories/19408" source="SECUNIA" adv="1">19408</ref>
      <ref url="http://secunia.com/advisories/19148" source="SECUNIA" adv="1">19148</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA" adv="1">19130</ref>
      <ref url="http://secunia.com/advisories/19002" source="SECUNIA" adv="1">19002</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0061.html" source="BUGTRAQ" adv="1">20060403 Barracuda ZOO archiver security bug leads to remote compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rahul_dhesi" name="zoo">
        <vers prev="1" num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0856" published="2006-02-23" name="CVE-2006-0856" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Scriptme SmE GB Host 1.21 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the Username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0543" source="VUPEN">ADV-2006-0543</ref>
      <ref url="http://www.securityfocus.com/bid/16609" source="BID">16609</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425317/100/0/threaded" source="BUGTRAQ">20060216 [eVuln] SmE GB Host Authentication Bypass Vulnerability</ref>
      <ref url="http://www.evuln.com/vulns/66/summary.html" source="MISC" adv="1">http://www.evuln.com/vulns/66/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24544" source="XF">smegbhost-login-sql-injection(24544)</ref>
      <ref url="http://secunia.com/advisories/18823" source="SECUNIA">18823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptme" name="sme_gb_host">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0857" published="2006-02-23" name="CVE-2006-0857" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425388/100/0/threaded" source="BUGTRAQ">20060218 e107 CMS 0.7.2 Chatbox plugin XSS vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24815" source="XF">e107-chatbox-xss(24815)</ref>
      <ref url="http://www.securityfocus.com/bid/16719" source="BID">16719</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0858" published="2006-02-23" name="CVE-2006-0858" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe'n'Sec products, might allow local users to gain privileges via a malicious "program" file in the C: folder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16762" source="BID">16762</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425504/100/0/threaded" source="BUGTRAQ">20060219 [TZO-062006] Safe'nVulnerable</ref>
      <ref url="http://secdev.zoller.lu/research/safnsec.htm" source="MISC">http://secdev.zoller.lu/research/safnsec.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="starforce" name="safe_n_sec_personal_+_anti-spyware">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0859" published="2006-02-23" name="CVE-2006-0859" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18946" source="SECUNIA" patch="1" adv="1">18946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24797" source="XF">guestbox-admin-access(24797)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0675" source="VUPEN" adv="1">ADV-2006-0675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426663/100/0/threaded" source="BUGTRAQ">20060302 Re: Guestbox XSS/an admin bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425495/100/0/threaded" source="BUGTRAQ">20060220 Guestbox XSS/an admin bypass</ref>
      <ref url="http://www.osvdb.org/23374" source="OSVDB">23374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_salzer" name="guestbox">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0860" published="2006-02-23" name="CVE-2006-0860" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular expression check, and (2) other unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16751" source="BID" patch="1">16751</ref>
      <ref url="http://secunia.com/advisories/18946" source="SECUNIA" patch="1" adv="1">18946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24798" source="XF">guestbox-gbshow-xss(24798)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0675" source="VUPEN" adv="1">ADV-2006-0675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426663/100/0/threaded" source="BUGTRAQ">20060302 Re: Guestbox XSS/an admin bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425495/100/0/threaded" source="BUGTRAQ">20060220 Guestbox XSS/an admin bypass</ref>
      <ref url="http://www.osvdb.org/23375" source="OSVDB">23375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_salzer" name="guestbox">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0861" published="2006-02-23" name="CVE-2006-0861" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Michael Salzer Guestbox 0.6, and other versoins before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a direct request to /gb/gblog.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23376" source="OSVDB" patch="1">23376</ref>
      <ref url="http://secunia.com/advisories/18946" source="SECUNIA" patch="1" adv="1">18946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24799" source="XF">guestbox-gblog-obtain-information(24799)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0675" source="VUPEN" adv="1">ADV-2006-0675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426663/100/0/threaded" source="BUGTRAQ">20060302 Re: Guestbox XSS/an admin bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425495/100/0/threaded" source="BUGTRAQ">20060220 Guestbox XSS/an admin bypass</ref>
      <ref url="http://securityreason.com/securityalert/460" source="SREASON">460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_salzer" name="guestbox">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0862" published="2006-02-23" name="CVE-2006-0862" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0695" source="VUPEN">ADV-2006-0695</ref>
      <ref url="http://www.securityfocus.com/bid/16776" source="BID">16776</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425779/100/0/threaded" source="BUGTRAQ">20060222 IRM 017: Multiple Vulnerabilities in Infovista Portal SE</ref>
      <ref url="http://www.irmplc.com/advisory017.htm" source="MISC">http://www.irmplc.com/advisory017.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24893" source="XF">vistaportal-parameter-directory-traversal(24893)</ref>
      <ref url="http://securitytracker.com/id?1015669" source="SECTRACK">1015669</ref>
      <ref url="http://secunia.com/advisories/18994" source="SECUNIA">18994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infovista" name="portalse">
        <vers num="2.0_build_20087" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0863" published="2006-02-23" name="CVE-2006-0863" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">InfoVista PortalSE 2.0 Build 20087 on Solaris 8 allows remote attackers to obtain sensitive information by specifying a nonexistent server in the server field, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0695" source="VUPEN">ADV-2006-0695</ref>
      <ref url="http://www.securityfocus.com/bid/16776" source="BID">16776</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425779/100/0/threaded" source="BUGTRAQ" adv="1">20060222 IRM 017: Multiple Vulnerabilities in Infovista Portal SE</ref>
      <ref url="http://www.irmplc.com/advisory017.htm" source="MISC" adv="1">http://www.irmplc.com/advisory017.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24894" source="XF">vistaportal-server-path-disclosure(24894)</ref>
      <ref url="http://securitytracker.com/id?1015669" source="SECTRACK">1015669</ref>
      <ref url="http://securityreason.com/securityalert/473" source="SREASON">473</ref>
      <ref url="http://secunia.com/advisories/18994" source="SECUNIA">18994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infovista" name="portalse">
        <vers num="2.0_build_20087" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0864" published="2006-02-23" name="CVE-2006-0864" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">filescan in Global Hauri ViRobot 2.0 20050817 does not verify the Cookie HTTP header, which allows remote attackers to gain administrative privileges via an arbitrary cookie value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2006-0x82-028-VIROBOT.txt" source="MISC">http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2006-0x82-028-VIROBOT.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0691" source="VUPEN">ADV-2006-0691</ref>
      <ref url="http://www.securityfocus.com/bid/16768" source="BID">16768</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425788/100/0/threaded" source="BUGTRAQ">20060222 [INetCop Security Advisory] Global Hauri Virobot cookie exploit</ref>
      <ref url="http://secunia.com/advisories/18974" source="SECUNIA" adv="1">18974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24850" source="XF">virobot-filescan-auth-bypass(24850)</ref>
      <ref url="http://securitytracker.com/id?1015658" source="SECTRACK">1015658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hauri" name="virobot">
        <vers num="2.0_2005-08-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0865" published="2006-02-23" name="CVE-2006-0865" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425630/100/0/threaded" source="BUGTRAQ">20060219 PunBB 1.2.10 Multiple DoS Vulnerabilities</ref>
      <ref url="http://www.neosecurityteam.net/advisories/Advisory-15.txt" source="MISC">http://www.neosecurityteam.net/advisories/Advisory-15.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24837" source="XF">punbb-register-ip-dos(24837)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0_alpha" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta1a" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0866" published="2006-02-23" name="CVE-2006-0866" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425630/100/0/threaded" source="BUGTRAQ">20060219 PunBB 1.2.10 Multiple DoS Vulnerabilities</ref>
      <ref url="http://www.neosecurityteam.net/advisories/Advisory-15.txt" source="MISC">http://www.neosecurityteam.net/advisories/Advisory-15.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24838" source="XF">punbb-login-bruteforce(24838)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0_alpha" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta1a" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0867" published="2006-02-23" name="CVE-2006-0867" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in certain versions of South River (aka SRT) WebDrive, possibly version 6.08 build 1131 and version 8, allows remote attackers to cause a denial of service (application crash and persistent erratic behavior) via a long string in the name entry field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425785/100/0/threaded" source="BUGTRAQ" adv="1">20060222 South River WebDrive Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24903" source="XF">webdrive-name-bo(24903)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="south_river" name="webdrive">
        <vers num="6.08_build_1131" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0868" published="2006-02-23" name="CVE-2006-0868" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16758" source="BID" patch="1" adv="1">16758</ref>
      <ref url="http://pear.php.net/package/Auth/download/1.3.0r4" source="CONFIRM" patch="1">http://pear.php.net/package/Auth/download/1.3.0r4</ref>
      <ref url="http://pear.php.net/package/Auth/download/1.2.4" source="CONFIRM" patch="1">http://pear.php.net/package/Auth/download/1.2.4</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0696" source="VUPEN">ADV-2006-0696</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425796/100/0/threaded" source="BUGTRAQ" adv="1">20060222 Multiple Injection Vulnerabilities in PHP PEAR::Auth Module</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24854" source="XF">auth-multiple-injections(24854)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-13.xml" source="GENTOO">GLSA-200603-13</ref>
      <ref url="http://securitytracker.com/id?1015666" source="SECTRACK">1015666</ref>
      <ref url="http://secunia.com/advisories/19301" source="SECUNIA">19301</ref>
      <ref url="http://secunia.com/advisories/19008" source="SECUNIA">19008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pear" name="xml_rpc">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.0rc1" />
        <vers num="1.2.0rc2" />
        <vers num="1.2.0rc3" />
        <vers num="1.2.0rc4" />
        <vers num="1.2.0rc5" />
        <vers num="1.2.0rc6" />
        <vers num="1.2.0rc7" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3.0rc1" />
        <vers num="1.3.0rc2" />
        <vers num="1.3.0rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0869" published="2006-02-23" name="CVE-2006-0869" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015659" source="SECTRACK" patch="1">1015659</ref>
      <ref url="http://pear.php.net/package/LiveUser/download/" source="CONFIRM" patch="1">http://pear.php.net/package/LiveUser/download/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24853" source="XF">liveuser-liveuser-file-deletion(24853)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24852" source="XF">liveuser-liveuser-file-access(24852)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0697" source="VUPEN">ADV-2006-0697</ref>
      <ref url="http://www.securityfocus.com/bid/16761" source="BID">16761</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425711/100/0/threaded" source="BUGTRAQ" adv="1">20060221 PEAR LiveUser File Access Vulnerabilities</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00103-02212006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00103-02212006</ref>
      <ref url="http://securityreason.com/securityalert/466" source="SREASON">466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pear" name="pear_liveuser">
        <vers num="0.10.0" />
        <vers num="0.11.0" />
        <vers num="0.11.1" />
        <vers num="0.12.0" />
        <vers num="0.13.0" />
        <vers num="0.13.1" />
        <vers num="0.13.2" />
        <vers num="0.13.3" />
        <vers num="0.14.0" />
        <vers num="0.15.0" />
        <vers num="0.15.1" />
        <vers num="0.16.0" />
        <vers num="0.16.1" />
        <vers num="0.16.2" />
        <vers num="0.16.3" />
        <vers num="0.16.4" />
        <vers num="0.16.5" />
        <vers num="0.16.6" />
        <vers num="0.16.7" />
        <vers num="0.16.8" />
        <vers num="0.3" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0870" published="2006-02-23" name="CVE-2006-0870" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: version 2.3 was later reported to be vulnerable as well.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24803" source="XF">mininuke-pages-sql-injection(24803)</ref>
      <ref url="http://www.securityfocus.com/bid/17636" source="BID">17636</ref>
      <ref url="http://www.securityfocus.com/bid/16730" source="BID">16730</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431602/100/0/threaded" source="BUGTRAQ">20060420 Mini-NUKE v2.3&lt;&lt;--- SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428361/100/0/threaded" source="BUGTRAQ">20060321 Mini-Nuke&lt;=1.8.2 SQL injection (6)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425599/100/0/threaded" source="BUGTRAQ">20060220 MiniNuke CMS System all versions (pages.asp) SQL Injection</ref>
      <ref url="http://www.osvdb.org/23438" source="OSVDB">23438</ref>
      <ref url="http://www.nukedx.com/?viewdoc=9" source="MISC">http://www.nukedx.com/?viewdoc=9</ref>
      <ref url="http://secunia.com/advisories/18439" source="SECUNIA" adv="1">18439</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431714/100/0/threaded" source="BUGTRAQ">20060421 Re: Mini-NUKE v2.3&lt;&lt;--- SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-nuke" name="mini-nuke_cms">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0871" published="2006-02-24" name="CVE-2006-0871" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter.  NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/" source="CONFIRM" patch="1">http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/</ref>
      <ref url="http://secunia.com/advisories/18935" source="SECUNIA" patch="1" adv="1">18935</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0719" source="VUPEN" adv="1">ADV-2006-0719</ref>
      <ref url="http://www.osvdb.org/23505" source="OSVDB">23505</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00104-02242006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00104-02242006</ref>
      <ref url="http://securityreason.com/securityalert/493" source="SREASON">493</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html" source="BUGTRAQ">20060224 Mambo Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers num="4.5.3h" edition="h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0872" published="2006-02-24" name="CVE-2006-0872" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://coppermine-gallery.net/forum/index.php?topic=28062.0" source="CONFIRM" patch="1">http://coppermine-gallery.net/forum/index.php?topic=28062.0</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0669" source="VUPEN">ADV-2006-0669</ref>
      <ref url="http://securitytracker.com/id?1015646" source="SECTRACK">1015646</ref>
      <ref url="http://secunia.com/advisories/18941" source="SECUNIA" adv="1">18941</ref>
      <ref url="http://retrogod.altervista.org/cpg_143_incl_xpl.html" source="MISC">http://retrogod.altervista.org/cpg_143_incl_xpl.html</ref>
      <ref url="http://retrogod.altervista.org/cpg_143_adv.html" source="MISC">http://retrogod.altervista.org/cpg_143_adv.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24814" source="XF">coppermine-init-file-include(24814)</ref>
      <ref url="http://www.securityfocus.com/bid/16718" source="BID">16718</ref>
      <ref url="http://www.securityfocus.com/archive/1/425387" source="BUGTRAQ">20060218 Coppermine Photo Gallery &lt;=1.4.3 remote code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0873" published="2006-02-24" name="CVE-2006-0873" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://coppermine-gallery.net/forum/index.php?topic=28062.0" source="CONFIRM" patch="1">http://coppermine-gallery.net/forum/index.php?topic=28062.0</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0669" source="VUPEN">ADV-2006-0669</ref>
      <ref url="http://securitytracker.com/id?1015646" source="SECTRACK">1015646</ref>
      <ref url="http://secunia.com/advisories/18941" source="SECUNIA" adv="1">18941</ref>
      <ref url="http://retrogod.altervista.org/cpg_143_adv.html" source="MISC">http://retrogod.altervista.org/cpg_143_adv.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24816" source="XF">coppermine-showdoc-file-include(24816)</ref>
      <ref url="http://www.securityfocus.com/bid/16718" source="BID">16718</ref>
      <ref url="http://www.securityfocus.com/archive/1/425387" source="BUGTRAQ">20060218 Coppermine Photo Gallery &lt;=1.4.3 remote code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0874" published="2006-02-24" name="CVE-2006-0874" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes".  NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (from January 8, 2005) is too vague to be sure, and CVE-2006-0854 does not provide version information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16787" source="BID" patch="1">16787</ref>
      <ref url="http://secunia.com/advisories/19003" source="SECUNIA" patch="1" adv="1">19003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24906" source="XF">iuser-ecommerce-undisclosed(24906)</ref>
      <ref url="http://www.intensivepoint.com/iuser-document.shtml" source="CONFIRM">http://www.intensivepoint.com/iuser-document.shtml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intensive_point" name="iuser_ecommerce">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0875" published="2006-02-24" name="CVE-2006-0875" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0694" source="VUPEN">ADV-2006-0694</ref>
      <ref url="http://www.securityfocus.com/bid/16769" source="BID">16769</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425775/100/0/threaded" source="BUGTRAQ" adv="1">20060222 [KAPDA::#27] - Runcms 1.x Cross_Site_Scripting vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015663" source="SECTRACK">1015663</ref>
      <ref url="http://secunia.com/advisories/18997" source="SECUNIA" adv="1">18997</ref>
      <ref url="http://kapda.ir/advisory-267.html" source="MISC" adv="1">http://kapda.ir/advisory-267.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24871" source="XF">runcms-ratefile-xss(24871)</ref>
      <ref url="http://www.osvdb.org/23388" source="OSVDB">23388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.3a" />
        <vers num="1.3a2" />
        <vers num="1.3a5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0876" published="2006-02-24" name="CVE-2006-0876" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18975" source="SECUNIA" patch="1" adv="1">18975</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0698" source="VUPEN">ADV-2006-0698</ref>
      <ref url="http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4" source="CONFIRM">http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4</ref>
      <ref url="http://www.securityfocus.com/bid/16792" source="BID">16792</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1061" source="DEBIAN">DSA-1061</ref>
      <ref url="http://secunia.com/advisories/20205" source="SECUNIA">20205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="popfile" name="popfile">
        <vers num="0.18.3" />
        <vers num="0.19.1" />
        <vers num="0.20.1" />
        <vers num="0.21.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0877" published="2006-02-24" name="CVE-2006-0877" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24831" source="XF">easyforum-join-xss(24831)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0706" source="VUPEN">ADV-2006-0706</ref>
      <ref url="http://secunia.com/advisories/18996" source="SECUNIA" adv="1">18996</ref>
      <ref url="http://evuln.com/vulns/85/summary.html" source="MISC" adv="1">http://evuln.com/vulns/85/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16958" source="BID">16958</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426760/100/0/threaded" source="BUGTRAQ">20060304 [eVuln] Easy Forum XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/23430" source="OSVDB">23430</ref>
      <ref url="http://hot-things.net/forum/show.php?f=2&amp;topic=20060224080919" source="CONFIRM">http://hot-things.net/forum/show.php?f=2&amp;topic=20060224080919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_forum" name="easy_forum">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0878" published="2006-02-24" name="CVE-2006-0878" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0703" source="VUPEN">ADV-2006-0703</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded" source="BUGTRAQ" adv="1">20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities</ref>
      <ref url="http://www.kapda.ir/advisory-268.html" source="MISC" adv="1">http://www.kapda.ir/advisory-268.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24898" source="XF">noahs-category-path-disclosure(24898)</ref>
      <ref url="http://securitytracker.com/id?1015667" source="SECTRACK">1015667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0879" published="2006-02-24" name="CVE-2006-0879" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0703" source="VUPEN">ADV-2006-0703</ref>
      <ref url="http://www.securityfocus.com/bid/16773" source="BID">16773</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded" source="BUGTRAQ" adv="1">20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities</ref>
      <ref url="http://www.kapda.ir/advisory-268.html" source="MISC" adv="1">http://www.kapda.ir/advisory-268.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24896" source="XF">noahs-search-sql-injection(24896)</ref>
      <ref url="http://securitytracker.com/id?1015667" source="SECTRACK">1015667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0880" published="2006-02-24" name="CVE-2006-0880" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0703" source="VUPEN">ADV-2006-0703</ref>
      <ref url="http://www.securityfocus.com/bid/16772" source="BID">16772</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded" source="BUGTRAQ" adv="1">20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities</ref>
      <ref url="http://www.kapda.ir/advisory-268.html" source="MISC" adv="1">http://www.kapda.ir/advisory-268.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24895" source="XF">noahs-indexphp-xss(24895)</ref>
      <ref url="http://securitytracker.com/id?1015667" source="SECTRACK">1015667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0881" published="2006-02-24" name="CVE-2006-0881" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0703" source="VUPEN">ADV-2006-0703</ref>
      <ref url="http://www.securityfocus.com/bid/16780" source="BID">16780</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded" source="BUGTRAQ" adv="1">20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities</ref>
      <ref url="http://www.kapda.ir/advisory-268.html" source="MISC" adv="1">http://www.kapda.ir/advisory-268.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24899" source="XF">noahs-gorumlib-file-include(24899)</ref>
      <ref url="http://securitytracker.com/id?1015667" source="SECTRACK">1015667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0882" published="2006-02-24" name="CVE-2006-0882" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0703" source="VUPEN">ADV-2006-0703</ref>
      <ref url="http://www.securityfocus.com/bid/16778" source="BID">16778</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded" source="BUGTRAQ" adv="1">20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities</ref>
      <ref url="http://www.kapda.ir/advisory-268.html" source="MISC" adv="1">http://www.kapda.ir/advisory-268.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24900" source="XF">noahs-include-directory-traversal(24900)</ref>
      <ref url="http://securitytracker.com/id?1015667" source="SECTRACK">1015667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0883" published="2006-03-06" name="CVE-2006-0883" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16892" source="BID" patch="1">16892</ref>
      <ref url="http://securitytracker.com/id?1015706" source="SECTRACK" patch="1">1015706</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25116" source="XF">openssh-openpam-dos(25116)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0805" source="VUPEN" adv="1">ADV-2006-0805</ref>
      <ref url="http://www.osvdb.org/23797" source="OSVDB">23797</ref>
      <ref url="http://securityreason.com/securityalert/520" source="SREASON">520</ref>
      <ref url="http://bugzilla.mindrot.org/show_bug.cgi?id=839" source="CONFIRM">http://bugzilla.mindrot.org/show_bug.cgi?id=839</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:09.openssh.asc" source="FREEBSD">FreeBSD-SA-06:09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.8.1p1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
        <vers num="5.4" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0884" published="2006-02-24" name="CVE-2006-0884" modified="2011-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16770" source="BID" patch="1">16770</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN" patch="1">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN" patch="1">DSA-1046</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25983" source="XF">mozilla-inline-fwd-code-execution(25983)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN" adv="1">ADV-2006-3749</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425786/100/0/threaded" source="BUGTRAQ">20060222 Mozilla Thunderbird : Remote Code Execution &amp; Denial of Service</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.osvdb.org/23653" source="OSVDB">23653</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-21.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-21.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:052" source="MANDRIVA">MDKSA-2006:052</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015665" source="SECTRACK">1015665</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA" adv="1">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA" adv="1">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA" adv="1">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10782" source="OVAL">oval:org.mitre.oval:def:10782</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2024" source="OVAL" sig="1">oval:org.mitre.oval:def:2024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0885" published="2006-02-25" name="CVE-2006-0885" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0685" source="VUPEN">ADV-2006-0685</ref>
      <ref url="http://www.osvdb.org/23400" source="OSVDB">23400</ref>
      <ref url="http://secunia.com/advisories/18981" source="SECUNIA" adv="1">18981</ref>
      <ref url="http://myimei.com/security/2006-02-20/cutenews141addcommentforprotectedusernamesxss-attack.html" source="MISC">http://myimei.com/security/2006-02-20/cutenews141addcommentforprotectedusernamesxss-attack.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24835" source="XF">cutenews-shownews-xss(24835)</ref>
      <ref url="http://www.securityfocus.com/bid/16740" source="BID">16740</ref>
      <ref url="http://www.securityfocus.com/archive/1/425583" source="BUGTRAQ">20060221 [myimei]CuteNews1.4.1~ Add Comment For Protected UserNames~ XSS Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0886" published="2006-02-25" name="CVE-2006-0886" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the "City/Region" field (mesto variable).  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0723" source="VUPEN">ADV-2006-0723</ref>
      <ref url="http://secunia.com/advisories/18714" source="SECUNIA" adv="1">18714</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24875" source="XF">dev-cityregion-xss(24875)</ref>
      <ref url="http://www.securityfocus.com/bid/16812" source="BID">16812</ref>
      <ref url="http://www.osvdb.org/23468" source="OSVDB">23468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev" name="dev_web_management_system">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0887" published="2006-02-25" name="CVE-2006-0887" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie.  NOTE: this description was significantly updated on 20060605 to reflect new details after an initial vague advisory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=31885&amp;release_id=396091" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=31885&amp;release_id=396091</ref>
      <ref url="http://secunia.com/advisories/16902" source="SECUNIA" patch="1" adv="1">16902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24873" source="XF">phplib-code-execution(24873)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0720" source="VUPEN" adv="1">ADV-2006-0720</ref>
      <ref url="http://www.securityfocus.com/bid/16801" source="BID">16801</ref>
      <ref url="http://www.osvdb.org/23466" source="OSVDB">23466</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00107-03052006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00107-03052006</ref>
      <ref url="http://securitytracker.com/id?1016123" source="SECTRACK">1016123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phplib_team" name="phplib">
        <vers num="7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0888" published="2006-02-25" name="CVE-2006-0888" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16616" source="BID">16616</ref>
      <ref url="http://milw0rm.com/exploits/1489" source="MILW0RM">1489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0889" published="2006-02-25" name="CVE-2006-0889" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0724" source="VUPEN">ADV-2006-0724</ref>
      <ref url="http://secunia.com/advisories/19007" source="SECUNIA" adv="1">19007</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24907" source="XF">calcium-eventtext-xss(24907)</ref>
      <ref url="http://www.securityfocus.com/bid/16851" source="BID">16851</ref>
      <ref url="http://www.osvdb.org/23471" source="OSVDB">23471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brown_bear_software" name="calcium">
        <vers num="3.10.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0890" published="2006-02-25" name="CVE-2006-0890" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0731" source="VUPEN">ADV-2006-0731</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425973/100/0/threaded" source="BUGTRAQ" adv="1">20060224 SpeedCommander 11.0 &amp; ZipStar 5.1 &amp; Squeez 5.1 Directory traversal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24909" source="XF">speedproject-zip-jar-directory-traversal(24909)</ref>
      <ref url="http://www.securityfocus.com/bid/16807" source="BID">16807</ref>
      <ref url="http://www.osvdb.org/23465" source="OSVDB">23465</ref>
      <ref url="http://secunia.com/advisories/19006" source="SECUNIA">19006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="speedproject" name="speedcommander">
        <vers num="11.01_build4450" />
      </prod>
      <prod vendor="speedproject" name="squeez">
        <vers num="5.1" />
      </prod>
      <prod vendor="speedproject" name="zipstar">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0891" published="2006-02-25" name="CVE-2006-0891" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16921" source="SECUNIA" adv="1">16921</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html" source="BUGTRAQ">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24934" source="XF">nocc-index-file-include(24934)</ref>
      <ref url="http://www.securityfocus.com/bid/16793" source="BID">16793</ref>
      <ref url="http://www.osvdb.org/23419" source="OSVDB">23419</ref>
      <ref url="http://www.osvdb.org/23418" source="OSVDB">23418</ref>
      <ref url="http://www.osvdb.org/23417" source="OSVDB">23417</ref>
      <ref url="http://www.osvdb.org/23416" source="OSVDB">23416</ref>
      <ref url="http://securitytracker.com/id?1015671" source="SECTRACK">1015671</ref>
      <ref url="http://retrogod.altervista.org/noccw_10_incl_xpl.html" source="MISC">http://retrogod.altervista.org/noccw_10_incl_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nocc" name="nocc">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0892" published="2006-02-25" name="CVE-2006-0892" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16921" source="SECUNIA" adv="1">16921</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html" source="BUGTRAQ">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16793" source="BID">16793</ref>
      <ref url="http://www.osvdb.org/23420" source="OSVDB">23420</ref>
      <ref url="http://securitytracker.com/id?1015671" source="SECTRACK">1015671</ref>
      <ref url="http://retrogod.altervista.org/noccw_10_incl_xpl.html" source="MISC">http://retrogod.altervista.org/noccw_10_incl_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nocc" name="nocc">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0893" published="2006-02-25" name="CVE-2006-0893" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) the tmp directory, which lists names of uploaded attachments.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16921" source="SECUNIA" adv="1">16921</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html" source="BUGTRAQ">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16793" source="BID">16793</ref>
      <ref url="http://www.osvdb.org/23422" source="OSVDB">23422</ref>
      <ref url="http://www.osvdb.org/23420" source="OSVDB">23420</ref>
      <ref url="http://securitytracker.com/id?1015671" source="SECTRACK">1015671</ref>
      <ref url="http://retrogod.altervista.org/noccw_10_incl_xpl.html" source="MISC">http://retrogod.altervista.org/noccw_10_incl_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nocc" name="nocc">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0894" published="2006-02-25" name="CVE-2006-0894" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION['nocc_theme'] parameter in footer.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16921" source="SECUNIA" adv="1">16921</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html" source="BUGTRAQ">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16793" source="BID">16793</ref>
      <ref url="http://www.osvdb.org/23427" source="OSVDB">23427</ref>
      <ref url="http://www.osvdb.org/23426" source="OSVDB">23426</ref>
      <ref url="http://www.osvdb.org/23425" source="OSVDB">23425</ref>
      <ref url="http://www.osvdb.org/23424" source="OSVDB">23424</ref>
      <ref url="http://www.osvdb.org/23423" source="OSVDB">23423</ref>
      <ref url="http://securitytracker.com/id?1015671" source="SECTRACK">1015671</ref>
      <ref url="http://retrogod.altervista.org/noccw_10_incl_xpl.html" source="MISC">http://retrogod.altervista.org/noccw_10_incl_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nocc" name="nocc">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0895" published="2006-02-25" name="CVE-2006-0895" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/16921" source="SECUNIA" adv="1">16921</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html" source="BUGTRAQ">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/16793" source="BID">16793</ref>
      <ref url="http://securitytracker.com/id?1015671" source="SECTRACK">1015671</ref>
      <ref url="http://securityreason.com/securityalert/478" source="SREASON">478</ref>
      <ref url="http://retrogod.altervista.org/noccw_10_incl_xpl.html" source="MISC">http://retrogod.altervista.org/noccw_10_incl_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nocc" name="nocc">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0896" published="2006-02-25" name="CVE-2006-0896" modified="2011-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24915" source="XF">smf-register-xss(24915)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0726" source="VUPEN" adv="1">ADV-2006-0726</ref>
      <ref url="http://www.simplemachines.org/community/index.php?topic=78841.0" source="CONFIRM">http://www.simplemachines.org/community/index.php?topic=78841.0</ref>
      <ref url="http://www.securityfocus.com/bid/16841" source="BID">16841</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426824/100/0/threaded" source="BUGTRAQ">20060306 [eVuln] Simple Machines Forum - SMF 'X-Forwarded-For' XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/23480" source="OSVDB">23480</ref>
      <ref url="http://securityreason.com/securityalert/545" source="SREASON" adv="1">545</ref>
      <ref url="http://secunia.com/advisories/19004" source="SECUNIA" adv="1">19004</ref>
      <ref url="http://evuln.com/vulns/86/summary.html" source="MISC" adv="1">http://evuln.com/vulns/86/summary.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000682.html" source="VIM">20060410 VEndor ACK: Simple Machines Forum Register.php X-Forwarded-For XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_machines" name="simple_machines_forum">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0897" published="2006-02-25" name="CVE-2006-0897" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the vendor has disputed this issue, saying that "[we] have a behind the scenes complex state management system that uses a combination of keys placed in JavaScript and Session State (server side) that protects against the type of SQL injection you describe.  We have tested for many of the cases and have not found it to be an issue."  Further investigation suggests that the original researcher might have triggered errors using invalid field values, which is not proof of SQL injection; however, the vendor did not receive a response from the original researcher.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24885" source="XF">vpmi-servicerequests-sql-injection(24885)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0725" source="VUPEN" adv="1">ADV-2006-0725</ref>
      <ref url="http://www.securityfocus.com/bid/16798" source="BID">16798</ref>
      <ref url="http://www.osvdb.org/23479" source="OSVDB">23479</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000599.html" source="VIM">20060310 Re: vendor dispute: VCS</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000598.html" source="VIM">20060310 vendor dispute: VCS</ref>
      <ref url="http://secunia.com/advisories/18842" source="SECUNIA" adv="1">18842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_communication_services" name="vpmi_enterprise">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0898" published="2006-02-25" name="CVE-2006-0898" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16802" source="BID" patch="1">16802</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425966/100/0/threaded" source="BUGTRAQ" adv="1">20060223 Vulnerability in Crypt::CBC Perl module, versions &lt;= 2.16</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA">31493</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24954" source="XF">crypt-cbc-header-weak-encryption(24954)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_38_security.html" source="SUSE">SUSE-SR:2006:015</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-15.xml" source="GENTOO">GLSA-200603-15</ref>
      <ref url="http://www.debian.org/security/2006/dsa-996" source="DEBIAN">DSA-996</ref>
      <ref url="http://securityreason.com/securityalert/488" source="SREASON">488</ref>
      <ref url="http://secunia.com/advisories/20899" source="SECUNIA">20899</ref>
      <ref url="http://secunia.com/advisories/19303" source="SECUNIA">19303</ref>
      <ref url="http://secunia.com/advisories/19187" source="SECUNIA">19187</ref>
      <ref url="http://secunia.com/advisories/18755" source="SECUNIA">18755</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lincoln_d._stein" name="crypt_cbc">
        <vers num="1.00" />
        <vers num="1.10" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.24" />
        <vers num="1.25" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="2.04" />
        <vers num="2.05" />
        <vers num="2.07" />
        <vers num="2.08" />
        <vers num="2.09" />
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers prev="1" num="2.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0899" published="2006-02-27" name="CVE-2006-0899" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24938" source="XF">4images-template-file-include(24938)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0754" source="VUPEN">ADV-2006-0754</ref>
      <ref url="http://www.securityfocus.com/bid/16855" source="BID">16855</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426468/100/0/threaded" source="BUGTRAQ">20060301 4images &lt;=1.7.1 remote code execution</ref>
      <ref url="http://www.osvdb.org/23529" source="OSVDB">23529</ref>
      <ref url="http://secunia.com/advisories/19026" source="SECUNIA" adv="1">19026</ref>
      <ref url="http://retrogod.altervista.org/4images_171_adv.html" source="MISC">http://retrogod.altervista.org/4images_171_adv.html</ref>
      <ref url="http://milw0rm.com/exploits/1533" source="MILW0RM">1533</ref>
      <ref url="http://securityreason.com/securityalert/518" source="SREASON">518</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4images" name="image_gallery_management_system">
        <vers prev="1" num="1.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0900" published="2006-02-27" name="CVE-2006-0900" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19017" source="SECUNIA" adv="1">19017</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002982.html" source="MLIST">[Dailydave] 20060226 fun with FreeBSD kernel</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24918" source="XF">freebsd-nfsd-kernel-dos(24918)</ref>
      <ref url="http://www.securityfocus.com/bid/16838" source="BID">16838</ref>
      <ref url="http://www.osvdb.org/23511" source="OSVDB">23511</ref>
      <ref url="http://securityreason.com/securityalert/521" source="SREASON">521</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:10.nfs.asc" source="FREEBSD">FreeBSD-SA-06:10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0901" published="2006-02-27" name="CVE-2006-0901" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16826" source="BID" patch="1">16826</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102161-1" source="SUNALERT" patch="1" adv="1">102161</ref>
      <ref url="http://secunia.com/advisories/19042" source="SECUNIA" patch="1" adv="1">19042</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0756" source="VUPEN">ADV-2006-0756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24911" source="XF">solaris-hsfs-privilege-elevation(24911)</ref>
      <ref url="http://securitytracker.com/id?1015680" source="SECTRACK">1015680</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1628" source="OVAL" sig="1">oval:org.mitre.oval:def:1628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="10.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0903" published="2006-02-27" name="CVE-2006-0903" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0752" source="VUPEN">ADV-2006-0752</ref>
      <ref url="http://www.securityfocus.com/bid/16850" source="BID">16850</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0364.html" source="REDHAT">RHSA-2008:0364</ref>
      <ref url="http://securitytracker.com/id?1015693" source="SECTRACK">1015693</ref>
      <ref url="http://secunia.com/advisories/30351" source="SECUNIA">30351</ref>
      <ref url="http://secunia.com/advisories/19034" source="SECUNIA" adv="1">19034</ref>
      <ref url="http://rst.void.ru/papers/advisory39.txt" source="MISC">http://rst.void.ru/papers/advisory39.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9915" source="OVAL">oval:org.mitre.oval:def:9915</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24966" source="XF">mysql-query-log-bypass-security(24966)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-274-1" source="UBUNTU">USN-274-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-274-2" source="UBUNTU">USN-274-2</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0083.html" source="REDHAT">RHSA-2007:0083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0544.html" source="REDHAT">RHSA-2006:0544</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:064" source="MANDRIVA">MDKSA-2006:064</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1079" source="DEBIAN">DSA-1079</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1073" source="DEBIAN">DSA-1073</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1071" source="DEBIAN">DSA-1071</ref>
      <ref url="http://secunia.com/advisories/20625" source="SECUNIA">20625</ref>
      <ref url="http://secunia.com/advisories/20333" source="SECUNIA">20333</ref>
      <ref url="http://secunia.com/advisories/20253" source="SECUNIA">20253</ref>
      <ref url="http://secunia.com/advisories/20241" source="SECUNIA">20241</ref>
      <ref url="http://secunia.com/advisories/19814" source="SECUNIA">19814</ref>
      <ref url="http://secunia.com/advisories/19502" source="SECUNIA">19502</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=17667" source="CONFIRM">http://bugs.mysql.com/bug.php?id=17667</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0653.html" source="FULLDISC">20060225 mysql &lt;= 5.0.18</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23" />
        <vers num="3.23.0" edition="alpha" />
        <vers num="3.23.1" />
        <vers num="3.23.10" />
        <vers num="3.23.11" />
        <vers num="3.23.12" />
        <vers num="3.23.13" />
        <vers num="3.23.14" />
        <vers num="3.23.15" />
        <vers num="3.23.16" />
        <vers num="3.23.17" />
        <vers num="3.23.18" />
        <vers num="3.23.19" />
        <vers num="3.23.2" />
        <vers num="3.23.20" edition="beta" />
        <vers num="3.23.21" />
        <vers num="3.23.22" />
        <vers num="3.23.23" />
        <vers num="3.23.24" />
        <vers num="3.23.25" />
        <vers num="3.23.26" />
        <vers num="3.23.27" />
        <vers num="3.23.28" edition="gamma" />
        <vers num="3.23.29" />
        <vers num="3.23.3" />
        <vers num="3.23.30" />
        <vers num="3.23.31" />
        <vers num="3.23.32" />
        <vers num="3.23.33" />
        <vers num="3.23.34" />
        <vers num="3.23.35" />
        <vers num="3.23.36" />
        <vers num="3.23.37" />
        <vers num="3.23.38" />
        <vers num="3.23.39" />
        <vers num="3.23.4" />
        <vers num="3.23.40" />
        <vers num="3.23.41" />
        <vers num="3.23.42" />
        <vers num="3.23.43" />
        <vers num="3.23.44" />
        <vers num="3.23.45" />
        <vers num="3.23.46" />
        <vers num="3.23.47" />
        <vers num="3.23.48" />
        <vers num="3.23.49" />
        <vers num="3.23.5" />
        <vers num="3.23.50" />
        <vers num="3.23.51" />
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.54" />
        <vers num="3.23.55" />
        <vers num="3.23.56" />
        <vers num="3.23.57" />
        <vers num="3.23.58" />
        <vers num="3.23.59" />
        <vers num="3.23.6" />
        <vers num="3.23.7" />
        <vers num="3.23.8" />
        <vers num="3.23.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.16" />
        <vers num="4.0.17" />
        <vers num="4.0.18" />
        <vers num="4.0.19" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.23" />
        <vers num="4.0.24" />
        <vers num="4.0.25" />
        <vers num="4.0.26" />
        <vers num="4.0.27" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.10" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.19" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.2" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0905" published="2006-03-23" name="CVE-2006-0905" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17191" source="BID" patch="1">17191</ref>
      <ref url="http://secunia.com/advisories/19366" source="SECUNIA" patch="1" adv="1">19366</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:11.ipsec.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-06:11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25398" source="XF">bsd-ipsec-replay(25398)</ref>
      <ref url="http://www.osvdb.org/24068" source="OSVDB">24068</ref>
      <ref url="http://securitytracker.com/id?1015809" source="SECTRACK">1015809</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-011.txt.asc" source="NETBSD">NetBSD-SA2006-011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p7" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
        <vers num="5.4" edition="stable" />
        <vers num="6.0" edition="release" />
        <vers num="6.0" edition="stable" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0906" published="2006-02-27" name="CVE-2006-0906" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0757" source="VUPEN">ADV-2006-0757</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426197/100/0/threaded" source="BUGTRAQ">20060226 2 SQL Injection in d3jeeb</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24941" source="XF">d3jeeb-catid-sql-injection(24941)</ref>
      <ref url="http://www.securityfocus.com/bid/16853" source="BID">16853</ref>
      <ref url="http://securitytracker.com/id?1015687" source="SECTRACK">1015687</ref>
      <ref url="http://secunia.com/advisories/19062" source="SECUNIA">19062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="top_line" name="d3jeeb_pro">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0907" published="2006-02-27" name="CVE-2006-0907" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/advisory-47.html" source="MISC" adv="1">http://www.waraxe.us/advisory-47.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426083/100/0/threaded" source="BUGTRAQ" adv="1">20060225 [waraxe-2006-SA#047] - Evading sql-injection filters in phpNuke 7.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0908" published="2006-02-27" name="CVE-2006-0908" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/advisory-47.html" source="MISC" adv="1">http://www.waraxe.us/advisory-47.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426083/100/0/threaded" source="BUGTRAQ" adv="1">20060225 [waraxe-2006-SA#047] - Evading sql-injection filters in phpNuke 7.8</ref>
      <ref url="http://securityreason.com/securityalert/497" source="SREASON">497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.8_patched_3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0909" published="2006-02-28" name="CVE-2006-0909" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory; (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subsm_queries.php in the sources/sql directory; (11) sources/acp_loaders/acp_pages_components.php; (12) sources/action_admin/member.php and (13) sources/action_admin/paysubscriptions.php; (14) login.php, (15) messenger.php, (16) moderate.php, (17) paysubscriptions.php, (18) register.php, (19) search.php, (20) topics.php, (21) and usercp.php in the sources/action_public directory; (22) bbcode/class_bbcode.php, (23) bbcode/class_bbcode_legacy.php, (24) editor/class_editor_rte.php, (25) editor/class_editor_std.php, (26) post/class_post.php, (27) post/class_post_edit.php, (28) post/class_post_new.php, (29) and post/class_post_reply.php in the sources/classes directory; (30) sources/components_acp/registration_DEPR.php; (31) sources/handlers/han_paysubscriptions.php; (32) func_usercp.php; (33) search_mysql_ftext.php, and (34) search_mysql_man.php in the sources/lib/ directory; and (35) convert/auth.php.bak, (36) external/auth.php, and (37) ldap/auth.php in the sources/loginauth directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24840" source="XF">invisionpowerboard-multiple-info-disclosure(24840)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425713/100/0/threaded" source="BUGTRAQ" adv="1">20060221 Invision Power Board 2.1.4 Multiple Vulnerabilities</ref>
      <ref url="http://neosecurityteam.net/index.php?action=advisories&amp;id=16" source="MISC" adv="1">http://neosecurityteam.net/index.php?action=advisories&amp;id=16</ref>
      <ref url="http://neosecurityteam.net/advisories/Advisory-16.txt" source="MISC" adv="1">http://neosecurityteam.net/advisories/Advisory-16.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466275/100/0/threaded" source="BUGTRAQ">20070419 IPB (Invision Power Board) Full Path Disclusure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1_beta2" />
        <vers num="2.1_beta3" />
        <vers num="2.1_beta4" />
        <vers num="2.1_beta5" />
        <vers num="2.1_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0910" published="2006-02-28" name="CVE-2006-0910" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24840" source="XF">invisionpowerboard-multiple-info-disclosure(24840)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425713/100/0/threaded" source="BUGTRAQ" adv="1">20060221 Invision Power Board 2.1.4 Multiple Vulnerabilities</ref>
      <ref url="http://neosecurityteam.net/index.php?action=advisories&amp;id=16" source="MISC" adv="1">http://neosecurityteam.net/index.php?action=advisories&amp;id=16</ref>
      <ref url="http://neosecurityteam.net/advisories/Advisory-16.txt" source="MISC" adv="1">http://neosecurityteam.net/advisories/Advisory-16.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1_beta2" />
        <vers num="2.1_beta3" />
        <vers num="2.1_beta4" />
        <vers num="2.1_beta5" />
        <vers num="2.1_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0911" published="2006-02-28" name="CVE-2006-0911" modified="2011-08-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&amp;btnLogIn=[Log&amp;In]=&amp;" or "&amp;b;tnLogIn=[Log&amp;In]=&amp;" in the URL.  NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/ipswitch_dos.txt" source="MISC" adv="1">http://zur.homelinux.com/Advisories/ipswitch_dos.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24864" source="XF">whatsup-nmservice-dos(24864)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0704" source="VUPEN" adv="1">ADV-2006-0704</ref>
      <ref url="http://www.securityfocus.com/bid/16771" source="BID">16771</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425780/100/0/threaded" source="BUGTRAQ" adv="1">20060222 IpSwitch WhatsUp Professional 2006 DoS</ref>
      <ref url="http://www.osvdb.org/23494" source="OSVDB">23494</ref>
      <ref url="http://securityreason.com/securityalert/472" source="SREASON">472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="whatsup">
        <vers num="professional_2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0912" published="2006-02-28" name="CVE-2006-0912" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a "certain RTP sequence."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0812" source="VUPEN">ADV-2006-0812</ref>
      <ref url="http://www.osvdb.org/23300" source="OSVDB">23300</ref>
      <ref url="http://oreka.sourceforge.net/" source="CONFIRM">http://oreka.sourceforge.net/</ref>
      <ref url="http://www.securityfocus.com/bid/16937" source="BID">16937</ref>
      <ref url="http://secunia.com/advisories/19095" source="SECUNIA">19095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreka" name="oreka">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0913" published="2006-02-28" name="CVE-2006-0913" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=312498" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=312498</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24819" source="XF" adv="1">bugzilla-editparams-sql-injection(24819)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0692" source="VUPEN">ADV-2006-0692</ref>
      <ref url="http://www.securityfocus.com/bid/16738" source="BID" adv="1">16738</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425584/100/0/threaded" source="BUGTRAQ" adv="1">20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4</ref>
      <ref url="http://secunia.com/advisories/18979" source="SECUNIA" adv="1">18979</ref>
      <ref url="http://www.osvdb.org/23378" source="OSVDB">23378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.18.2" />
        <vers num="2.18.3" />
        <vers num="2.18.4" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
        <vers num="2.21" />
        <vers num="2.21.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0914" published="2006-02-28" name="CVE-2006-0914" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=312498" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=312498</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42802" source="XF">bugzilla-duplicates-sql-injection(42802)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0692" source="VUPEN">ADV-2006-0692</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425584/100/0/threaded" source="BUGTRAQ" adv="1">20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.16.10" />
        <vers num="2.17" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18.1" />
        <vers num="2.18.2" />
        <vers num="2.18.3" />
        <vers num="2.18.4" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0915" published="2006-02-28" name="CVE-2006-0915" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=313441" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=313441</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0692" source="VUPEN">ADV-2006-0692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.16.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0916" published="2006-02-28" name="CVE-2006-0916" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=325079" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=325079</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24821" source="XF" adv="1">bugzilla-login-data-redirection(24821)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0692" source="VUPEN">ADV-2006-0692</ref>
      <ref url="http://www.securityfocus.com/bid/16745" source="BID" adv="1">16745</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425584/100/0/threaded" source="BUGTRAQ" adv="1">20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4</ref>
      <ref url="http://secunia.com/advisories/18979" source="SECUNIA" adv="1">18979</ref>
      <ref url="http://securityreason.com/securityalert/464" source="SREASON">464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.19.3" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
        <vers num="2.21" />
        <vers num="2.21.1" />
        <vers num="2.21.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0917" published="2006-02-28" name="CVE-2006-0917" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24868" source="XF">melange-chat-command-information-disclosure(24868)</ref>
      <ref url="http://www.securityfocus.com/bid/16747" source="BID">16747</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425589/100/0/threaded" source="BUGTRAQ">20060221 grab cookie information with Melange Chat Server 1.10</ref>
      <ref url="http://www.oh2600.com/forum/viewtopic.php?t=43" source="MISC">http://www.oh2600.com/forum/viewtopic.php?t=43</ref>
      <ref url="http://secunia.com/advisories/18984" source="SECUNIA" adv="1">18984</ref>
      <ref url="http://securityreason.com/securityalert/463" source="SREASON">463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="melange" name="melange_chat_system">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0918" published="2006-02-28" name="CVE-2006-0918" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18989" source="SECUNIA" patch="1" adv="1">18989</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0717" source="VUPEN">ADV-2006-0717</ref>
      <ref url="http://www.securityfocus.com/bid/16797" source="BID">16797</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425936/100/0/threaded" source="BUGTRAQ">20060223 NSA Group Security Advisory NSAG-&amp;sup1;198-23.02.2006 Vulnerability The Bat v. 3.60.07</ref>
      <ref url="http://www.nsag.ru/vuln/953.html" source="MISC">http://www.nsag.ru/vuln/953.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24882" source="XF">thebat-subject-bo(24882)</ref>
      <ref url="http://securityreason.com/securityalert/485" source="SREASON">485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ritlabs" name="the_bat">
        <vers num="3.60.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0919" published="2006-02-28" name="CVE-2006-0919" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0718" source="VUPEN">ADV-2006-0718</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425924/100/0/threaded" source="BUGTRAQ" adv="1">20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt</ref>
      <ref url="http://www.osvdb.org/23462" source="OSVDB">23462</ref>
      <ref url="http://secunia.com/advisories/18993" source="SECUNIA">18993</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oi" name="email_marketing_system">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0920" published="2006-02-28" name="CVE-2006-0920" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425924/100/0/threaded" source="BUGTRAQ" adv="1">20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16794" source="BID">16794</ref>
      <ref url="http://securityreason.com/securityalert/483" source="SREASON">483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oi" name="email_marketing_system">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0921" published="2006-02-28" name="CVE-2006-0921" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425937/100/0/threaded" source="BUGTRAQ" adv="1">20060223 NSA Group Security Advisory NSAG-&amp;sup1;195-23.02.2006 Vulnerability FCKeditor 2.0 FC</ref>
      <ref url="http://www.nsag.ru/vuln/952.html" source="MISC">http://www.nsag.ru/vuln/952.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24878" source="XF">fckeditor-connector-obtain-information(24878)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434559/30/4890/threaded" source="BUGTRAQ">20060519 Re: NSA Group Security Advisory NSAG-&amp;sup1;195-23.02.2006 Vulnerability FCKeditor 2.0 FC</ref>
      <ref url="http://securityreason.com/securityalert/484" source="SREASON">484</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fckeditor" name="fckeditor">
        <vers num="2.0_fc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0922" published="2006-02-28" name="CVE-2006-0922" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=14972" source="MISC" patch="1">http://www.cubecart.com/site/forums/index.php?showtopic=14972</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=14825" source="MISC" patch="1">http://www.cubecart.com/site/forums/index.php?showtopic=14825</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24883" source="XF">cubecart-connector-file-include(24883)</ref>
      <ref url="http://www.securityfocus.com/bid/16796" source="BID">16796</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425931/100/0/threaded" source="BUGTRAQ" adv="1">20060223 NSA Group Security Advisory NSAG-&amp;sup1;197-23.02.2006 Vulnerability CubeCart 3.0.0 ? 3.0.6</ref>
      <ref url="http://www.nsag.ru/vuln/892.html" source="MISC">http://www.nsag.ru/vuln/892.html</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=14960" source="MISC">http://www.cubecart.com/site/forums/index.php?showtopic=14960</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=14817" source="MISC">http://www.cubecart.com/site/forums/index.php?showtopic=14817</ref>
      <ref url="http://www.cubecart.com/site/forums/index.php?showtopic=14704" source="CONFIRM">http://www.cubecart.com/site/forums/index.php?showtopic=14704</ref>
      <ref url="http://securityreason.com/securityalert/482" source="SREASON">482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="3.0.0_alpha" />
        <vers num="3.0.0_alpha-2" />
        <vers num="3.0.0_alpha-rgf" />
        <vers num="3.0.0_beta" />
        <vers num="3.0.0_final" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0923" published="2006-02-28" name="CVE-2006-0923" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0750" source="VUPEN">ADV-2006-0750</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425983/100/0/threaded" source="BUGTRAQ" adv="1">20060224 Advisory: MyPHPNuke &lt;= 1.8.8 multiple XSS vulnerabilities</ref>
      <ref url="http://www.nukedx.com/?viewdoc=12" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24887" source="XF">myphpnuke-reviews-download-xss(24887)</ref>
      <ref url="http://www.securityfocus.com/bid/16815" source="BID">16815</ref>
      <ref url="http://www.myphpnuke.com/article.php?sid=1035&amp;mode=thread&amp;order=0" source="CONFIRM">http://www.myphpnuke.com/article.php?sid=1035&amp;mode=thread&amp;order=0</ref>
      <ref url="http://securityreason.com/securityalert/491" source="SREASON">491</ref>
      <ref url="http://secunia.com/advisories/19052" source="SECUNIA">19052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpnuke" name="myphpnuke">
        <vers prev="1" num="1.8.8" />
        <vers num="1.8.8_7" />
        <vers num="1.8.8_8_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0924" published="2006-02-28" name="CVE-2006-0924" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Brown Bear iCal version 3.10 and previous.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0727" source="VUPEN">ADV-2006-0727</ref>
      <ref url="http://www.securityfocus.com/bid/16845" source="BID">16845</ref>
      <ref url="http://www.osvdb.org/23472" source="OSVDB">23472</ref>
      <ref url="http://secunia.com/advisories/19001" source="SECUNIA" adv="1">19001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24919" source="XF">ical-calendartext-xss(24919)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brown_bear_software" name="ical">
        <vers num="3.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0925" published="2006-02-28" name="CVE-2006-0925" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0729" source="VUPEN">ADV-2006-0729</ref>
      <ref url="http://www.nsag.ru/vuln/888.html" source="MISC">http://www.nsag.ru/vuln/888.html</ref>
      <ref url="http://secunia.com/advisories/18921" source="SECUNIA" adv="1">18921</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24916" source="XF">mdaemon-imap-foldername-dos(24916)</ref>
      <ref url="http://www.securityfocus.com/bid/16854" source="BID">16854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="8.1.1" />
        <vers num="8.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0926" published="2006-02-28" name="CVE-2006-0926" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0732" source="VUPEN">ADV-2006-0732</ref>
      <ref url="http://www.securityfocus.com/bid/16806" source="BID">16806</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425972/100/0/threaded" source="BUGTRAQ">20060224 StuffIt and ZipMagic Family of products Directory traversal</ref>
      <ref url="http://www.hamid.ir/security/stuffit.txt" source="MISC">http://www.hamid.ir/security/stuffit.txt</ref>
      <ref url="http://secunia.com/advisories/19010" source="SECUNIA" adv="1">19010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24886" source="XF">stuffit-zipmagic-archive-directory-traversal(24886)</ref>
      <ref url="http://www.osvdb.org/23463" source="OSVDB">23463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smithmicro" name="stuffit_deluxe">
        <vers num="9.0" />
      </prod>
      <prod vendor="smithmicro" name="stuffit_expander">
        <vers num="9.0.0.21_engine_9.0.0.21" />
      </prod>
      <prod vendor="smithmicro" name="stuffit_standard">
        <vers num="9.0" />
      </prod>
      <prod vendor="smithmicro" name="zipmagic_deluxe">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0927" published="2006-02-28" name="CVE-2006-0927" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Vulnerability affects JGS-XA, JGS-Gallery Addon versions 4.0.0 and previous.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16810" source="BID" adv="1">16810</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425981/100/0/threaded" source="BUGTRAQ" adv="1">20060224 Advisory: Woltlab Burning Board 2.x (JGS-Gallery MOD &lt;= 4.0)multiple XSS vulnerabilities</ref>
      <ref url="http://www.nukedx.com/?viewdoc=11" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24888" source="XF">wbb-jgsgallerymod-xss(24888)</ref>
      <ref url="http://www.securityfocus.com/bid/16843" source="BID">16843</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0615.html" source="FULLDISC">20060224 Advisory: Woltlab Burning Board 2.x (JGS-Gallery MOD &lt;= 4.0) multiple XSS vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgs-xa" name="jgs-gallery_addon">
        <vers num="4.0" />
      </prod>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.0" />
        <vers num="2.0.3" />
        <vers num="2.1.5" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0928" published="2006-02-28" name="CVE-2006-0928" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0733" source="VUPEN">ADV-2006-0733</ref>
      <ref url="http://www.securityfocus.com/bid/16808" source="BID">16808</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425968/100/0/threaded" source="BUGTRAQ" adv="1">20060224 NSA Group Security Advisory NSAG-&amp;sup1;198-23.02.2006 Vulnerability ArGoSoft Mail Server Pro</ref>
      <ref url="http://www.nsag.ru/vuln/879.html" source="MISC">http://www.nsag.ru/vuln/879.html</ref>
      <ref url="http://secunia.com/advisories/18990" source="SECUNIA" adv="1">18990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8" edition="" />
        <vers num="1.8" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0929" published="2006-02-28" name="CVE-2006-0929" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. (dot dot) in the RENAME command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0733" source="VUPEN">ADV-2006-0733</ref>
      <ref url="http://www.securityfocus.com/bid/16809" source="BID">16809</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425969/100/0/threaded" source="BUGTRAQ" adv="1">20060224 NSA Group Security Advisory NSAG-&amp;sup1;200-24.02.2006 Vulnerability ArGoSoft Mail Server Pro IMAP</ref>
      <ref url="http://www.nsag.ru/vuln/878.html" source="MISC">http://www.nsag.ru/vuln/878.html</ref>
      <ref url="http://secunia.com/advisories/18990" source="SECUNIA" adv="1">18990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.8.1" edition="" />
        <vers num="1.8.8.1" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0930" published="2006-02-28" name="CVE-2006-0930" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0733" source="VUPEN">ADV-2006-0733</ref>
      <ref url="http://www.nsag.ru/vuln/877.html" source="MISC">http://www.nsag.ru/vuln/877.html</ref>
      <ref url="http://secunia.com/advisories/18990" source="SECUNIA" adv="1">18990</ref>
      <ref url="http://securityreason.com/securityalert/487" source="SREASON">487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8" edition="" />
        <vers num="1.8" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0931" published="2006-02-28" name="CVE-2006-0931" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0728" source="VUPEN">ADV-2006-0728</ref>
      <ref url="http://www.securityfocus.com/bid/16805" source="BID">16805</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425967/100/0/threaded" source="BUGTRAQ" adv="1">20060224 Archive_Tar v 1.2(Tested) (Tar file management class) Directory traversal</ref>
      <ref url="http://www.osvdb.org/23481" source="OSVDB">23481</ref>
      <ref url="http://www.hamid.ir/security/phptar.txt" source="MISC" adv="1">http://www.hamid.ir/security/phptar.txt</ref>
      <ref url="http://secunia.com/advisories/19011" source="SECUNIA" adv="1">19011</ref>
      <ref url="http://pear.php.net/package/Archive_Tar/download/" source="CONFIRM">http://pear.php.net/package/Archive_Tar/download/</ref>
      <ref url="http://pear.php.net/bugs/bug.php?id=6933" source="CONFIRM">http://pear.php.net/bugs/bug.php?id=6933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pear" name="pear_archive_tar">
        <vers prev="1" num="1.2" />
        <vers prev="1" num="1.3.0" />
        <vers prev="1" num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0932" published="2006-02-28" name="CVE-2006-0932" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425967/100/0/threaded" source="BUGTRAQ" adv="1">20060224 Archive_Tar v 1.2(Tested) (Tar file management class) Directory traversal</ref>
      <ref url="http://www.hamid.ir/security/phpzip.txt" source="MISC" adv="1">http://www.hamid.ir/security/phpzip.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24972" source="XF">ziplib-directory-traversal(24972)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426153/100/0/threaded" source="BUGTRAQ">20060225 Archive_Zip (Zip file management class) Directory traversal</ref>
      <ref url="http://securityreason.com/securityalert/486" source="SREASON">486</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pear" name="pear_archive_zip">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0933" published="2006-02-28" name="CVE-2006-0933" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24874" source="XF">phpx-xcode-tag-xss(24874)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0722" source="VUPEN">ADV-2006-0722</ref>
      <ref url="http://www.securityfocus.com/bid/16799" source="BID">16799</ref>
      <ref url="http://secunia.com/advisories/18688" source="SECUNIA" adv="1">18688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers num="3.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0934" published="2006-02-28" name="CVE-2006-0934" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24877" source="XF" adv="1">webinsta-limbo-contact-form-xss(24877)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0721" source="VUPEN">ADV-2006-0721</ref>
      <ref url="http://www.securityfocus.com/bid/16811" source="BID">16811</ref>
      <ref url="http://www.osvdb.org/23469" source="OSVDB">23469</ref>
      <ref url="http://secunia.com/advisories/18723" source="SECUNIA" adv="1">18723</ref>
      <ref url="http://osvdb.org/ref/23/23469-limbo.txt" source="MISC">http://osvdb.org/ref/23/23469-limbo.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limbo_cms" name="limbo_cms">
        <vers num="1.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0935" published="2006-02-28" name="CVE-2006-0935" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16782" source="BID">16782</ref>
      <ref url="http://archives.neohapsis.com/archives/dailydave/2006-q1/0179.html" source="MLIST">[Dailydave] 20060221 word dos 4fun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0936" published="2006-02-28" name="CVE-2006-0936" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19014" source="SECUNIA" adv="1">19014</ref>
      <ref url="http://nsag.ru/vuln/894.html" source="MISC">http://nsag.ru/vuln/894.html</ref>
      <ref url="http://www.securityfocus.com/bid/16823" source="BID">16823</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426077/100/0/threaded" source="BUGTRAQ">20060225 NSA Group Security Advisory NSAG-&amp;sup1;202-25.02.2006 Vulnerability WEBSITE GENERATOR 3.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_host_shop" name="website_generator">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0937" published="2006-02-28" name="CVE-2006-0937" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18998" source="SECUNIA" adv="1">18998</ref>
      <ref url="http://nsag.ru/vuln/890.html" source="MISC">http://nsag.ru/vuln/890.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24890" source="XF">mailgust-index-info-disclosure(24890)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unu_networks" name="mailgust">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0938" published="2006-02-28" name="CVE-2006-0938" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16817" source="BID">16817</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426076/100/0/threaded" source="BUGTRAQ">20060225 Advisory: eZ publish &lt;= 3.7.3 (imagecatalogue module) XSSvulnerability</ref>
      <ref url="http://www.nukedx.com/?viewdoc=16" source="MISC">http://www.nukedx.com/?viewdoc=16</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24956" source="XF">ezpublish-referrerurl-xss(24956)</ref>
      <ref url="http://securitytracker.com/id?1015683" source="SECTRACK">1015683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ez_systems" name="ez_publish">
        <vers num="3.4.8" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.8" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.5" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0939" published="2006-02-28" name="CVE-2006-0939" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16828" source="BID">16828</ref>
      <ref url="http://www.securityfocus.com/archive/1/426082" source="BUGTRAQ">20060225 SQL Injection in DCI-Taskeen</ref>
      <ref url="http://securitytracker.com/id?1015685" source="SECTRACK">1015685</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24963" source="XF">dci-taskeen-multiple-scripts-sql-injection(24963)</ref>
      <ref url="http://securityreason.com/securityalert/495" source="SREASON">495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dci-designs" name="dci-taskeen">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0940" published="2006-02-28" name="CVE-2006-0940" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0755" source="VUPEN">ADV-2006-0755</ref>
      <ref url="http://www.osvdb.org/23482" source="OSVDB">23482</ref>
      <ref url="http://secunia.com/advisories/19047" source="SECUNIA" adv="1">19047</ref>
      <ref url="http://evuln.com/vulns/87/summary.html" source="MISC" adv="1">http://evuln.com/vulns/87/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24897" source="XF">shoutlive-savesettings-file-include(24897)</ref>
      <ref url="http://www.securityfocus.com/bid/16857" source="BID">16857</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426985/100/0/threaded" source="BUGTRAQ">20060307 [eVuln] ShoutLIVE PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/557" source="SREASON">557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cynical_games" name="shoutlive">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0941" published="2006-02-28" name="CVE-2006-0941" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0755" source="VUPEN">ADV-2006-0755</ref>
      <ref url="http://www.osvdb.org/23483" source="OSVDB">23483</ref>
      <ref url="http://secunia.com/advisories/19047" source="SECUNIA" adv="1">19047</ref>
      <ref url="http://evuln.com/vulns/87/summary.html" source="MISC" adv="1">http://evuln.com/vulns/87/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24901" source="XF">shoutlive-post-xss(24901)</ref>
      <ref url="http://www.securityfocus.com/bid/16857" source="BID">16857</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426985/100/0/threaded" source="BUGTRAQ">20060307 [eVuln] ShoutLIVE PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/557" source="SREASON">557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cynical_games" name="shoutlive">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0942" published="2006-02-28" name="CVE-2006-0942" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16567" source="BID">16567</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/PwsPHP_SQL_Inj.php" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/PwsPHP_SQL_Inj.php</ref>
      <ref url="http://www.osvdb.org/28444" source="OSVDB">28444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers prev="1" num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0943" published="2006-02-28" name="CVE-2006-0943" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0748" source="VUPEN">ADV-2006-0748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426183/100/0/threaded" source="BUGTRAQ">20060226 Re: PwsPHP Injection SQL on Index.php</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426084/100/0/threaded" source="BUGTRAQ">20060225 PwsPHP Injection SQL on Index.php</ref>
      <ref url="http://www.pwsphp.com/index.php?mod=news&amp;ac=commentaires&amp;id=278" source="CONFIRM">http://www.pwsphp.com/index.php?mod=news&amp;ac=commentaires&amp;id=278</ref>
      <ref url="http://securitytracker.com/id?1015684" source="SECTRACK">1015684</ref>
      <ref url="http://securityreason.com/securityalert/496" source="SREASON">496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwsphp" name="pwsphp">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0944" published="2006-02-28" name="CVE-2006-0944" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24984" source="XF">archangel-admin-auth-bypass(24984)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426184/100/0/threaded" source="BUGTRAQ">20060226 Archangel Weblog 0.90.02 Admin Authentication Bypass &amp; Remote File Inclusion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24984" source="XF">archangel-admin-auth-bypass(24984)</ref>
      <ref url="http://www.securityfocus.com/bid/16848" source="BID">16848</ref>
      <ref url="http://www.osvdb.org/23620" source="OSVDB">23620</ref>
      <ref url="http://www.milw0rm.com/exploits/3859" source="MILW0RM">3859</ref>
      <ref url="http://securitytracker.com/id?1015689" source="SECTRACK">1015689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archangelmgt" name="weblog">
        <vers num="0.90.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0945" published="2006-02-28" name="CVE-2006-0945" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25142" source="XF">archangel-index-file-include(25142)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24984" source="XF">archangel-admin-auth-bypass(24984)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24984" source="XF">archangel-admin-auth-bypass(24984)</ref>
      <ref url="http://www.securityfocus.com/bid/16848" source="BID">16848</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426184/100/0/threaded" source="BUGTRAQ">20060226 Archangel Weblog 0.90.02 Admin Authentication Bypass &amp; Remote File Inclusion</ref>
      <ref url="http://www.osvdb.org/23621" source="OSVDB">23621</ref>
      <ref url="http://securitytracker.com/id?1015689" source="SECTRACK">1015689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archangelmgt" name="weblog">
        <vers num="0.90.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0946" published="2006-02-28" name="CVE-2006-0946" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0765" source="VUPEN">ADV-2006-0765</ref>
      <ref url="http://www.securityfocus.com/bid/16839" source="BID">16839</ref>
      <ref url="http://www.securityfocus.com/archive/1/426186" source="BUGTRAQ">20060226 Thomson SpeedTouch 500 modems vulnerable to XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24977" source="XF">speedtouch-localnetwork-xss(24977)</ref>
      <ref url="http://www.osvdb.org/23527" source="OSVDB">23527</ref>
      <ref url="http://securitytracker.com/id?1015688" source="SECTRACK">1015688</ref>
      <ref url="http://secunia.com/advisories/19069" source="SECUNIA">19069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomson" name="speedtouch">
        <vers num="516_5.3.2.6.0" />
        <vers num="530_5.3.2.6.0" />
        <vers num="536_5.3.2.6.0" />
        <vers num="546_5.3.2.6.0" />
        <vers num="576_5.3.2.6.0" />
        <vers num="580_5.3.2.6.0" />
        <vers num="585_5.3.2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0947" published="2006-02-28" name="CVE-2006-0947" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0765" source="VUPEN">ADV-2006-0765</ref>
      <ref url="http://www.securityfocus.com/bid/16839" source="BID">16839</ref>
      <ref url="http://www.securityfocus.com/archive/1/426186" source="BUGTRAQ">20060226 Thomson SpeedTouch 500 modems vulnerable to XSS</ref>
      <ref url="http://securitytracker.com/id?1015688" source="SECTRACK">1015688</ref>
      <ref url="http://secunia.com/advisories/19069" source="SECUNIA">19069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomson" name="speedtouch">
        <vers num="516_5.3.2.6.0" />
        <vers num="530_5.3.2.6.0" />
        <vers num="536_5.3.2.6.0" />
        <vers num="546_5.3.2.6.0" />
        <vers num="576_5.3.2.6.0" />
        <vers num="580_5.3.2.6.0" />
        <vers num="585_5.3.2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0948" published="2006-08-21" name="CVE-2006-0948" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.</descript>
    </desc>
    <sols>
      <sol source="nvd">AOL has released fixes to address this issue. These fixes can be automatically applied by logging in to the service.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/28445" source="XF" patch="1">aol-default-insecure-permissions(28445)</ref>
      <ref url="http://www.securityfocus.com/bid/19583" source="BID" patch="1">19583</ref>
      <ref url="http://securitytracker.com/id?1016717" source="SECTRACK" patch="1">1016717</ref>
      <ref url="http://secunia.com/advisories/18734" source="SECUNIA" patch="1" adv="1">18734</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3317" source="VUPEN">ADV-2006-3317</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/443622/100/0/threaded" source="BUGTRAQ" adv="1">20060818 Secunia Research: AOL Insecure Default Directory Permissions</ref>
      <ref url="http://www.osvdb.org/27995" source="OSVDB">27995</ref>
      <ref url="http://securityreason.com/securityalert/1416" source="SREASON">1416</ref>
      <ref url="http://secunia.com/secunia_research/2006-08" source="MISC">http://secunia.com/secunia_research/2006-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol">
        <vers num="9.0_4184.2340" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0949" published="2006-03-06" name="CVE-2006-0949" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects RaidenHTTPD, RaidenHTTPD version 1.1.47 and may affect all previous versions.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23616" source="OSVDB" patch="1" adv="1">23616</ref>
      <ref url="http://secunia.com/secunia_research/2006-15/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-15/advisory/</ref>
      <ref url="http://secunia.com/advisories/19032" source="SECUNIA" patch="1" adv="1">19032</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0807" source="VUPEN">ADV-2006-0807</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25037" source="XF">raidenhttpd-extension-obtain-information(25037)</ref>
      <ref url="http://www.securityfocus.com/bid/16934" source="BID">16934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raidenhttpd" name="raidenhttpd">
        <vers num="1.1.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0950" published="2006-03-13" name="CVE-2006-0950" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427475/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060313 Secunia Research: unalz Filename Handling Directory TraversalVulnerability</ref>
      <ref url="http://secunia.com/advisories/19063" source="SECUNIA" patch="1" adv="1">19063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25171" source="XF">unalz-archive-directory-traversal(25171)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0938" source="VUPEN" adv="1">ADV-2006-0938</ref>
      <ref url="http://www.securityfocus.com/bid/17105" source="BID">17105</ref>
      <ref url="http://www.osvdb.org/23835" source="OSVDB">23835</ref>
      <ref url="http://securitytracker.com/id?1015780" source="SECTRACK">1015780</ref>
      <ref url="http://securityreason.com/securityalert/575" source="SREASON">575</ref>
      <ref url="http://secunia.com/secunia_research/2006-16/" source="MISC">http://secunia.com/secunia_research/2006-16/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114226632422033&amp;w=2" source="FULLDISC">20060313 Secunia Research: unalz Filename Handling</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unalz" name="unalz">
        <vers num="0.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0951" published="2006-04-07" name="CVE-2006-0951" modified="2011-03-07" discovered="2006-03-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19054" source="SECUNIA" patch="1" adv="1">19054</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1242" source="VUPEN">ADV-2006-1242</ref>
      <ref url="http://secunia.com/secunia_research/2006-17/advisory/" source="MISC">http://secunia.com/secunia_research/2006-17/advisory/</ref>
      <ref url="http://www.osvdb.org/24394" source="OSVDB">24394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0956" published="2006-03-02" name="CVE-2006-0956" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects NuFW, NuFW Firewall versions 1.0.20 and previous.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.nufw.org/+NuFW-1-21-minor-security-fix+.html" source="CONFIRM" patch="1" adv="1">http://www.nufw.org/+NuFW-1-21-minor-security-fix+.html</ref>
      <ref url="http://secunia.com/advisories/19046" source="SECUNIA" patch="1" adv="1">19046</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0762" source="VUPEN">ADV-2006-0762</ref>
      <ref url="http://www.securityfocus.com/bid/16868" source="BID">16868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nufw" name="nufw_firewall">
        <vers num="1.0.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0957" published="2006-03-02" name="CVE-2006-0957" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19020" source="SECUNIA" patch="1" adv="1">19020</ref>
      <ref url="http://evuln.com/vulns/89/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/89/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0759" source="VUPEN">ADV-2006-0759</ref>
      <ref url="http://soft.zoneo.net/freeForum/changes.php" source="CONFIRM">http://soft.zoneo.net/freeForum/changes.php</ref>
      <ref url="http://www.securityfocus.com/bid/16871" source="BID">16871</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427321/100/0/threaded" source="BUGTRAQ">20060310 [eVuln] FreeForum PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoneo-soft" name="freeforum">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0958" published="2006-03-02" name="CVE-2006-0958" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19020" source="SECUNIA" patch="1" adv="1">19020</ref>
      <ref url="http://evuln.com/vulns/89/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/89/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0759" source="VUPEN">ADV-2006-0759</ref>
      <ref url="http://soft.zoneo.net/freeForum/changes.php" source="CONFIRM">http://soft.zoneo.net/freeForum/changes.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24925" source="XF">freeforum-func-xss(24925)</ref>
      <ref url="http://www.securityfocus.com/bid/16877" source="BID">16877</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427321/100/0/threaded" source="BUGTRAQ">20060310 [eVuln] FreeForum PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoneo-soft" name="freeforum">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0959" published="2006-03-02" name="CVE-2006-0959" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie.  NOTE: 1.04 has also been reported to be affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24953" source="XF">mybb-misc-sql-injection(24953)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0774" source="VUPEN" adv="1">ADV-2006-0774</ref>
      <ref url="http://www.securityfocus.com/bid/16631" source="BID">16631</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426653/100/0/threaded" source="BUGTRAQ">20060303 MyBB 1.04 Perl Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426320/100/0/threaded" source="BUGTRAQ">20060228 MyBB 1.3 NewSQL Injection</ref>
      <ref url="http://www.osvdb.org/23554" source="OSVDB">23554</ref>
      <ref url="http://securityreason.com/securityalert/512" source="SREASON">512</ref>
      <ref url="http://secunia.com/advisories/19061" source="SECUNIA" adv="1">19061</ref>
      <ref url="http://milw0rm.com/exploits/1539" source="MILW0RM">1539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0960" published="2006-03-02" name="CVE-2006-0960" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0780" source="VUPEN">ADV-2006-0780</ref>
      <ref url="http://www.securityfocus.com/bid/16894" source="BID">16894</ref>
      <ref url="http://www.security.nnov.ru/Ldocument605.html" source="MISC">http://www.security.nnov.ru/Ldocument605.html</ref>
      <ref url="http://securitytracker.com/id?1015690" source="SECTRACK">1015690</ref>
      <ref url="http://secunia.com/advisories/19037" source="SECUNIA" adv="1">19037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24968" source="XF">netpassage-udp-dos(24968)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compex" name="netpassage_wpe54g">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0961" published="2006-03-02" name="CVE-2006-0961" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter.  NOTE: this product has also been referred to as "Cilem News," although that does not appear to be the proper name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24920" source="XF">cilemnews-sql-injection(24920)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0881" source="VUPEN" adv="1">ADV-2006-0881</ref>
      <ref url="http://www.securityfocus.com/bid/16813" source="BID">16813</ref>
      <ref url="http://www.osvdb.org/23618" source="OSVDB">23618</ref>
      <ref url="http://www.nukedx.com/?viewdoc=10" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=10</ref>
      <ref url="http://securitytracker.com/id?1015677" source="SECTRACK">1015677</ref>
      <ref url="http://secunia.com/advisories/19157" source="SECUNIA" adv="1">19157</ref>
      <ref url="http://milw0rm.com/exploits/1562" source="MILW0RM">1562</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114079912721723&amp;w=2" source="FULLDISC">20060224 Advisory: CilemNews System &lt;= 1.1 Remote SQL</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0449.html" source="BUGTRAQ">20060224 Advisory: CilemNews System &lt;= 1.1 Remote SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cilem" name="cilem_haber">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0962" published="2006-03-02" name="CVE-2006-0962" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0799" source="VUPEN">ADV-2006-0799</ref>
      <ref url="http://secunia.com/advisories/19084" source="SECUNIA" adv="1">19084</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25019" source="XF">vubb-index-sql-injection(25019)</ref>
      <ref url="http://www.securityfocus.com/bid/16930" source="BID">16930</ref>
      <ref url="http://milw0rm.com/exploits/1543" source="MILW0RM">1543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vubb" name="vubb">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0963" published="2006-03-02" name="CVE-2006-0963" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in STLport 5.0.2 might allow local users to execute arbitrary code via (1) long locale environment variables to a strcpy function call in c_locale_glibc2.c and (2) long arguments to unspecified functions in num_put_float.cpp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19051" source="SECUNIA" patch="1" adv="1">19051</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0800" source="VUPEN">ADV-2006-0800</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=397543" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=397543</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25159" source="XF">stlport-strcpy-local-bo(25159)</ref>
      <ref url="http://www.securityfocus.com/bid/16928" source="BID">16928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stlport" name="stlport">
        <vers num="5.0.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0964" published="2006-03-02" name="CVE-2006-0964" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16906" source="BID">16906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded" source="BUGTRAQ" adv="1">20060301 NCP VPN/PKI Client - various Bugs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25242" source="XF">ncp-client-firewall-bypass-security(25242)</ref>
      <ref url="http://secunia.com/advisories/19082" source="SECUNIA">19082</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html" source="FULLDISC">20060301 NCP VPN/PKI Client - various Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncp_network_communications" name="secure_client">
        <vers num="8.11_build_146" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0965" published="2006-03-02" name="CVE-2006-0965" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass security protections and configure privileged options via a long argument to ncpmon.exe, which provides access to alternate privileged menus, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16906" source="BID">16906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded" source="BUGTRAQ" adv="1">20060301 NCP VPN/PKI Client - various Bugs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25243" source="XF">ncp-ncpmon-bo(25243)</ref>
      <ref url="http://secunia.com/advisories/19082" source="SECUNIA">19082</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html" source="FULLDISC">20060301 NCP VPN/PKI Client - various Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncp_network_communications" name="secure_client">
        <vers num="8.11_build_146" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0966" published="2006-03-02" name="CVE-2006-0966" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users cause a denial of service (CPU consumption) via a large number of arguments to ncprwsnt.exe, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16906" source="BID">16906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded" source="BUGTRAQ" adv="1">20060301 NCP VPN/PKI Client - various Bugs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25248" source="XF">ncp-ncprwsnt-dos(25248)</ref>
      <ref url="http://secunia.com/advisories/19082" source="SECUNIA">19082</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html" source="FULLDISC">20060301 NCP VPN/PKI Client - various Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncp_network_communications" name="secure_client">
        <vers num="8.11_build_146" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0967" published="2006-03-02" name="CVE-2006-0967" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000.  NOTE: this issue was reported as a buffer overflow, but that term usually does not apply in flooding attacks.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16906" source="BID">16906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded" source="BUGTRAQ" adv="1">20060301 NCP VPN/PKI Client - various Bugs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25249" source="XF">ncp-udp-dos(25249)</ref>
      <ref url="http://secunia.com/advisories/19082" source="SECUNIA">19082</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html" source="FULLDISC">20060301 NCP VPN/PKI Client - various Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncp_network_communications" name="secure_client">
        <vers num="8.11_build_146" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0968" published="2006-03-02" name="CVE-2006-0968" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16906" source="BID">16906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded" source="BUGTRAQ" adv="1">20060301 NCP VPN/PKI Client - various Bugs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25251" source="XF">ncp-connect-command-execution(25251)</ref>
      <ref url="http://securityreason.com/securityalert/524" source="SREASON">524</ref>
      <ref url="http://secunia.com/advisories/19082" source="SECUNIA">19082</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html" source="FULLDISC">20060301 NCP VPN/PKI Client - various Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncp_network_communications" name="secure_client">
        <vers num="8.11_build_146" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0969" published="2006-03-03" name="CVE-2006-0969" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Top sites de PixelArtKingdom allows remote attackers to include and execute arbitrary files via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426249/100/0/threaded" source="BUGTRAQ">20060227 PixelArtKingdom TopSites Remote Command Exucetion</ref>
      <ref url="http://securityreason.com/securityalert/507" source="SREASON">507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelartkingdom" name="top_sites">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0970" published="2006-03-03" name="CVE-2006-0970" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426214/100/0/threaded" source="BUGTRAQ">20060227 Knowledgebases Remote Command Exucetion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24989" source="XF">activecampaign-index-command-execution(24989)</ref>
      <ref url="http://www.osvdb.org/3228" source="OSVDB">3228</ref>
      <ref url="http://securityreason.com/securityalert/505" source="SREASON">505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecampaign" name="1-2-all">
        <vers num="" />
      </prod>
      <prod vendor="activecampaign" name="general">
        <vers num="" />
      </prod>
      <prod vendor="activecampaign" name="isalient">
        <vers num="" />
      </prod>
      <prod vendor="activecampaign" name="knowledgebuilder">
        <vers num="" />
      </prod>
      <prod vendor="activecampaign" name="supporttrio">
        <vers num="" />
      </prod>
      <prod vendor="activecampaign" name="visualedit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0971" published="2006-03-03" name="CVE-2006-0971" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0761" source="VUPEN">ADV-2006-0761</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426250/100/0/threaded" source="BUGTRAQ" adv="1">20060227 directory traversal in DirectContact 0.3b</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24930" source="XF">directcontact-dotdot-dir-traversal(24930)</ref>
      <ref url="http://www3.autistici.org/fdonato/advisory/DirectContact0.3b-adv.txt" source="MISC">http://www3.autistici.org/fdonato/advisory/DirectContact0.3b-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16849" source="BID">16849</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427464/100/0/threaded" source="BUGTRAQ">20060312 directory traversal Fixed in DirectContact 0.3c</ref>
      <ref url="http://www.osvdb.org/23519" source="OSVDB">23519</ref>
      <ref url="http://securitytracker.com/id?1015686" source="SECTRACK">1015686</ref>
      <ref url="http://securityreason.com/securityalert/506" source="SREASON">506</ref>
      <ref url="http://secunia.com/advisories/19053" source="SECUNIA">19053</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042560.html" source="FULLDISC">20060227 directory traversal in DirectContact 0.3b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionel_reyero" name="directcontact">
        <vers num="0.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0972" published="2006-03-03" name="CVE-2006-0972" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.  NOTE: the category vector is already covered by CVE-2005-3846.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426195/100/0/threaded" source="BUGTRAQ" adv="1">20060226 2 SQL Injection in Fantastic News</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24943" source="XF">fantasticnews-news-sql-injection(24943)</ref>
      <ref url="http://www.securityfocus.com/bid/16842" source="BID">16842</ref>
      <ref url="http://securityreason.com/securityalert/501" source="SREASON">501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fscripts" name="fantastic_news">
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0973" published="2006-03-03" name="CVE-2006-0973" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/phpWebSite-topic-sql-inj.pl" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/phpWebSite-topic-sql-inj.pl</ref>
      <ref url="http://www.securityfocus.com/bid/16825" source="BID" adv="1">16825</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25799" source="XF">phpwebsite-topics-sql-injection(25799)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435009/100/0/threaded" source="BUGTRAQ">20060523 sql injection in phpWebSite 0.8.3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430870/100/0/threaded" source="BUGTRAQ">20060412 phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit</ref>
      <ref url="http://milw0rm.com/exploits/1525" source="MILW0RM">1525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.7.3" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.9.3" />
        <vers num="0.9.3.1" />
        <vers num="0.9.3.2" />
        <vers num="0.9.3.3" />
        <vers num="0.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0974" published="2006-03-03" name="CVE-2006-0974" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Battleaxe Software, bttlxeForum versions 2.0 and previous</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24981" source="XF">bttlxeforum-failure-xss(24981)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0776" source="VUPEN">ADV-2006-0776</ref>
      <ref url="http://www.securityfocus.com/bid/16821" source="BID">16821</ref>
      <ref url="http://www.osvdb.org/23540" source="OSVDB">23540</ref>
      <ref url="http://secunia.com/advisories/19043" source="SECUNIA" adv="1">19043</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0548.html" source="BUGTRAQ">20060226 bttlxeForum 2.* XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleaxe_software" name="bttlxeforum">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0975" reject="1" published="2006-03-03" name="CVE-2006-0975" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0459.  Reason: This candidate is a reservation duplicate of CVE-2006-0459.  Notes: All CVE users should reference CVE-2006-0459 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0976" published="2006-03-03" name="CVE-2006-0976" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24955" source="XF">spid-scanlanginsert-file-include(24955)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0766" source="VUPEN">ADV-2006-0766</ref>
      <ref url="http://www.securityfocus.com/bid/16822" source="BID">16822</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426073/100/0/threaded" source="BUGTRAQ">20060225 NSA Group Security Advisory NSAG-&amp;sup1;201-25.02.2006 Vulnerability SPiD v1.3.1</ref>
      <ref url="http://www.nsag.ru/vuln/955.html" source="MISC">http://www.nsag.ru/vuln/955.html</ref>
      <ref url="http://secunia.com/advisories/19033" source="SECUNIA" adv="1">19033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spid" name="spid">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0977" published="2006-03-03" name="CVE-2006-0977" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0786" source="VUPEN">ADV-2006-0786</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426181/100/0/threaded" source="BUGTRAQ">20060225 Mail Transport System Professional--Open Relay Hole</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24985" source="XF">mts-mail-relay(24985)</ref>
      <ref url="http://www.securityfocus.com/bid/16840" source="BID">16840</ref>
      <ref url="http://secunia.com/advisories/19067" source="SECUNIA">19067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="craig_morrison" name="mts_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0978" published="2006-03-03" name="CVE-2006-0978" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects ArGoSoft, Mail Server Pro version 1.8.8.5, and may affect all previous versions.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0751" source="VUPEN">ADV-2006-0751</ref>
      <ref url="http://www.securityfocus.com/bid/16834" source="BID">16834</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426206/100/0/threaded" source="BUGTRAQ" adv="1">20060227 Secunia Research: ArGoSoft Mail Server Pro viewheaders ScriptInsertion</ref>
      <ref url="http://www.osvdb.org/23512" source="OSVDB">23512</ref>
      <ref url="http://secunia.com/secunia_research/2006-6/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2006-6/advisory/</ref>
      <ref url="http://secunia.com/advisories/18991" source="SECUNIA">18991</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24945" source="XF">argosoft-mailserverpro-viewheaders-xss(24945)</ref>
      <ref url="http://securityreason.com/securityalert/504" source="SREASON">504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="argosoft_mail_server">
        <vers num="1.8.8.5" edition="" />
        <vers num="1.8.8.5" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0979" published="2006-03-03" name="CVE-2006-0979" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the local weblog publisher in Nidelven IT Issue Dealer before 0.9.96 has unknown impact and attack vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Nidelven IT, Issue Dealer versions 0.9.95 and previous.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23502" source="OSVDB" patch="1" adv="1">23502</ref>
      <ref url="http://issuedealer.com/changes/" source="CONFIRM">http://issuedealer.com/changes/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24929" source="XF">issuedealer-unpublished-issue-disclosure(24929)</ref>
      <ref url="http://www.securityfocus.com/bid/16884" source="BID">16884</ref>
      <ref url="http://secunia.com/advisories/19018" source="SECUNIA">19018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nidelven_it" name="issue_dealer">
        <vers num="0.9.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0980" published="2006-03-03" name="CVE-2006-0980" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0764" source="VUPEN">ADV-2006-0764</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426198/100/0/threaded" source="BUGTRAQ" adv="1">20060226 CGI Calendar XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24946" source="XF">cgicalendar-index-viewday-xss(24946)</ref>
      <ref url="http://secunia.com/advisories/19066" source="SECUNIA">19066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jay_eckles" name="cgi_calendar">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0981" published="2006-03-03" name="CVE-2006-0981" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects e-merge, WinAce versions 2.6 and previous.</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24902" source="XF" adv="1">winace-rar-tar-directory-traversal(24902)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0730" source="VUPEN">ADV-2006-0730</ref>
      <ref url="http://www.securityfocus.com/bid/16800" source="BID" adv="1">16800</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425971/100/0/threaded" source="BUGTRAQ" adv="1">20060224 WinAce Archiver v2.6 Directory traversal</ref>
      <ref url="http://www.osvdb.org/23464" source="OSVDB" adv="1">23464</ref>
      <ref url="http://www.hamid.ir/security/winace.txt" source="MISC" adv="1">http://www.hamid.ir/security/winace.txt</ref>
      <ref url="http://secunia.com/advisories/19013" source="SECUNIA" adv="1">19013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-merge" name="e-merge_winace">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0982" published="2006-03-03" name="CVE-2006-0982" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allows remote attackers to bypass virus protection, as demonstrated using the EICAR test file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426348/100/0/threaded" source="BUGTRAQ">20060228 Virex on-access scanning unreliable</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virex">
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":macintosh" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0983" published="2006-03-03" name="CVE-2006-0983" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=438526" source="MISC" patch="1">http://sourceforge.net/forum/forum.php?forum_id=438526</ref>
      <ref url="http://www.securityfocus.com/bid/16874" source="BID" adv="1">16874</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426319/100/0/threaded" source="BUGTRAQ">20060228 QwikiWiki v1.4 XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24950" source="XF">qwikiwiki-index-xss(24950)</ref>
      <ref url="http://www.osvdb.org/23700" source="OSVDB">23700</ref>
      <ref url="http://securityreason.com/securityalert/510" source="SREASON">510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_barrett" name="qwikiwiki">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0984" published="2006-03-03" name="CVE-2006-0984" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the gTopNombre parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects EJ3, TOPo version 2.2.178, and possibly all previous versions.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0775" source="VUPEN">ADV-2006-0775</ref>
      <ref url="http://www.securityfocus.com/bid/16879" source="BID" adv="1">16879</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426318/100/0/threaded" source="BUGTRAQ" adv="1">20060228 EJ3 TOPo - Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24980" source="XF">topo-incheader-xss(24980)</ref>
      <ref url="http://www.osvdb.org/23541" source="OSVDB">23541</ref>
      <ref url="http://securityreason.com/securityalert/511" source="SREASON">511</ref>
      <ref url="http://secunia.com/advisories/19070" source="SECUNIA">19070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ej3" name="topo">
        <vers num="2.2.178" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0985" published="2006-03-03" name="CVE-2006-0985" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426304/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060227 WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://NeoSecurityTeam.net/advisories/Advisory-17.txt" source="MISC" patch="1" adv="1">http://NeoSecurityTeam.net/advisories/Advisory-17.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0777" source="VUPEN">ADV-2006-0777</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24957" source="XF">wordpress-wpcommentspost-xss(24957)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426574/100/0/threaded" source="BUGTRAQ">20060302 Re: FW: WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426504/100/0/threaded" source="BUGTRAQ">20060228 FW: WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19050" source="SECUNIA">19050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
        <vers num="1.5.1.3" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0986" published="2006-03-03" name="CVE-2006-0986" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory.  NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463.  The menu-header.php vector is already covered by CVE-2005-2110.  Other vectors might be covered by CVE-2005-1688.  NOTE: if the typical installation of WordPress does not list any site-specific files to wp-includes, then vector [13] is not an exposure.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426304/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060227 WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://NeoSecurityTeam.net/advisories/Advisory-17.txt" source="MISC" patch="1" adv="1">http://NeoSecurityTeam.net/advisories/Advisory-17.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0777" source="VUPEN">ADV-2006-0777</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426574/100/0/threaded" source="BUGTRAQ">20060302 Re: FW: WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426504/100/0/threaded" source="BUGTRAQ">20060228 FW: WordPress 2.0.1 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19050" source="SECUNIA">19050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
        <vers num="1.5.1.3" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0987" published="2006-03-03" name="CVE-2006-0987" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of ISC BIND, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects ISC, BIND versions 9.3.2 and previous.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf" source="MISC" patch="1" adv="1">http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426368/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060228 recursive DNS servers DDoS as a growing DDoS problem</ref>
      <ref url="http://dns.measurement-factory.com/surveys/sum1.html" source="MISC">http://dns.measurement-factory.com/surveys/sum1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0988" published="2006-03-03" name="CVE-2006-0988" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of Windows 2000 -and- Windows Server 2003.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf" source="MISC" patch="1" adv="1">http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426368/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060228 recursive DNS servers DDoS as a growing DDoS problem</ref>
      <ref url="http://dns.measurement-factory.com/surveys/sum1.html" source="MISC">http://dns.measurement-factory.com/surveys/sum1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0989" published="2006-03-27" name="CVE-2006-0989" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/880801" source="CERT-VN">VU#880801</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-005.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-005.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1124" source="VUPEN">ADV-2006-1124</ref>
      <ref url="http://seer.support.veritas.com/docs/281521.htm" source="CONFIRM" adv="1">http://seer.support.veritas.com/docs/281521.htm</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25471" source="XF">netbackup-vmd-sscanf-bo(25471)</ref>
      <ref url="http://www.securityfocus.com/bid/17264" source="BID">17264</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428944/100/0/threaded" source="BUGTRAQ">20060327 ZDI-06-005: Symantec VERITAS NetBackup Volume Manager Buffer Overflow</ref>
      <ref url="http://www.osvdb.org/24172" source="OSVDB">24172</ref>
      <ref url="http://securitytracker.com/id?1015832" source="SECTRACK">1015832</ref>
      <ref url="http://securityreason.com/securityalert/639" source="SREASON">639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="veritas" name="netbackup">
        <vers num="4.5.0" edition="fp" />
        <vers num="4.5.0" edition="fp:businessserver" />
        <vers num="4.5.0" edition="fp:datacenter" />
        <vers num="4.5.0" edition="mp" />
        <vers num="4.5.0" edition="mp:datacenter" />
        <vers num="4.5.0" edition="mp:businessserver" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":server" />
        <vers num="5.0" edition=":enterprise_server" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise_server" />
        <vers num="5.1" edition=":server" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":server" />
        <vers num="6.0" edition=":enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0990" published="2006-03-27" name="CVE-2006-0990" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/744137" source="CERT-VN">VU#744137</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-006.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-006.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1124" source="VUPEN">ADV-2006-1124</ref>
      <ref url="http://seer.support.veritas.com/docs/281521.htm" source="CONFIRM" adv="1">http://seer.support.veritas.com/docs/281521.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25472" source="XF">netbackup-bpdbm-sprintf-bo(25472)</ref>
      <ref url="http://www.securityfocus.com/bid/17264" source="BID">17264</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428992/100/0/threaded" source="BUGTRAQ">20060327 SYM06-006, Veritas NetBackup: Multiple Overflow Vulnerabilities in NetBackup Daemons</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428988/100/0/threaded" source="BUGTRAQ">20060327 ZDI-06-006: Symantec VERITAS NetBackup Database Manager Buffer Overflow</ref>
      <ref url="http://securitytracker.com/id?1015832" source="SECTRACK">1015832</ref>
      <ref url="http://securityreason.com/securityalert/642" source="SREASON">642</ref>
      <ref url="http://secunia.com/advisories/19417" source="SECUNIA">19417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="veritas" name="netbackup">
        <vers num="4.5.0" edition="fp" />
        <vers num="4.5.0" edition="fp:businessserver" />
        <vers num="4.5.0" edition="fp:datacenter" />
        <vers num="4.5.0" edition="mp" />
        <vers num="4.5.0" edition="mp:datacenter" />
        <vers num="4.5.0" edition="mp:businessserver" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":server" />
        <vers num="5.0" edition=":enterprise_server" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise_server" />
        <vers num="5.1" edition=":server" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":server" />
        <vers num="6.0" edition=":enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0991" published="2006-03-27" name="CVE-2006-0991" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted "Request Service" packets to the vnetd service (TCP port 13724).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/377441" source="CERT-VN">VU#377441</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25473" source="XF">netbackup-vnetd-bo(25473)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1124" source="VUPEN">ADV-2006-1124</ref>
      <ref url="http://www.tippingpoint.com/security/advisories/TSRT-06-01.html" source="MISC" adv="1">http://www.tippingpoint.com/security/advisories/TSRT-06-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/17264" source="BID">17264</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428979/100/0/threaded" source="BUGTRAQ">20060327 TSRT-06-01: Symantec VERITAS NetBackup vnetd Buffer Overflow Vulnerability</ref>
      <ref url="http://seer.support.veritas.com/docs/281521.htm" source="CONFIRM">http://seer.support.veritas.com/docs/281521.htm</ref>
      <ref url="http://securitytracker.com/id?1015832" source="SECTRACK">1015832</ref>
      <ref url="http://secunia.com/advisories/19417" source="SECUNIA">19417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="veritas" name="netbackup">
        <vers num="4.5.0" edition="fp" />
        <vers num="4.5.0" edition="fp:businessserver" />
        <vers num="4.5.0" edition="fp:datacenter" />
        <vers num="4.5.0" edition="mp" />
        <vers num="4.5.0" edition="mp:datacenter" />
        <vers num="4.5.0" edition="mp:businessserver" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":server" />
        <vers num="5.0" edition=":enterprise_server" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise_server" />
        <vers num="5.1" edition=":server" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":server" />
        <vers num="6.0" edition=":enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0992" published="2006-04-14" name="CVE-2006-0992" modified="2011-03-07" discovered="2006-03-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon.  NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092.  This is the correct identifier.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to GroupWise Messenger, 2.0 Public Beta 2 to fix this issue.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-008.html" source="MISC" patch="1" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-06-008.html</ref>
      <ref url="http://www.securityfocus.com/bid/17503" source="BID" patch="1">17503</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100861.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?10100861.htm</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1355" source="VUPEN">ADV-2006-1355</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430911/100/0/threaded" source="BUGTRAQ" adv="1">20060413 ZDI-06-008: Novell GroupWise Messenger Accept-Language Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25828" source="XF">groupwise-accept-language-bo(25828)</ref>
      <ref url="http://www.osvdb.org/24617" source="OSVDB">24617</ref>
      <ref url="http://www.milw0rm.com/exploits/1679" source="MILW0RM">1679</ref>
      <ref url="http://securitytracker.com/id?1015911" source="SECTRACK">1015911</ref>
      <ref url="http://secunia.com/advisories/19663" source="SECUNIA">19663</ref>
      <ref url="http://metasploit.blogspot.com/2006/04/exploit-development-groupwise_14.html" source="MISC">http://metasploit.blogspot.com/2006/04/exploit-development-groupwise_14.html</ref>
      <ref url="http://cirt.dk/advisories/cirt-42-advisory.txt" source="MISC">http://cirt.dk/advisories/cirt-42-advisory.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise_messenger">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0993" published="2006-05-09" name="CVE-2006-0993" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might allow remote attackers to obtain potentially sensitive information such as configuration settings.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to 3Com TippingPoint SMS Server version 2.2.1.4478</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-013.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-06-013.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1752" source="VUPEN">ADV-2006-1752</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433432/100/0/threaded" source="BUGTRAQ">20060509 ZDI-06-013: 3Com TippingPoint SMS Server Information Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26338" source="XF">tippingpoint-sms-information-disclosure(26338)</ref>
      <ref url="http://www.securityfocus.com/bid/17935" source="BID">17935</ref>
      <ref url="http://www.osvdb.org/25360" source="OSVDB">25360</ref>
      <ref url="http://www.3com.com/securityalert/alerts/3COM-06-002.html" source="CONFIRM">http://www.3com.com/securityalert/alerts/3COM-06-002.html</ref>
      <ref url="http://securitytracker.com/id?1016051" source="SECTRACK">1016051</ref>
      <ref url="http://securityreason.com/securityalert/870" source="SREASON">870</ref>
      <ref url="http://secunia.com/advisories/20058" source="SECUNIA">20058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="tippingpoint_sms_server">
        <vers prev="1" num="2.2.1.4477" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0994" published="2006-05-10" name="CVE-2006-0994" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, allows remote attackers to execute arbitrary code via a CAB file with "invalid folder count values," which leads to heap corruption.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has issued a fixed version</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-012.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-012.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1730" source="VUPEN">ADV-2006-1730</ref>
      <ref url="http://www.securityfocus.com/bid/17876" source="BID">17876</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433272/100/0/threaded" source="BUGTRAQ">20060508 ZDI-06-012: Sophos Anti-Virus CAB Unpacking Code Execution Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1016041" source="SECTRACK">1016041</ref>
      <ref url="http://secunia.com/advisories/20028" source="SECUNIA" adv="1">20028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26305" source="XF">sophos-cab-parsing-bo(26305)</ref>
      <ref url="http://securityreason.com/securityalert/869" source="SREASON">869</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045897.html" source="FULLDISC">20060508 ZDI-06-012: Sophos Anti-Virus CAB Unpacking Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers prev="1" num="4.04" />
        <vers prev="1" num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0995" published="2006-03-03" name="CVE-2006-0995" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup service) via a malformed packet to TCP port 497, which triggers an assert error.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects EMC Dantz, Retrospect versions 7.0.x (all 7.0.x versions previous to 7.0.109) as well as versions 6.5.x (all 6.5.x versions previous to 6.5.138)</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20060302 EMC Dantz Retrospect 7 Backup client DoS Vulnerability</ref>
      <ref url="http://kb.dantz.com/article.asp?article=8361&amp;p=2" source="CONFIRM" patch="1" adv="1">http://kb.dantz.com/article.asp?article=8361&amp;p=2</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0811" source="VUPEN">ADV-2006-0811</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25143" source="XF">retrospect-backup-packet-dos(25143)</ref>
      <ref url="http://www.securityfocus.com/bid/16933" source="BID">16933</ref>
      <ref url="http://securitytracker.com/id?1015714" source="SECTRACK">1015714</ref>
      <ref url="http://secunia.com/advisories/19097" source="SECUNIA">19097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc_dantz" name="retrospect">
        <vers num="6.5" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0996" published="2006-04-10" name="CVE-2006-0996" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=php-cvs&amp;m=114374620416389&amp;w=2" source="MLIST" patch="1">[php-cvs] 20060330 cvs: php-src /ext/standard info.c</ref>
      <ref url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c?r1=1.260&amp;r2=1.261" source="CONFIRM" patch="1">http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c?r1=1.260&amp;r2=1.261</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25702" source="XF">php-phpinfo-long-array-xss(25702)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2685" source="VUPEN">ADV-2006-2685</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1290" source="VUPEN">ADV-2006-1290</ref>
      <ref url="http://www.ubuntu.com/usn/usn-320-1" source="UBUNTU">USN-320-1</ref>
      <ref url="http://www.securityfocus.com/bid/17362" source="BID">17362</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0501.html" source="REDHAT">RHSA-2006:0501</ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.4.3" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.4.3</ref>
      <ref url="http://www.osvdb.org/24484" source="OSVDB">24484</ref>
      <ref url="http://www.novell.com/linux/security/advisories/05-05-2006.html" source="SUSE">SUSE-SA:2006:024</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:074" source="MANDRIVA">MDKSA-2006:074</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm</ref>
      <ref url="http://securitytracker.com/id?1015879" source="SECTRACK">1015879</ref>
      <ref url="http://securityreason.com/securityalert/675" source="SREASON">675</ref>
      <ref url="http://securityreason.com/achievement_securityalert/34" source="SREASONRES">20060408 phpinfo() Cross Site Scripting PHP 5.1.2 and 4.4.2</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200605-08.xml" source="GENTOO">GLSA-200605-08</ref>
      <ref url="http://secunia.com/advisories/21564" source="SECUNIA" adv="1">21564</ref>
      <ref url="http://secunia.com/advisories/21252" source="SECUNIA" adv="1">21252</ref>
      <ref url="http://secunia.com/advisories/21125" source="SECUNIA" adv="1">21125</ref>
      <ref url="http://secunia.com/advisories/20951" source="SECUNIA" adv="1">20951</ref>
      <ref url="http://secunia.com/advisories/20222" source="SECUNIA" adv="1">20222</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA" adv="1">20210</ref>
      <ref url="http://secunia.com/advisories/20052" source="SECUNIA" adv="1">20052</ref>
      <ref url="http://secunia.com/advisories/19979" source="SECUNIA" adv="1">19979</ref>
      <ref url="http://secunia.com/advisories/19832" source="SECUNIA" adv="1">19832</ref>
      <ref url="http://secunia.com/advisories/19775" source="SECUNIA" adv="1">19775</ref>
      <ref url="http://secunia.com/advisories/19599" source="SECUNIA" adv="1">19599</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0549.html" source="REDHAT">RHSA-2006:0549</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0276.html" source="REDHAT">RHSA-2006:0276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10997" source="OVAL">oval:org.mitre.oval:def:10997</ref>
      <ref url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c" source="CONFIRM">http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.2" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0997" published="2006-03-23" name="CVE-2006-0997" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1043" source="VUPEN">ADV-2006-1043</ref>
      <ref url="http://www.securityfocus.com/bid/17176" source="BID">17176</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25380" source="XF">netware-nile-ssl-cleartext(25380)</ref>
      <ref url="http://www.osvdb.org/24046" source="OSVDB">24046</ref>
      <ref url="http://securitytracker.com/id?1015799" source="SECTRACK">1015799</ref>
      <ref url="http://secunia.com/advisories/19324" source="SECUNIA">19324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp1.1a" />
        <vers num="6.5" edition="sp1.1b" />
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
        <vers num="6.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0998" published="2006-03-23" name="CVE-2006-0998" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1043" source="VUPEN">ADV-2006-1043</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25381" source="XF">netware-nile-weak-encryption(25381)</ref>
      <ref url="http://www.osvdb.org/24047" source="OSVDB">24047</ref>
      <ref url="http://securitytracker.com/id?1015799" source="SECTRACK">1015799</ref>
      <ref url="http://secunia.com/advisories/19324" source="SECUNIA">19324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp1.1a" />
        <vers num="6.5" edition="sp1.1b" />
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
        <vers num="6.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0999" published="2006-03-23" name="CVE-2006-0999" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1043" source="VUPEN">ADV-2006-1043</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25382" source="XF">netware-nile-forced-weak-encryption(25382)</ref>
      <ref url="http://www.osvdb.org/24048" source="OSVDB">24048</ref>
      <ref url="http://securitytracker.com/id?1015799" source="SECTRACK">1015799</ref>
      <ref url="http://secunia.com/advisories/19324" source="SECUNIA">19324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp1.1a" />
        <vers num="6.5" edition="sp1.1b" />
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
        <vers num="6.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1000" published="2006-03-06" name="CVE-2006-1000" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0749" source="VUPEN">ADV-2006-0749</ref>
      <ref url="http://www.securityfocus.com/bid/16818" source="BID" adv="1">16818</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426075/100/0/threaded" source="BUGTRAQ" adv="1">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (newsdetailsview.aspnewsid) Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426074/100/0/threaded" source="BUGTRAQ" adv="1">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (login.asp) AuthencationByPass Vulnerability</ref>
      <ref url="http://www.nukedx.com/?viewdoc=14" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=14</ref>
      <ref url="http://www.nukedx.com/?viewdoc=13" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=13</ref>
      <ref url="http://securitytracker.com/id?1015682" source="SECTRACK" adv="1">1015682</ref>
      <ref url="http://secunia.com/advisories/19024" source="SECUNIA" adv="1">19024</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042525.html" source="FULLDISC">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (newsdetailsview.asp newsid) Remote SQL Injection Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042524.html" source="FULLDISC">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (login.asp) Authencation ByPass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="g2soft" name="pentacle_in-out_board">
        <vers num="6.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1001" published="2006-03-06" name="CVE-2006-1001" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary SQL commands via the fid parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Lansuite, LanParty Intranet System version 2.1 (Beta) &amp; LanSuite, LanParty Intranet System versions 2.0.6 and previous.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0747" source="VUPEN">ADV-2006-0747</ref>
      <ref url="http://www.securityfocus.com/bid/16836" source="BID" adv="1">16836</ref>
      <ref url="http://secunia.com/advisories/19048" source="SECUNIA" adv="1">19048</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24940" source="XF">lansuite-fid-sql-injection(24940)</ref>
      <ref url="http://www.osvdb.org/23533" source="OSVDB">23533</ref>
      <ref url="http://milw0rm.com/exploits/1526" source="MILW0RM">1526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lansuite" name="lanparty_intranet_system">
        <vers num="2.0.6" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1002" published="2006-03-06" name="CVE-2006-1002" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NETGEAR WGT624 Wireless DSL router has a default account of super_username "Gearguy" and super_passwd "Geardog", which allows remote attackers to modify the configuration.  NOTE: followup posts have suggested that this might not occur with all WGT624 routers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24926" source="XF">netgear-wgt624-default-account(24926)</ref>
      <ref url="http://www.securityfocus.com/bid/16835" source="BID">16835</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485396/100/0/threaded" source="BUGTRAQ">20071220 Re: Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431026/30/5580/threaded" source="BUGTRAQ">20060413 Re: Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426313/100/0/threaded" source="BUGTRAQ">20060227 Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426187/100/0/threaded" source="BUGTRAQ">20060226 NETGEAR WGT624 ? Wireless DSL router default user name/password vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="wgt624">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1003" published="2006-03-06" name="CVE-2006-1003" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16837" source="BID">16837</ref>
      <ref url="http://www.securityfocus.com/archive/1/426185" source="BUGTRAQ">20060227 NETGEAR WGT624 ? Wireless DSL Firewall/Router vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24927" source="XF">netgear-wgt624-cleartext-config(24927)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="wgt624">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1004" published="2006-03-06" name="CVE-2006-1004" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the AG_ID parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0763" source="VUPEN">ADV-2006-0763</ref>
      <ref url="http://secunia.com/advisories/19025" source="SECUNIA" adv="1">19025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24971" source="XF">parodia-agencyprofile-xss(24971)</ref>
      <ref url="http://www.securityfocus.com/bid/16865" source="BID">16865</ref>
      <ref url="http://www.osvdb.org/23548" source="OSVDB">23548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactusoft" name="parodia">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1005" published="2006-03-06" name="CVE-2006-1005" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an invalid AG_ID parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects CactuSoft, Parodia version 6.2, and may affect all previous versions as well.</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19025" source="SECUNIA" adv="1">19025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactusoft" name="parodia">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1006" published="2006-03-06" name="CVE-2006-1006" modified="2011-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24978" source="XF" patch="1">sendcard-unspecified-sql-injection(24978)</ref>
      <ref url="http://www.securityfocus.com/bid/16900" source="BID" patch="1">16900</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=544749" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=544749</ref>
      <ref url="http://secunia.com/advisories/19056" source="SECUNIA" patch="1" adv="1">19056</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0778" source="VUPEN" adv="1">ADV-2006-0778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendcard" name="sendcard">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.10" />
        <vers num="1.20" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" edition="pl1" />
        <vers num="3.0.5" edition="pl2" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.0" edition="rc1" />
        <vers num="3.2.0" edition="rc2" />
        <vers num="3.2.0" edition="rc3" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers prev="1" num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1007" published="2006-03-06" name="CVE-2006-1007" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) dir and (2) page_id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24974" source="XF">n8cms-index-sql-injection(24974)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0779" source="VUPEN">ADV-2006-0779</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427222/100/0/threaded" source="BUGTRAQ">20060309 n8cms 1.1 &amp; 1.2 version Sql &amp;#304;njection And XSS</ref>
      <ref url="http://secunia.com/advisories/19068" source="SECUNIA" adv="1">19068</ref>
      <ref url="http://biyosecurity.be/bugs/n8cms.txt" source="MISC">http://biyosecurity.be/bugs/n8cms.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16858" source="BID">16858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nathan_landry" name="n8cms_sitesuite_cms">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1008" published="2006-03-06" name="CVE-2006-1008" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir and (2) page_id parameter to (a) index.php and (3) userid parameter to (b) mailto.php.  NOTE: it is possible that issues 1 and 2 are resultant from SQL injection.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may affect all versions of Nathan Landry, n8cms.</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25126" source="XF">n8cms--xss(25126)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24975" source="XF">n8cms-mailto-xss(24975)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0779" source="VUPEN">ADV-2006-0779</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427222/100/0/threaded" source="BUGTRAQ">20060309 n8cms 1.1 &amp; 1.2 version Sql &amp;#304;njection And XSS</ref>
      <ref url="http://secunia.com/advisories/19068" source="SECUNIA" adv="1">19068</ref>
      <ref url="http://biyosecurity.be/bugs/n8cms.txt" source="MISC">http://biyosecurity.be/bugs/n8cms.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16858" source="BID">16858</ref>
      <ref url="http://securityreason.com/securityalert/562" source="SREASON">562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nathan_landry" name="n8cms_sitesuite_cms">
        <vers num="1.1" />
        <vers num="1.12" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1009" published="2006-03-06" name="CVE-2006-1009" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">M4 Project enigma-suite before 0.73.3 (Windows) has a default password of "nominal" for the "enigma-client" account, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0787" source="VUPEN">ADV-2006-0787</ref>
      <ref url="http://www.osvdb.org/23572" source="OSVDB">23572</ref>
      <ref url="http://www.bytereef.org/m4-project-blog.html" source="CONFIRM">http://www.bytereef.org/m4-project-blog.html</ref>
      <ref url="http://secunia.com/advisories/19077" source="SECUNIA" adv="1">19077</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24993" source="XF">enigma-suite-default-acoount(24993)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="m4_project" name="enigma-suite">
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.73.1" />
        <vers num="0.73.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1010" published="2006-03-06" name="CVE-2006-1010" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (segmentation fault) and possibly execute code by sending the server a large request.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects CrossFire versions 1.8.0 and previous.</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24932" source="XF" patch="1" adv="1">crossfire-oldsocketmode-bo(24932)</ref>
      <ref url="http://secunia.com/advisories/19044" source="SECUNIA" patch="1" adv="1">19044</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?r1=1.80&amp;r2=1.81" source="CONFIRM" patch="1">http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?r1=1.80&amp;r2=1.81</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0760" source="VUPEN">ADV-2006-0760</ref>
      <ref url="http://aluigi.altervista.org/poc/crossfirebof.zip" source="MISC" adv="1">http://aluigi.altervista.org/poc/crossfirebof.zip</ref>
      <ref url="http://www.securityfocus.com/bid/16883" source="BID">16883</ref>
      <ref url="http://www.osvdb.org/23549" source="OSVDB">23549</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-11.xml" source="GENTOO">GLSA-200604-11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1001" source="DEBIAN">DSA-1001</ref>
      <ref url="http://secunia.com/advisories/19785" source="SECUNIA">19785</ref>
      <ref url="http://secunia.com/advisories/19194" source="SECUNIA">19194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crossfire" name="crossfire">
        <vers num="1.7.0" />
        <vers num="1.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1011" published="2006-03-06" name="CVE-2006-1011" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25020" source="XF">lettermerger-files-disclose-information(25020)</ref>
      <ref url="http://www.securityfocus.com/bid/16917" source="BID">16917</ref>
      <ref url="http://www.osvdb.org/23599" source="OSVDB">23599</ref>
      <ref url="http://secunia.com/advisories/19074" source="SECUNIA" adv="1">19074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peters_software" name="lettermerger">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1012" published="2006-03-06" name="CVE-2006-1012" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-01</ref>
      <ref url="http://secunia.com/advisories/19109" source="SECUNIA" patch="1" adv="1">19109</ref>
      <ref url="http://www.securityfocus.com/bid/16950" source="BID">16950</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25321" source="XF">wordpress-comment-sql-injection(25321)</ref>
      <ref url="http://secunia.com/advisories/19123" source="SECUNIA">19123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1013" published="2006-03-06" name="CVE-2006-1013" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426498/100/0/threaded" source="BUGTRAQ">20060301 SMBlog Remote Command Exucetion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25220" source="XF">smartblog-index-file-include(25220)</ref>
      <ref url="http://www.securityfocus.com/bid/16905" source="BID">16905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartblog" name="smartblog">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1014" published="2006-03-06" name="CVE-2006-1014" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="3.2" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.1" CVSS_base_score="3.2">
    <desc>
      <descript source="cve">Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail.  NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of PHP from 4.0.x through 5.1.x </sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426342/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060228 (PHP) mb_send_mail security bypass</ref>
      <ref url="http://secunia.com/advisories/18694" source="SECUNIA" patch="1" adv="1">18694</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0772" source="VUPEN">ADV-2006-0772</ref>
      <ref url="http://www.securityfocus.com/bid/16878" source="BID">16878</ref>
      <ref url="http://www.osvdb.org/23534" source="OSVDB">23534</ref>
      <ref url="http://www.novell.com/linux/security/advisories/05-05-2006.html" source="SUSE">SUSE-SA:2006:024</ref>
      <ref url="http://secunia.com/advisories/19979" source="SECUNIA">19979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.0" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1015" published="2006-03-06" name="CVE-2006-1015" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments.  NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426497/100/0/threaded" source="BUGTRAQ">20060301 Re: (PHP) mb_send_mail security bypass</ref>
      <ref url="http://www.securityfocus.com/bid/16878" source="BID">16878</ref>
      <ref url="http://www.novell.com/linux/security/advisories/05-05-2006.html" source="SUSE">SUSE-SA:2006:024</ref>
      <ref url="http://securityreason.com/securityalert/517" source="SREASON">517</ref>
      <ref url="http://secunia.com/advisories/19979" source="SECUNIA">19979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1016" published="2006-03-06" name="CVE-2006-1016" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24923" source="XF">ie-iscomponentinstalled-bo(24923)</ref>
      <ref url="http://www.metasploit.com/projects/Framework/modules/exploits/ie_iscomponentinstalled.pm" source="MISC">http://www.metasploit.com/projects/Framework/modules/exploits/ie_iscomponentinstalled.pm</ref>
      <ref url="http://metasploit.com/projects/Framework/exploits.html#ie_iscomponentinstalled" source="MISC">http://metasploit.com/projects/Framework/exploits.html#ie_iscomponentinstalled</ref>
      <ref url="http://www.securityfocus.com/bid/16870" source="BID">16870</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1017" published="2006-03-06" name="CVE-2006-1017" modified="2011-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24964" source="XF">php-imap-restriction-bypass(24964)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0772" source="VUPEN" adv="1">ADV-2006-0772</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426339/100/0/threaded" source="BUGTRAQ">20060228 (PHP) imap functions bypass safemode and open_basedir restrictions</ref>
      <ref url="http://www.php.net/release_5_1_5.php" source="CONFIRM">http://www.php.net/release_5_1_5.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.1.5" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.1.5</ref>
      <ref url="http://www.osvdb.org/23535" source="OSVDB">23535</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122" source="MANDRIVA">MDKSA-2006:122</ref>
      <ref url="http://securityreason.com/securityalert/516" source="SREASON">516</ref>
      <ref url="http://secunia.com/advisories/21546" source="SECUNIA" adv="1">21546</ref>
      <ref url="http://secunia.com/advisories/21050" source="SECUNIA" adv="1">21050</ref>
      <ref url="http://secunia.com/advisories/18694" source="SECUNIA" adv="1">18694</ref>
      <ref url="http://bugs.php.net/bug.php?id=37265" source="CONFIRM">http://bugs.php.net/bug.php?id=37265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1018" published="2006-03-06" name="CVE-2006-1018" modified="2009-09-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25163" source="XF">dawaween-poems-sql-injection(25163)</ref>
      <ref url="http://www.securityfocus.com/bid/16909" source="BID">16909</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426622/100/0/threaded" source="BUGTRAQ">20060302 sql in Dawaween V 1.03</ref>
      <ref url="http://www.osvdb.org/23827" source="OSVDB">23827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dci-designs" name="dawaween">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1019" published="2006-03-06" name="CVE-2006-1019" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which reference a source URL that appears to be for an unrelated issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24990" source="XF">ukiboard-fce-xss(24990)</ref>
      <ref url="http://www.securityfocus.com/bid/16912" source="BID">16912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ukiweb" name="ukiboard">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1020" published="2006-03-06" name="CVE-2006-1020" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0790" source="VUPEN">ADV-2006-0790</ref>
      <ref url="http://evuln.com/vulns/90/summary.html" source="MISC">http://evuln.com/vulns/90/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25167" source="XF">vegasforum-forumlib-sql-injection(25167)</ref>
      <ref url="http://www.securityfocus.com/bid/17079" source="BID">17079</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427470/100/0/threaded" source="BUGTRAQ">20060313 [eVuln] Vegas Forum SQL Injection Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/574" source="SREASON">574</ref>
      <ref url="http://secunia.com/advisories/19219" source="SECUNIA">19219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="johnny_vegas" name="vegas_forum">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1021" published="2006-03-06" name="CVE-2006-1021" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://yns.zaxaz.com/2006/02/28/pehepe-membership-management-system-multiple-vulnerabilities/" source="MISC">http://yns.zaxaz.com/2006/02/28/pehepe-membership-management-system-multiple-vulnerabilities/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0781" source="VUPEN">ADV-2006-0781</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426363/100/0/threaded" source="BUGTRAQ">20060228 PEHEPE Membership Management System Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19055" source="SECUNIA" adv="1">19055</ref>
      <ref url="http://www.securityfocus.com/bid/16885" source="BID">16885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pehepe" name="membership_management_system">
        <vers num="3" />
      </prod>
      <prod vendor="pehepe" name="uyelik_sistemi">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1022" published="2006-03-06" name="CVE-2006-1022" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to include and execute arbitrary PHP code via a URL in the uye_klasor parameter, along with a misafir[] parameter that is set to UYE_SEVIYE.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects PeHePe, Membership Management System (a.k.a Uyelik Sistemi) versions 3.0 and previous.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://yns.zaxaz.com/2006/02/28/pehepe-membership-management-system-multiple-vulnerabilities/" source="MISC" adv="1">http://yns.zaxaz.com/2006/02/28/pehepe-membership-management-system-multiple-vulnerabilities/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0781" source="VUPEN">ADV-2006-0781</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426363/100/0/threaded" source="BUGTRAQ" adv="1">20060228 PEHEPE Membership Management System Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19055" source="SECUNIA" adv="1">19055</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24970" source="XF">pehepe-uyeklasor-command-execution(24970)</ref>
      <ref url="http://www.securityfocus.com/bid/16887" source="BID">16887</ref>
      <ref url="http://www.osvdb.org/23567" source="OSVDB">23567</ref>
      <ref url="http://securityreason.com/securityalert/515" source="SREASON">515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pehepe" name="membership_management_system">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1023" published="2006-03-06" name="CVE-2006-1023" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of HP, System Management Homepage from 2.0.0 through 2.1.4.  This vulnarebility is only present in the following Windows OS environments: Microsoft Windows 2000, 2003, 2003 for x64, 2003 for Itanium and also Windows XP.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00601530" source="HP" patch="1">HPSBMA02099</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426345/100/0/threaded" source="HP" patch="1" adv="1">SSRT061118</ref>
      <ref url="http://securitytracker.com/id?1015692" source="SECTRACK" patch="1" adv="1">1015692</ref>
      <ref url="http://secunia.com/advisories/19059" source="SECUNIA" patch="1" adv="1">19059</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0769" source="VUPEN">ADV-2006-0769</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24996" source="XF">hp-system-managemenet-homepage-dir-traversal(24996)</ref>
      <ref url="http://www.securityfocus.com/bid/16876" source="BID">16876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num="2.0.0" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1024" published="2006-03-06" name="CVE-2006-1024" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of AddSoft, StoreBot 2005 Professional Edition.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24987" source="XF" adv="1">storebot-mgrlogin-sql-injection(24987)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0784" source="VUPEN">ADV-2006-0784</ref>
      <ref url="http://www.securityfocus.com/bid/16897" source="BID">16897</ref>
      <ref url="http://www.osvdb.org/23575" source="OSVDB" adv="1">23575</ref>
      <ref url="http://secunia.com/advisories/19019" source="SECUNIA" adv="1">19019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="addsoft" name="storebot">
        <vers num="2005" edition="" />
        <vers num="2005" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1025" published="2006-03-06" name="CVE-2006-1025" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24986" source="XF" adv="1">storebot-manage-xss(24986)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0785" source="VUPEN">ADV-2006-0785</ref>
      <ref url="http://www.securityfocus.com/bid/16898" source="BID">16898</ref>
      <ref url="http://www.osvdb.org/23574" source="OSVDB" adv="1">23574</ref>
      <ref url="http://secunia.com/advisories/19060" source="SECUNIA" adv="1">19060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="addsoft" name="storebot">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1026" published="2006-03-06" name="CVE-2006-1026" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">JFacets before 0.2 allows remote attackers to gain privileges as any account via a GET request with a modified account profileID.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects JFacets versions prior to 0.2.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24958" source="XF" patch="1" adv="1">jfacets-auth-authentication-bypass(24958)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=154666&amp;release_id=396824" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=154666&amp;release_id=396824</ref>
      <ref url="http://secunia.com/advisories/19031" source="SECUNIA" patch="1" adv="1">19031</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0767" source="VUPEN">ADV-2006-0767</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1439037&amp;group_id=154666&amp;atid=792697" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1439037&amp;group_id=154666&amp;atid=792697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jfacets" name="jfacets">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1027" published="2006-03-06" name="CVE-2006-1027" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via a "/" (slash) in the feed parameter to index.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.joomla.org/content/view/938/78/" source="CONFIRM" patch="1">http://www.joomla.org/content/view/938/78/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426538/100/0/threaded" source="BUGTRAQ" adv="1">20060302 JOOMLA CMS 1.0.7 DoS &amp; path disclosing</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25028" source="XF">joomla-multiple-disclose-path(25028)</ref>
      <ref url="http://www.osvdb.org/23815" source="OSVDB">23815</ref>
      <ref url="http://securityreason.com/securityalert/527" source="SREASON">527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1028" published="2006-03-06" name="CVE-2006-1028" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.joomla.org/content/view/938/78/" source="CONFIRM" patch="1">http://www.joomla.org/content/view/938/78/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426538/100/0/threaded" source="BUGTRAQ" adv="1">20060302 JOOMLA CMS 1.0.7 DoS &amp; path disclosing</ref>
      <ref url="http://www.osvdb.org/23817" source="OSVDB">23817</ref>
      <ref url="http://securityreason.com/securityalert/527" source="SREASON">527</ref>
      <ref url="http://secunia.com/advisories/19105" source="SECUNIA">19105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1029" published="2006-03-06" name="CVE-2006-1029" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The cross-site scripting (XSS) countermeasures in class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause a denial of service via a crafted mosmsg parameter to index.php with a malformed sequence of multiple tags, as demonstrated using "&lt;&lt;&gt;AAA&lt;&gt;&lt;&gt;", possibly due to nested or empty tags.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426538/100/0/threaded" source="BUGTRAQ" adv="1">20060302 JOOMLA CMS 1.0.7 DoS &amp; path disclosing</ref>
      <ref url="http://www.osvdb.org/23816" source="OSVDB">23816</ref>
      <ref url="http://www.joomla.org/content/view/938/78/" source="MISC">http://www.joomla.org/content/view/938/78/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1030" published="2006-03-06" name="CVE-2006-1030" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack vector that reveals the path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.joomla.org/content/view/938/78/" source="CONFIRM" patch="1">http://www.joomla.org/content/view/938/78/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0818" source="VUPEN">ADV-2006-0818</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25028" source="XF">joomla-multiple-disclose-path(25028)</ref>
      <ref url="http://www.osvdb.org/23818" source="OSVDB">23818</ref>
      <ref url="http://secunia.com/advisories/19105" source="SECUNIA">19105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1031" published="2006-03-07" name="CVE-2006-1031" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24935" source="XF">igenus-sg-home-file-include(24935)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0753" source="VUPEN" adv="1">ADV-2006-0753</ref>
      <ref url="http://www.securityfocus.com/bid/16829" source="BID">16829</ref>
      <ref url="http://www.osvdb.org/23530" source="OSVDB">23530</ref>
      <ref url="http://secunia.com/advisories/19036" source="SECUNIA" adv="1">19036</ref>
      <ref url="http://retrogod.altervista.org/igenus_202_xpl_pl.html" source="MISC">http://retrogod.altervista.org/igenus_202_xpl_pl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igenus" name="igenus_webmail">
        <vers num="2.0" />
        <vers num="2.01" />
        <vers num="2.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1032" published="2006-03-07" name="CVE-2006-1032" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0745" source="VUPEN">ADV-2006-0745</ref>
      <ref url="http://www.securityfocus.com/bid/16833" source="BID">16833</ref>
      <ref url="http://www.securityfocus.com/archive/1/426193" source="BUGTRAQ" adv="1">20060226 phpRPC Library Remote Code Execution</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00105-02262006" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00105-02262006</ref>
      <ref url="http://securitytracker.com/id?1015691" source="SECTRACK">1015691</ref>
      <ref url="http://securityreason.com/securityalert/502" source="SREASON">502</ref>
      <ref url="http://secunia.com/advisories/19058" source="SECUNIA">19058</ref>
      <ref url="http://secunia.com/advisories/19028" source="SECUNIA">19028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprpc" name="phprpc">
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1033" published="2006-03-07" name="CVE-2006-1033" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0688" source="VUPEN">ADV-2006-0688</ref>
      <ref url="http://www.securityfocus.com/bid/16784" source="BID">16784</ref>
      <ref url="http://securitytracker.com/id?1015661" source="SECTRACK">1015661</ref>
      <ref url="http://secunia.com/advisories/18940" source="SECUNIA" adv="1">18940</ref>
      <ref url="http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.html" source="MISC" adv="1">http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24843" source="XF">cpg-dragonfly-multiple-xss(24843)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpg-nuke" name="dragonfly_cms">
        <vers num="9.0.1.1" />
        <vers num="9.0.2.0" />
        <vers num="9.0.3.0" />
        <vers num="9.0.4.0" />
        <vers num="9.0.5.0" />
        <vers num="9.0.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1034" published="2006-03-07" name="CVE-2006-1034" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16843" source="BID">16843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="1.1.1" />
        <vers num="2.0_beta_3" />
        <vers num="2.0_beta_4" />
        <vers num="2.0_beta_5" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.2.2" />
        <vers num="2.3.1" />
        <vers num="2.3.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1035" published="2006-03-07" name="CVE-2006-1035" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/298958" source="CERT-VN" adv="1">VU#298958</ref>
      <ref url="http://www.securityfocus.com/bid/16844" source="BID">16844</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf" source="MISC" adv="1">http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf</ref>
      <ref url="http://secunia.com/advisories/19076" source="SECUNIA">19076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="diagnostics">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
        <vers num="11.5.10.1" />
        <vers num="11.5.10.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1036" published="2006-03-07" name="CVE-2006-1036" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to "permissions."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16844" source="BID" patch="1">16844</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf" source="MISC" patch="1" adv="1">http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf</ref>
      <ref url="http://secunia.com/advisories/19076" source="SECUNIA">19076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="diagnostics">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1037" published="2006-03-07" name="CVE-2006-1037" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via uknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16844" source="BID">16844</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf" source="MISC" adv="1">http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25259" source="XF">oracle-diagnostics-sql-injection(25259)</ref>
      <ref url="http://secunia.com/advisories/19076" source="SECUNIA">19076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="diagnostics">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
        <vers num="11.5.10.1" />
        <vers num="11.5.10.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1038" published="2006-03-07" name="CVE-2006-1038" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19040" source="SECUNIA" patch="1" adv="1">19040</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0806" source="VUPEN">ADV-2006-0806</ref>
      <ref url="http://www.vandyke.com/products/securecrt/history.txt" source="CONFIRM">http://www.vandyke.com/products/securecrt/history.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25092" source="XF">securecrt-securefx-string-bo(25092)</ref>
      <ref url="http://www.vandyke.com/products/securefx/history.txt" source="CONFIRM">http://www.vandyke.com/products/securefx/history.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16935" source="BID">16935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="van_dyke_technologies" name="securecrt">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0_beta_1" />
        <vers num="5.0_beta_2" />
        <vers num="5.0_beta_3" />
        <vers num="5.0_beta_4" />
        <vers num="5.0_beta_5" />
        <vers num="5.0_beta_6" />
      </prod>
      <prod vendor="van_dyke_technologies" name="securefx">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0_beta_1" />
        <vers num="3.0_beta_2" />
        <vers num="3.0_beta_3" />
        <vers num="3.0_beta_4" />
        <vers num="3.0_beta_5" />
        <vers num="3.0_beta_6" />
        <vers num="3.0_beta_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1039" published="2006-03-07" name="CVE-2006-1039" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25003" source="XF">sap-was-url-obtain-information(25003)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0810" source="VUPEN" adv="1">ADV-2006-0810</ref>
      <ref url="http://www.securityfocus.com/bid/18006" source="BID">18006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426449/100/0/threaded" source="BUGTRAQ">20060301 SAP Web Application Server http request url parsing vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015702" source="SECTRACK">1015702</ref>
      <ref url="http://secunia.com/advisories/19085" source="SECUNIA" adv="1">19085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_web_application_server">
        <vers num="6.10" />
        <vers num="6.20" />
        <vers num="6.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1040" published="2006-03-07" name="CVE-2006-1040" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of Jelsoft, vBulletin between 3.0.12 and 3.5.3</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kapda.ir/advisory-266.html" source="MISC" patch="1" adv="1">http://www.kapda.ir/advisory-266.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0808" source="VUPEN">ADV-2006-0808</ref>
      <ref url="http://www.vbulletin.com/forum/showthread.php?postid=1079030" source="CONFIRM">http://www.vbulletin.com/forum/showthread.php?postid=1079030</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426589/100/0/threaded" source="BUGTRAQ">20060302 vBulletin3.0.12&amp;3.5.3~is_valid_email()~XSS Attack</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426537/100/0/threaded" source="BUGTRAQ" adv="1">20060301 [KAPDA::#26]vBulletin.3.5.3~3.0.12-XSS</ref>
      <ref url="http://www.osvdb.org/23614" source="OSVDB">23614</ref>
      <ref url="http://secunia.com/advisories/19100" source="SECUNIA">19100</ref>
      <ref url="http://www.securityfocus.com/bid/16919" source="BID">16919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.12" />
        <vers num="3.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1041" published="2006-03-07" name="CVE-2006-1041" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gregarius 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_query parameter to search.php or (2) tag parameter to tags.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426656/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060303 Gregarius 0.5.2 XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0819" source="VUPEN">ADV-2006-0819</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25058" source="XF">gregarius-multiple-xss(25058)</ref>
      <ref url="http://www.securityfocus.com/bid/16939" source="BID">16939</ref>
      <ref url="http://www.osvdb.org/23679" source="OSVDB">23679</ref>
      <ref url="http://www.osvdb.org/23678" source="OSVDB">23678</ref>
      <ref url="http://secunia.com/advisories/19102" source="SECUNIA">19102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gregarius" name="gregarius">
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1042" published="2006-03-07" name="CVE-2006-1042" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Gregarius 0.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) folder parameter to feed.php or (2) rss_query parameter to search.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426656/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060303 Gregarius 0.5.2 XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0819" source="VUPEN">ADV-2006-0819</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25059" source="XF">gregarius-feed-sql-injection(25059)</ref>
      <ref url="http://www.securityfocus.com/bid/16939" source="BID">16939</ref>
      <ref url="http://www.osvdb.org/23681" source="OSVDB">23681</ref>
      <ref url="http://www.osvdb.org/23680" source="OSVDB">23680</ref>
      <ref url="http://securityreason.com/securityalert/537" source="SREASON">537</ref>
      <ref url="http://secunia.com/advisories/19102" source="SECUNIA">19102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gregarius" name="gregarius">
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1043" published="2006-03-07" name="CVE-2006-1043" modified="2011-08-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25148" source="XF">visualstudio-dataproject-bo(25148)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0825" source="VUPEN" adv="1">ADV-2006-0825</ref>
      <ref url="http://www.securityfocus.com/bid/16953" source="BID">16953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426830/100/0/threaded" source="BUGTRAQ">20060305 Microsoft Visual Studio 6.0 Sp6 Malformed .dbp File BoF Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426767/100/0/threaded" source="BUGTRAQ" adv="1">20060304 Visual Studio 6.0 Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/23711" source="OSVDB">23711</ref>
      <ref url="http://www.frsirt.com/exploits/20060305.ms-visual-dbp.c.php" source="MISC" adv="1">http://www.frsirt.com/exploits/20060305.ms-visual-dbp.c.php</ref>
      <ref url="http://securitytracker.com/id?1015721" source="SECTRACK" adv="1">1015721</ref>
      <ref url="http://secunia.com/advisories/19081" source="SECUNIA" adv="1">19081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_interdev">
        <vers num="6.0" />
      </prod>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1044" published="2006-03-07" name="CVE-2006-1044" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI.  NOTE: technical details will be released after the grace period has ended on 20060603.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects L-Soft, Listserv (LITE and HPO) 14.4 and all prior versions that are installed with the web archive interface.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/841132" source="CERT-VN">VU#841132</ref>
      <ref url="http://www.securityfocus.com/bid/16951" source="BID" patch="1">16951</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426770/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060304 Critical Risk Vulnerability in L-Soft Listserv</ref>
      <ref url="http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalert" source="CONFIRM" patch="1">http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalert</ref>
      <ref url="http://securitytracker.com/id?1015722" source="SECTRACK" patch="1" adv="1">1015722</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0824" source="VUPEN">ADV-2006-0824</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25168" source="XF">listserv-wa-cgi-bo(25168)</ref>
      <ref url="http://www.ngssoftware.com/advisories/listserv_3.txt" source="MISC">http://www.ngssoftware.com/advisories/listserv_3.txt</ref>
      <ref url="http://secunia.com/advisories/19106" source="SECUNIA">19106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lsoft" name="listserv">
        <vers num="14.3" />
        <vers num="14.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1045" published="2006-03-07" name="CVE-2006-1045" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/bid/16881" source="BID">16881</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/426347" source="BUGTRAQ">20060228 Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10254" source="OVAL">oval:org.mitre.oval:def:10254</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24959" source="XF">thunderbird-inline-information-disclosure(24959)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-26.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-26.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://securityreason.com/securityalert/514" source="SREASON">514</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1975" source="OVAL" sig="1">oval:org.mitre.oval:def:1975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1046" published="2006-03-07" name="CVE-2006-1046" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19133" source="SECUNIA" patch="1" adv="1">19133</ref>
      <ref url="http://aluigi.altervista.org/adv/monopdx-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/monopdx-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0844" source="VUPEN">ADV-2006-0844</ref>
      <ref url="http://www.securityfocus.com/bid/16981" source="BID">16981</ref>
      <ref url="http://www.robertjohnkaper.com/downloads/atlantik/monopd-0.9.3-dosfix.diff" source="CONFIRM">http://www.robertjohnkaper.com/downloads/atlantik/monopd-0.9.3-dosfix.diff</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25161" source="XF">monopd-string-dos(25161)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monopd" name="monopd">
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1047" published="2006-03-07" name="CVE-2006-1047" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.joomla.org/content/view/938/78/" source="CONFIRM">http://www.joomla.org/content/view/938/78/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1048" published="2006-03-07" name="CVE-2006-1048" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3) Newsfeeds, (4) Weblinks, (5) Content, (6) Content Section, (7) Content Category, (8) Contact items, or (9) Contact Search, (10) Content Search, (11) Newsfeed Search, or (12) Weblink Search.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Joomla! versions 1.0.7 and previous.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25033" source="XF" patch="1">joomla-multiple-bypass-security(25033)</ref>
      <ref url="http://www.joomla.org/content/view/938/78/" source="CONFIRM" patch="1">http://www.joomla.org/content/view/938/78/</ref>
      <ref url="http://secunia.com/advisories/19105" source="SECUNIA" patch="1" adv="1">19105</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0818" source="VUPEN">ADV-2006-0818</ref>
      <ref url="http://www.osvdb.org/23822" source="OSVDB">23822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1049" published="2006-03-07" name="CVE-2006-1049" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19105" source="SECUNIA" patch="1" adv="1">19105</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0818" source="VUPEN" adv="1">ADV-2006-0818</ref>
      <ref url="http://www.osvdb.org/23819" source="OSVDB">23819</ref>
      <ref url="http://www.joomla.org/content/view/938/78/" source="CONFIRM">http://www.joomla.org/content/view/938/78/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1050" published="2006-03-07" name="CVE-2006-1050" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">** DISPUTED **  Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the vendor has disputed this vulnerability, stating that "The kwikpay.mdb file supplied with kwikpay is a template for the database structure of user databases created by kwikpay and to store a demonstration payroll. It does not contain any sensitive user information.  When a user payroll database is opened, the encryption of the database is checked and if the database is not encrypted, the user is prompted to encrypt the database, but the choice is the customers."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25114" source="XF">kwikpay-payroll-insecure-permissions(25114)</ref>
      <ref url="http://www.osvdb.org/23617" source="OSVDB">23617</ref>
      <ref url="http://secunia.com/advisories/19075" source="SECUNIA" adv="1">19075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kwik-pay" name="kwik-pay_payroll">
        <vers num="4.2.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1051" published="2006-03-07" name="CVE-2006-1051" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16989" source="BID" patch="1">16989</ref>
      <ref url="http://secunia.com/advisories/19112" source="SECUNIA" patch="1" adv="1">19112</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0841" source="VUPEN">ADV-2006-0841</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=398713&amp;group_id=155783" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=398713&amp;group_id=155783</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25115" source="XF">akarru-users-sql-injection(25115)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="akarru" name="social_bookmarking_engine">
        <vers num="0.4.3.2" />
        <vers num="0.4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1052" published="2006-05-05" name="CVE-2006-1052" modified="2010-08-21" discovered="2006-03-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17830" source="BID" patch="1">17830</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA" patch="1" adv="1">19955</ref>
      <ref url="http://marc.theaimsgroup.com/?l=selinux&amp;m=114226465106131&amp;w=2" source="MLIST" patch="1">[selinux] 20060313 [SECURITY] SELinux ptrace bug (CVE-2006-1052)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://selinuxnews.org/wp/index.php/2006/03/13/security-ptrace-bug-cve-2006-1052/" source="MISC">http://selinuxnews.org/wp/index.php/2006/03/13/security-ptrace-bug-cve-2006-1052/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10102" source="OVAL">oval:org.mitre.oval:def:10102</ref>
      <ref url="http://marc.theaimsgroup.com/?l=git-commits-head&amp;m=114210002712363&amp;w=2" source="MLIST">[git-commits-head] 20060311 [PATCH] selinux: tracer SID fix</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.osvdb.org/25232" source="OSVDB">25232</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086" source="MANDRIVA">MDKSA-2006:086</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1184" source="DEBIAN">DSA-1184</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/22093" source="SECUNIA">22093</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20157" source="SECUNIA">20157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="" />
        <vers num="2.6.0" edition=":64-bit_x86" />
        <vers num="2.6.0" edition=":itanium_ia64_montecito" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="" />
        <vers num="2.6.11" edition=":x86_64" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16_rc7" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="final" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-1054" reject="1" published="2006-05-26" name="CVE-2006-1054" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1861.  Reason: This candidate is a reservation duplicate of CVE-2006-1861.  Notes: All CVE users should reference CVE-2006-1861 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1055" published="2006-04-05" name="CVE-2006-1055" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causing an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6e0dd741a89be35defa05bd79f4211c5a2762825;hp=597a7679dd83691be2f3a53e1f3f915b4a7f6eba" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6e0dd741a89be35defa05bd79f4211c5a2762825;hp=597a7679dd83691be2f3a53e1f3f915b4a7f6eba</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6e0dd741a89be35defa05bd79f4211c5a2762825" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6e0dd741a89be35defa05bd79f4211c5a2762825</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1475" source="VUPEN">ADV-2006-1475</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1273" source="VUPEN">ADV-2006-1273</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25693" source="XF">linux-fillwritebuffer-dos(25693)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0020" source="TRUSTIX">2006-0020</ref>
      <ref url="http://www.securityfocus.com/bid/17402" source="BID">17402</ref>
      <ref url="http://www.osvdb.org/24443" source="OSVDB">24443</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA">19955</ref>
      <ref url="http://secunia.com/advisories/19735" source="SECUNIA">19735</ref>
      <ref url="http://secunia.com/advisories/19495" source="SECUNIA">19495</ref>
      <ref url="http://lwn.net/Alerts/180820/" source="FEDORA">FEDORA-2006-423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1056" published="2006-04-20" name="CVE-2006-1056" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to Linux Kernel version 2.6.16.9 :
http://www.kernel.org/</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17600" source="BID" patch="1">17600</ref>
      <ref url="http://secunia.com/advisories/19724" source="SECUNIA" patch="1" adv="1">19724</ref>
      <ref url="http://secunia.com/advisories/19715" source="SECUNIA" patch="1" adv="1">19715</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187911" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187911</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187910" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187910</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25871" source="XF">amd-fpu-information-disclosure(25871)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN" adv="1">ADV-2006-4502</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4353" source="VUPEN" adv="1">ADV-2006-4353</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN" adv="1">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1475" source="VUPEN" adv="1">ADV-2006-1475</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1426" source="VUPEN" adv="1">ADV-2006-1426</ref>
      <ref url="http://www.vmware.com/download/esx/esx-254-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-254-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-213-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-213-200610-patch.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451421/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0009 - VMware ESX Server 3.0.0 AMD fxsave/restore issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0579.html" source="REDHAT">RHSA-2006:0579</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0437.html" source="REDHAT">RHSA-2006:0437</ref>
      <ref url="http://www.osvdb.org/24807" source="OSVDB">24807</ref>
      <ref url="http://www.osvdb.org/24746" source="OSVDB">24746</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm</ref>
      <ref url="http://securitytracker.com/id?1015966" source="SECTRACK">1015966</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt" source="MISC">http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt</ref>
      <ref url="http://secunia.com/advisories/22876" source="SECUNIA" adv="1">22876</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA" adv="1">22875</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA" adv="1">22417</ref>
      <ref url="http://secunia.com/advisories/21983" source="SECUNIA" adv="1">21983</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA" adv="1">21465</ref>
      <ref url="http://secunia.com/advisories/21136" source="SECUNIA" adv="1">21136</ref>
      <ref url="http://secunia.com/advisories/21035" source="SECUNIA" adv="1">21035</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA" adv="1">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA" adv="1">20716</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA" adv="1">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA" adv="1">20398</ref>
      <ref url="http://secunia.com/advisories/19735" source="SECUNIA" adv="1">19735</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9995" source="OVAL">oval:org.mitre.oval:def:9995</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=114548768214478&amp;w=2" source="MLIST">[linux-kernel] 20060419 RE: Linux 2.6.16.9</ref>
      <ref url="http://lwn.net/Alerts/180820/" source="FEDORA">FEDORA-2006-423</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9</ref>
      <ref url="http://kb.vmware.com/kb/2533126" source="CONFIRM">http://kb.vmware.com/kb/2533126</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:14.fpu.asc" source="FREEBSD">FreeBSD-SA-06:14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.16" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers prev="1" num="2.6.16.8" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16_rc7" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="final" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1057" published="2006-04-24" name="CVE-2006-1057" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-announce-list/2006-April/msg00160.html" source="FEDORA" patch="1">FEDORA-2006-338</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1040" source="DEBIAN" patch="1" adv="1">DSA-1040</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188303" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188303</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26092" source="XF">gdm-slavec-symlink(26092)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1465" source="VUPEN" adv="1">ADV-2006-1465</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-278-1" source="UBUNTU">USN-278-1</ref>
      <ref url="http://www.securityfocus.com/bid/17635" source="BID">17635</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0286.html" source="REDHAT">RHSA-2007:0286</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:083" source="MANDRIVA">MDKSA-2006:083</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10092" source="OVAL">oval:org.mitre.oval:def:10092</ref>
      <ref url="http://cvs.gnome.org/viewcvs/gdm2/daemon/slave.c?r1=1.260&amp;r2=1.261" source="CONFIRM">http://cvs.gnome.org/viewcvs/gdm2/daemon/slave.c?r1=1.260&amp;r2=1.261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1058" published="2006-04-04" name="CVE-2006-1058" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25569" source="XF">busybox-passwd-weak-security(25569)</ref>
      <ref url="http://www.securityfocus.com/bid/17330" source="BID">17330</ref>
      <ref url="http://secunia.com/advisories/19477" source="SECUNIA" adv="1">19477</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9483" source="OVAL">oval:org.mitre.oval:def:9483</ref>
      <ref url="http://bugs.busybox.net/view.php?id=604" source="CONFIRM">http://bugs.busybox.net/view.php?id=604</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0244.html" source="REDHAT">RHSA-2007:0244</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-250.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-250.htm</ref>
      <ref url="http://secunia.com/advisories/25848" source="SECUNIA">25848</ref>
      <ref url="http://secunia.com/advisories/25098" source="SECUNIA">25098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="busybox" name="busybox">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1059" published="2006-03-30" name="CVE-2006-1059" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429370/100/0/threaded" source="BUGTRAQ" patch="1">20060330 [SECURITY] Samba 3.0.21-3.0.21c: Exposure of machine account credentials in winbindd log files</ref>
      <ref url="http://us1.samba.org/samba/security/CAN-2006-1059.html" source="CONFIRM" patch="1">http://us1.samba.org/samba/security/CAN-2006-1059.html</ref>
      <ref url="http://secunia.com/advisories/19455" source="SECUNIA" patch="1" adv="1">19455</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25575" source="XF">samba-logfile-account-cleartext(25575)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1179" source="VUPEN">ADV-2006-1179</ref>
      <ref url="http://www.trustix.org/errata/2006/0018" source="TRUSTIX">2006-0018</ref>
      <ref url="http://www.securityfocus.com/bid/17314" source="BID">17314</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00114.html" source="FEDORA">FEDORA-2006-259</ref>
      <ref url="http://www.osvdb.org/24263" source="OSVDB">24263</ref>
      <ref url="http://securitytracker.com/id?1015850" source="SECTRACK">1015850</ref>
      <ref url="http://secunia.com/advisories/19539" source="SECUNIA">19539</ref>
      <ref url="http://secunia.com/advisories/19468" source="SECUNIA">19468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1060" published="2006-04-11" name="CVE-2006-1060" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19779" source="SECUNIA" patch="1" adv="1">19779</ref>
      <ref url="http://secunia.com/advisories/19757" source="SECUNIA" patch="1" adv="1">19757</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25718" source="XF">xzgv-jpeg-bo(25718)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1288" source="VUPEN" adv="1">ADV-2006-1288</ref>
      <ref url="http://www.securityfocus.com/bid/17409" source="BID">17409</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_sr.html" source="SUSE">SUSE-SR:2006:008</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1038" source="DEBIAN">DSA-1038</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1037" source="DEBIAN">DSA-1037</ref>
      <ref url="http://securityreason.com/securityalert/756" source="SREASON">756</ref>
      <ref url="http://secunia.com/advisories/19790" source="SECUNIA" adv="1">19790</ref>
      <ref url="http://secunia.com/advisories/19731" source="SECUNIA" adv="1">19731</ref>
      <ref url="http://secunia.com/advisories/19572" source="SECUNIA" adv="1">19572</ref>
      <ref url="http://secunia.com/advisories/19571" source="SECUNIA" adv="1">19571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xzgv" name="xzgv">
        <vers prev="1" num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1061" published="2006-03-20" name="CVE-2006-1061" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 7.15.3.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19271" source="SECUNIA" patch="1" adv="1">19271</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1008" source="VUPEN">ADV-2006-1008</ref>
      <ref url="http://curl.haxx.se/docs/adv_20060320.html" source="CONFIRM">http://curl.haxx.se/docs/adv_20060320.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25318" source="XF">curl-tftp-bo(25318)</ref>
      <ref url="http://www.trustix.org/errata/2006/0016" source="TRUSTIX">2006-0016</ref>
      <ref url="http://www.securityfocus.com/bid/17154" source="BID">17154</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00048.html" source="FEDORA">FEDORA-2006-189</ref>
      <ref url="http://www.osvdb.org/23982" source="OSVDB">23982</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-19.xml" source="GENTOO">GLSA-200603-19</ref>
      <ref url="http://secunia.com/advisories/19371" source="SECUNIA">19371</ref>
      <ref url="http://secunia.com/advisories/19344" source="SECUNIA">19344</ref>
      <ref url="http://secunia.com/advisories/19335" source="SECUNIA">19335</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1326.html" source="FULLDISC">20060320 [SSAG#001] :: cURL tftp:// URL Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_stenberg" name="curl">
        <vers num="7.15.0" />
        <vers num="7.15.1" />
        <vers num="7.15.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1062" published="2006-03-07" name="CVE-2006-1062" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of Lurker from 0.1a through 0.2</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168</ref>
      <ref url="http://secunia.com/advisories/19136" source="SECUNIA" patch="1" adv="1">19136</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0850" source="VUPEN">ADV-2006-0850</ref>
      <ref url="http://terpstra.ca/lurker/message/20060302.130003.4c5c2680.en.html" source="MLIST" adv="1">[Lurker-users] 20060302 Serious security vulnerabilities found</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25149" source="XF">lurker-lurker-information-disclosure(25149)</ref>
      <ref url="http://www.securityfocus.com/bid/17003" source="BID">17003</ref>
      <ref url="http://www.osvdb.org/23694" source="OSVDB">23694</ref>
      <ref url="http://www.debian.org/security/2006/dsa-999" source="DEBIAN">DSA-999</ref>
      <ref url="http://secunia.com/advisories/19145" source="SECUNIA">19145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lurker" name="lurker">
        <vers num="0.1a" />
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1063" published="2006-03-07" name="CVE-2006-1063" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox".</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnarability affects all verions of Lurker from 0.1a through 0.2
</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168</ref>
      <ref url="http://secunia.com/advisories/19136" source="SECUNIA" patch="1" adv="1">19136</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0850" source="VUPEN">ADV-2006-0850</ref>
      <ref url="http://terpstra.ca/lurker/message/20060302.130003.4c5c2680.en.html" source="MLIST" adv="1">[Lurker-users] 20060302 Serious security vulnerabilities found</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25153" source="XF">lurker-mbox-error(25153)</ref>
      <ref url="http://www.securityfocus.com/bid/17003" source="BID">17003</ref>
      <ref url="http://www.osvdb.org/23695" source="OSVDB">23695</ref>
      <ref url="http://www.debian.org/security/2006/dsa-999" source="DEBIAN">DSA-999</ref>
      <ref url="http://secunia.com/advisories/19145" source="SECUNIA">19145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lurker" name="lurker">
        <vers num="0.1a" />
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1064" published="2006-03-07" name="CVE-2006-1064" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all verions of Lurker from 0.1a through 2.0</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168</ref>
      <ref url="http://secunia.com/advisories/19136" source="SECUNIA" patch="1" adv="1">19136</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0850" source="VUPEN">ADV-2006-0850</ref>
      <ref url="http://terpstra.ca/lurker/message/20060302.130003.4c5c2680.en.html" source="MLIST" adv="1">[Lurker-users] 20060302 Serious security vulnerabilities found</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25154" source="XF">lurker-unspecified-xss(25154)</ref>
      <ref url="http://www.securityfocus.com/bid/17003" source="BID">17003</ref>
      <ref url="http://www.osvdb.org/23696" source="OSVDB">23696</ref>
      <ref url="http://www.debian.org/security/2006/dsa-999" source="DEBIAN">DSA-999</ref>
      <ref url="http://secunia.com/advisories/19145" source="SECUNIA">19145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lurker" name="lurker">
        <vers num="0.1a" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1065" published="2006-03-07" name="CVE-2006-1065" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25018" source="XF">mybb-search-sql-injection(25018)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426631/100/0/threaded" source="BUGTRAQ" adv="1">20060302 MyBB 1.0.4 New SQL Injection</ref>
      <ref url="http://secunia.com/advisories/19061" source="SECUNIA" adv="1">19061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1066" published="2006-03-26" name="CVE-2006-1066" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17216" source="BID" patch="1">17216</ref>
      <ref url="http://www.osvdb.org/24098" source="OSVDB" patch="1">24098</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA" patch="1" adv="1">19374</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN" adv="1">DSA-1017</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113932292516359&amp;w=2" source="MLIST">[linux-kernel] 20060207 [PATCH] arch/x86_64/kernel/traps.c PTRACE_SINGLESTEP oops</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:151" source="MANDRIVA">MDKSA-2006:151</ref>
      <ref url="http://secunia.com/advisories/21614" source="SECUNIA">21614</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA">19955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1067" published="2006-03-07" name="CVE-2006-1067" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426934/100/0/threaded" source="BUGTRAQ">20060306 RE: linksys router + irc DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426761/100/0/threaded" source="BUGTRAQ">20060303 linksys router + irc DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426756/100/0/threaded" source="BUGTRAQ">20060304 Various router DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/426863/100/0/threaded" source="BUGTRAQ">20060306 Re: linksys router + irc DoS</ref>
      <ref url="http://www.hm2k.org/news/1141413208.html" source="MISC">http://www.hm2k.org/news/1141413208.html </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25230" source="XF">multiple-vendor-dccsend-dos(25230)</ref>
      <ref url="http://www.securityfocus.com/bid/16954" source="BID">16954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wrt54g_v5">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1068" published="2006-03-07" name="CVE-2006-1068" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Netgear 614 and 624 routers, possibly running VXWorks, allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may affects NetGear Router models 614 and 624 (including WGR614, WGT624, WGT624SC, WGU624, and possibly others) and is most likely related to VXWorks.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426934/100/0/threaded" source="BUGTRAQ" adv="1">20060306 RE: linksys router + irc DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426761/100/0/threaded" source="BUGTRAQ" adv="1">20060303 linksys router + irc DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426756/100/0/threaded" source="BUGTRAQ" adv="1">20060304 Various router DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/426863/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Re: linksys router + irc DoS</ref>
      <ref url="http://www.hm2k.org/news/1141413208.html" source="MISC">http://www.hm2k.org/news/1141413208.html </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25230" source="XF">multiple-vendor-dccsend-dos(25230)</ref>
      <ref url="http://www.securityfocus.com/bid/16954" source="BID">16954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="netgear_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1069" published="2006-03-07" name="CVE-2006-1069" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.geeklog.net/article.php/geeklog-1.4.0sr2" source="CONFIRM" patch="1">http://www.geeklog.net/article.php/geeklog-1.4.0sr2</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0851" source="VUPEN">ADV-2006-0851</ref>
      <ref url="http://www.securityfocus.com/bid/17010" source="BID">17010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geeklog" name="geeklog">
        <vers num="1.3.11" />
        <vers num="1.3.11_sr1" />
        <vers num="1.3.11_sr2" />
        <vers num="1.3.11_sr3" />
        <vers num="1.3.11_sr4" />
        <vers num="1.3.9" />
        <vers num="1.3.9_sr1" />
        <vers num="1.3.9_sr2" />
        <vers num="1.3.9_sr3" />
        <vers num="1.3.9_sr4" />
        <vers num="1.4.0" />
        <vers num="1.4.0_sr1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1070" published="2006-03-07" name="CVE-2006-1070" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0842" source="VUPEN">ADV-2006-0842</ref>
      <ref url="http://www.securityfocus.com/bid/16968" source="BID">16968</ref>
      <ref url="http://secunia.com/advisories/19098" source="SECUNIA" adv="1">19098</ref>
      <ref url="http://biyosecurity.be/bugs/dvguestbook.txt" source="MISC">http://biyosecurity.be/bugs/dvguestbook.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25049" source="XF">dvguestbook-index-dvgbook-xss(25049)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427214/100/0/threaded" source="BUGTRAQ">20060309 DVguestbook 1.0 And 1.2.2 Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dvguestbook" name="dvguestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1071" published="2006-03-07" name="CVE-2006-1071" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0843" source="VUPEN">ADV-2006-0843</ref>
      <ref url="http://www.securityfocus.com/bid/16968" source="BID">16968</ref>
      <ref url="http://biyosecurity.be/bugs/dvguestbook.txt" source="MISC">http://biyosecurity.be/bugs/dvguestbook.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25049" source="XF">dvguestbook-index-dvgbook-xss(25049)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427214/100/0/threaded" source="BUGTRAQ">20060309 DVguestbook 1.0 And 1.2.2 Cross Site Scripting</ref>
      <ref url="http://secunia.com/advisories/19099" source="SECUNIA">19099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dvguestbook" name="dvguestbook">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1072" published="2006-03-07" name="CVE-2006-1072" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16965" source="BID">16965</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426769/100/0/threaded" source="BUGTRAQ">20060304 Simplog &lt;= 1.0.2 Vulnerabilities</ref>
      <ref url="http://notlegal.ws/simplogsploit.txt" source="MISC">http://notlegal.ws/simplogsploit.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25066" source="XF">simplog-post-xss(25066)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1073" published="2006-03-07" name="CVE-2006-1073" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0839" source="VUPEN">ADV-2006-0839</ref>
      <ref url="http://www.securityfocus.com/bid/16965" source="BID">16965</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426769/100/0/threaded" source="BUGTRAQ">20060304 Simplog &lt;= 1.0.2 Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19115" source="SECUNIA" adv="1">19115</ref>
      <ref url="http://notlegal.ws/simplogsploit.txt" source="MISC">http://notlegal.ws/simplogsploit.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25067" source="XF">simplog-index-traverse-directories(25067)</ref>
      <ref url="http://securityreason.com/securityalert/542" source="SREASON">542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1074" published="2006-03-08" name="CVE-2006-1074" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0849" source="VUPEN">ADV-2006-0849</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426864/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Liero Xtreme 0.62b</ref>
      <ref url="http://aluigi.altervista.org/adv/lieroxxx-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/lieroxxx-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25185" source="XF">liero-connect-dos(25185)</ref>
      <ref url="http://www.securityfocus.com/bid/16992" source="BID">16992</ref>
      <ref url="http://secunia.com/advisories/19079" source="SECUNIA">19079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_boettcher" name="liero_xtreme">
        <vers num="0.56b_pack_1.7" />
        <vers num="0.62b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1075" published="2006-03-08" name="CVE-2006-1075" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in a level (aka .lxl) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0849" source="VUPEN">ADV-2006-0849</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426864/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Liero Xtreme 0.62b</ref>
      <ref url="http://aluigi.altervista.org/adv/lieroxxx-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/lieroxxx-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25187" source="XF">liero-visualization-format-string(25187)</ref>
      <ref url="http://www.securityfocus.com/bid/16990" source="BID">16990</ref>
      <ref url="http://securityreason.com/securityalert/549" source="SREASON">549</ref>
      <ref url="http://secunia.com/advisories/19079" source="SECUNIA">19079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_boettcher" name="liero_xtreme">
        <vers num="0.56b_pack_1.7" />
        <vers num="0.62b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1076" published="2006-03-08" name="CVE-2006-1076" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16971" source="BID">16971</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426875/100/0/threaded" source="BUGTRAQ">20060306 SQL injection in Invision Power Board v2.1.5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25254" source="XF">invision-index-sql-injection(25254)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430357/100/0/threaded" source="BUGTRAQ">20060405 Re: SQL injection in Invision Power Board v2.1.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1077" published="2006-03-08" name="CVE-2006-1077" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16983" source="BID">16983</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426826/100/0/threaded" source="BUGTRAQ">20060306 evoBlog Remote Name tag Script injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431869/100/0/threaded" source="BUGTRAQ">20060423 Re: evoBlog Remote Name tag Script injection</ref>
      <ref url="http://www.osvdb.org/23826" source="OSVDB">23826</ref>
      <ref url="http://securityreason.com/securityalert/544" source="SREASON">544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evo-dev" name="evoblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1078" published="2006-03-08" name="CVE-2006-1078" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file.  NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE.  However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16972" source="BID">16972</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426823/100/0/threaded" source="BUGTRAQ">20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114154083000296&amp;w=2" source="MLIST">[thttpd] 20060305 Re: htpasswd.c security issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114153031201867&amp;w=2" source="MLIST">[thttpd] 20060305 htpasswd.c security issues</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31236" source="XF">apache-htpasswd-strcpy-bo(31236)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25216" source="XF">thttpd-command-file-bo(25216)</ref>
      <ref url="http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html" source="FULLDISC">20041029 Apache 1.3.33 local buffer overflow in apache 1.3.31 not fixed in .33?</ref>
      <ref url="http://seclists.org/bugtraq/2004/Oct/0359.html" source="BUGTRAQ">20041029 Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html" source="FULLDISC">20070102 Apache 1.3.37 htpasswd buffer overflow vulnerability</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=41279" source="MISC">http://issues.apache.org/bugzilla/show_bug.cgi?id=41279</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=31975" source="MISC">http://issues.apache.org/bugzilla/show_bug.cgi?id=31975</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html" source="FULLDISC">20040916 FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="thttpd">
        <vers num="2.25b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1079" published="2006-03-08" name="CVE-2006-1079" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function.  NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE.  However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16972" source="BID">16972</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426823/100/0/threaded" source="BUGTRAQ">20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.</ref>
      <ref url="http://www.osvdb.org/23828" source="OSVDB">23828</ref>
      <ref url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114154083000296&amp;w=2" source="MLIST">[thttpd] 20060305 Re: htpasswd.c security issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114153031201867&amp;w=2" source="MLIST">[thttpd] 20060305 htpasswd.c security issues</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25217" source="XF">thttpd-command-line-bo(25217)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="thttpd">
        <vers num="2.25b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1080" published="2006-03-08" name="CVE-2006-1080" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0864" source="VUPEN">ADV-2006-0864</ref>
      <ref url="http://www.securityfocus.com/bid/16979" source="BID">16979</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426825/100/0/threaded" source="BUGTRAQ">20060304 Game-Panel &lt;= 2.1.6 XSS</ref>
      <ref url="http://notlegal.ws/gamepanel.txt" source="MISC">http://notlegal.ws/gamepanel.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25144" source="XF">gamepanel-login-xss(25144)</ref>
      <ref url="http://secunia.com/advisories/19143" source="SECUNIA">19143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="game-panel" name="game-panel">
        <vers num="2.6" />
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1081" published="2006-03-08" name="CVE-2006-1081" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25017" source="XF">nexus-forgottenpassword-sql-injection(25017)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0809" source="VUPEN">ADV-2006-0809</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426575/100/0/threaded" source="BUGTRAQ" adv="1">20060302 PluggedOut Nexus SQL injection</ref>
      <ref url="http://secunia.com/advisories/19089" source="SECUNIA" adv="1">19089</ref>
      <ref url="http://hamid.ir/security/nexus.txt" source="MISC" adv="1">http://hamid.ir/security/nexus.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16915" source="BID">16915</ref>
      <ref url="http://securitytracker.com/id?1015715" source="SECTRACK">1015715</ref>
      <ref url="http://securityreason.com/securityalert/536" source="SREASON">536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jonathan_beckett" name="pluggedout_nexus">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1082" published="2006-03-08" name="CVE-2006-1082" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4) cell_title_background_color and (5) browse_cat_name parameters in browse.php, the (6) gamefile parameter in displaygame.php, and (7) possibly other parameters in unspecified PHP scripts.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0821" source="VUPEN">ADV-2006-0821</ref>
      <ref url="http://www.securityfocus.com/bid/16957" source="BID">16957</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426755/100/0/threaded" source="BUGTRAQ">20060304 phpArcadeScript XSS Injections</ref>
      <ref url="http://secunia.com/advisories/19124" source="SECUNIA" adv="1">19124</ref>
      <ref url="http://securityreason.com/securityalert/533" source="SREASON">533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phparcadescript" name="phparcadescript">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1083" published="2006-03-08" name="CVE-2006-1083" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other parameters, to (a) admin.php and (b) other unspecified scripts.  NOTE: the admin.php/option[language] vector can be used by remote unauthenticated attackers to include arbitrary files in conjunction with CVE-2006-1085.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0822" source="VUPEN">ADV-2006-0822</ref>
      <ref url="http://www.securityfocus.com/bid/16963" source="BID">16963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded" source="BUGTRAQ">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.phpstats.net/forum/viewtopic.php?t=140" source="MISC">http://www.phpstats.net/forum/viewtopic.php?t=140</ref>
      <ref url="http://secunia.com/advisories/19116" source="SECUNIA" adv="1">19116</ref>
      <ref url="http://retrogod.altervista.org/php_stats_0191_adv.html" source="MISC">http://retrogod.altervista.org/php_stats_0191_adv.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded" source="BUGTRAQ">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded" source="BUGTRAQ">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-stats" name="php-stats">
        <vers prev="1" num="0.1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1084" published="2006-03-08" name="CVE-2006-1084" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to click.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0822" source="VUPEN">ADV-2006-0822</ref>
      <ref url="http://www.securityfocus.com/bid/16963" source="BID">16963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded" source="BUGTRAQ">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.phpstats.net/forum/viewtopic.php?t=140" source="MISC">http://www.phpstats.net/forum/viewtopic.php?t=140</ref>
      <ref url="http://secunia.com/advisories/19116" source="SECUNIA" adv="1">19116</ref>
      <ref url="http://retrogod.altervista.org/php_stats_0191_adv.html" source="MISC">http://retrogod.altervista.org/php_stats_0191_adv.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded" source="BUGTRAQ">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded" source="BUGTRAQ">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-stats" name="php-stats">
        <vers prev="1" num="0.1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1085" published="2006-03-08" name="CVE-2006-1085" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0822" source="VUPEN">ADV-2006-0822</ref>
      <ref url="http://www.securityfocus.com/bid/16963" source="BID">16963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded" source="BUGTRAQ">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.phpstats.net/forum/viewtopic.php?t=140" source="MISC">http://www.phpstats.net/forum/viewtopic.php?t=140</ref>
      <ref url="http://secunia.com/advisories/19116" source="SECUNIA" adv="1">19116</ref>
      <ref url="http://retrogod.altervista.org/php_stats_0191_adv.html" source="MISC">http://retrogod.altervista.org/php_stats_0191_adv.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded" source="BUGTRAQ">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded" source="BUGTRAQ">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-stats" name="php-stats">
        <vers prev="1" num="0.1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-1086" reject="1" published="2006-03-08" name="CVE-2006-1086" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1083.  Reason: This candidate is a duplicate of CVE-2006-1083.  Notes: All CVE users should reference CVE-2006-1083 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1087" published="2006-03-08" name="CVE-2006-1087" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php.  NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0822" source="VUPEN">ADV-2006-0822</ref>
      <ref url="http://www.securityfocus.com/bid/16963" source="BID">16963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded" source="BUGTRAQ">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.phpstats.net/forum/viewtopic.php?t=140" source="MISC">http://www.phpstats.net/forum/viewtopic.php?t=140</ref>
      <ref url="http://secunia.com/advisories/19116" source="SECUNIA" adv="1">19116</ref>
      <ref url="http://retrogod.altervista.org/php_stats_0191_adv.html" source="MISC">http://retrogod.altervista.org/php_stats_0191_adv.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded" source="BUGTRAQ">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded" source="BUGTRAQ">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-stats" name="php-stats">
        <vers prev="1" num="0.1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1088" published="2006-03-08" name="CVE-2006-1088" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0822" source="VUPEN">ADV-2006-0822</ref>
      <ref url="http://www.securityfocus.com/bid/16963" source="BID">16963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded" source="BUGTRAQ">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.phpstats.net/forum/viewtopic.php?t=140" source="MISC">http://www.phpstats.net/forum/viewtopic.php?t=140</ref>
      <ref url="http://secunia.com/advisories/19116" source="SECUNIA" adv="1">19116</ref>
      <ref url="http://retrogod.altervista.org/php_stats_0191_adv.html" source="MISC">http://retrogod.altervista.org/php_stats_0191_adv.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded" source="BUGTRAQ">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded" source="BUGTRAQ">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-stats" name="php-stats">
        <vers prev="1" num="0.1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1089" published="2006-03-09" name="CVE-2006-1089" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.punbb.org/download/patch/punbb-1.2.10_to_1.2.11.patch" source="CONFIRM" patch="1">http://www.punbb.org/download/patch/punbb-1.2.10_to_1.2.11.patch</ref>
      <ref url="http://secunia.com/advisories/19039" source="SECUNIA" patch="1" adv="1">19039</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0773" source="VUPEN">ADV-2006-0773</ref>
      <ref url="http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt" source="CONFIRM">http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24982" source="XF">punbb-header-xss(24982)</ref>
      <ref url="http://www.securityfocus.com/bid/16891" source="BID">16891</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0_alpha" />
        <vers num="1.0_beta1" />
        <vers num="1.0_beta1a" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1090" published="2006-03-09" name="CVE-2006-1090" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects PunBB version 1.2.10, and may affect all previous versions.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.punbb.org/download/patch/punbb-1.2.10_to_1.2.11.patch" source="CONFIRM" patch="1">http://www.punbb.org/download/patch/punbb-1.2.10_to_1.2.11.patch</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0773" source="VUPEN">ADV-2006-0773</ref>
      <ref url="http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt" source="CONFIRM">http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24837" source="XF">punbb-register-ip-dos(24837)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1091" published="2006-03-09" name="CVE-2006-1091" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16942" source="BID">16942</ref>
      <ref url="http://www.securityfocus.com/archive/1/426699" source="BUGTRAQ" adv="1">20060303 Kaspersky Memory/CPU Usage Leak by design</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25221" source="XF">kaspersky-unspecified-dos(25221)</ref>
      <ref url="http://securityreason.com/securityalert/535" source="SREASON">535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="5.0.5" />
        <vers num="5.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1092" published="2006-03-09" name="CVE-2006-1092" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to allocate a large amount of system memory that does not get freed.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of Sun, Solaris 8.x through 10.x</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0829" source="VUPEN">ADV-2006-0829</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102159-1" source="SUNALERT" adv="1">102159</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25152" source="XF">solaris-proc-pagedata-dos(25152)</ref>
      <ref url="http://www.securityfocus.com/bid/16966" source="BID">16966</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://securitytracker.com/id?1015723" source="SECTRACK">1015723</ref>
      <ref url="http://secunia.com/advisories/19716" source="SECUNIA">19716</ref>
      <ref url="http://secunia.com/advisories/19128" source="SECUNIA">19128</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1618" source="OVAL" sig="1">oval:org.mitre.oval:def:1618</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1093" published="2006-03-09" name="CVE-2006-1093" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0788" source="VUPEN">ADV-2006-0788</ref>
      <ref url="http://securitytracker.com/id?1015716" source="SECTRACK" adv="1">1015716</ref>
      <ref url="http://www.securityfocus.com/bid/16908" source="BID">16908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.0.2" />
        <vers num="5.0.2.1" />
        <vers num="5.0.2.10" />
        <vers num="5.0.2.11" />
        <vers num="5.0.2.12" />
        <vers num="5.0.2.13" />
        <vers num="5.0.2.14" />
        <vers num="5.0.2.2" />
        <vers num="5.0.2.3" />
        <vers num="5.0.2.4" />
        <vers num="5.0.2.5" />
        <vers num="5.0.2.6" />
        <vers num="5.0.2.7" />
        <vers num="5.0.2.8" />
        <vers num="5.0.2.9" />
        <vers num="5.1.1" />
        <vers num="5.1.1.1" />
        <vers num="5.1.1.2" />
        <vers num="5.1.1.3" />
        <vers num="5.1.1.4" />
        <vers num="5.1.1.5" />
        <vers num="5.1.1.6" />
        <vers num="5.1.1.7" />
        <vers num="5.1.1.8" />
        <vers num="5.1.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1094" published="2006-03-09" name="CVE-2006-1094" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16914" source="BID">16914</ref>
      <ref url="http://www.securityfocus.com/archive/1/426583" source="BUGTRAQ">20060301 Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities</ref>
      <ref url="http://www.nukedx.com/?viewdoc=17" source="MISC">http://www.nukedx.com/?viewdoc=17</ref>
      <ref url="http://www.osvdb.org/23810" source="OSVDB">23810</ref>
      <ref url="http://www.osvdb.org/23808" source="OSVDB">23808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datenbank_module" name="datenbank_module">
        <vers prev="1" num="2.7" />
      </prod>
      <prod vendor="woltlab" name="burning_board">
        <vers num="1.1.1" />
        <vers num="2.0_beta_3" />
        <vers num="2.0_beta_4" />
        <vers num="2.0_beta_5" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.2.2" />
        <vers num="2.3.1" />
        <vers num="2.3.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1095" published="2006-03-09" name="CVE-2006-1095" modified="2011-04-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16916" source="BID" patch="1">16916</ref>
      <ref url="http://www.cgisecurity.com/2006/02/07" source="MISC" patch="1">http://www.cgisecurity.com/2006/02/07</ref>
      <ref url="http://securitytracker.com/id?1015764" source="SECTRACK" patch="1">1015764</ref>
      <ref url="http://secunia.com/advisories/19239" source="SECUNIA" patch="1" adv="1">19239</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24965" source="XF">modpython-filesession-command-execution(24965)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0768" source="VUPEN" adv="1">ADV-2006-0768</ref>
      <ref url="http://www.modpython.org/fs_sec_warn.html" source="CONFIRM">http://www.modpython.org/fs_sec_warn.html</ref>
      <ref url="http://svn.apache.org/viewcvs.cgi/httpd/mod_python/branches/3.2.x/NEWS?rev=378945" source="CONFIRM">http://svn.apache.org/viewcvs.cgi/httpd/mod_python/branches/3.2.x/NEWS?rev=378945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_python">
        <vers num="3.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1096" published="2006-03-09" name="CVE-2006-1096" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter.  NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability most likely affects all versions of Digital Builder, NZ Ecommerce.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0803" source="VUPEN">ADV-2006-0803</ref>
      <ref url="http://www.securityfocus.com/bid/16931" source="BID">16931</ref>
      <ref url="http://www.osvdb.org/23600" source="OSVDB">23600</ref>
      <ref url="http://secunia.com/advisories/19088" source="SECUNIA">19088</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital_builder" name="nz_ecommerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1097" published="2006-03-09" name="CVE-2006-1097" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may only affect Datenbank MOD 2.7 and earlier versions in a Woltlab Burning Board environment. </sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/426583" source="BUGTRAQ" adv="1">20060301 Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities</ref>
      <ref url="http://www.nukedx.com/?viewdoc=17" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=17</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25004" source="XF">wbb-multiple-xss(25004)</ref>
      <ref url="http://www.osvdb.org/23811" source="OSVDB">23811</ref>
      <ref url="http://www.osvdb.org/23809" source="OSVDB">23809</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0033.html" source="FULLDISC">20060301 Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datenbank_module" name="datenbank_module">
        <vers num="mod_2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1098" published="2006-03-09" name="CVE-2006-1098" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php.  NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0803" source="VUPEN">ADV-2006-0803</ref>
      <ref url="http://www.securityfocus.com/bid/16931" source="BID">16931</ref>
      <ref url="http://www.osvdb.org/23601" source="OSVDB">23601</ref>
      <ref url="http://secunia.com/advisories/19088" source="SECUNIA" adv="1">19088</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital_builder" name="nz_ecommerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1099" published="2006-03-09" name="CVE-2006-1099" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16932" source="BID">16932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logit" name="logit">
        <vers num="1.3" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1100" published="2006-03-09" name="CVE-2006-1100" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of input data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25083" source="XF">sauerbraten-sgetstr-bo(25083)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0848" source="VUPEN">ADV-2006-0848</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0847" source="VUPEN">ADV-2006-0847</ref>
      <ref url="http://www.securityfocus.com/bid/16986" source="BID">16986</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426867/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Cube engine 2005_08_29</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref>
      <ref url="http://secunia.com/advisories/19111" source="SECUNIA">19111</ref>
      <ref url="http://secunia.com/advisories/19110" source="SECUNIA">19110</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/sauerbraten/sauerbraten/src/shared/cube.h?r1=1.7&amp;r2=1.8" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/sauerbraten/sauerbraten/src/shared/cube.h?r1=1.7&amp;r2=1.8</ref>
      <ref url="http://aluigi.altervista.org/adv/evilcube-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/evilcube-adv.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml" source="GENTOO">GLSA-200603-10</ref>
      <ref url="http://secunia.com/advisories/19199" source="SECUNIA">19199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sauerbraten" name="cube">
        <vers num="2005-08-09" />
      </prod>
      <prod vendor="sauerbraten" name="sauerbraten">
        <vers num="2004-05-08" />
        <vers num="2004-05-23" />
        <vers num="2004-11-02" />
        <vers num="2005-05-24" />
        <vers num="2005-05-29" />
        <vers num="2005-06-05" />
        <vers num="2005-06-12" />
        <vers num="2005-07-04" />
        <vers num="2005-08-15" />
        <vers num="2005-11-07" />
        <vers num="2006-01-31" />
        <vers num="2006-02-27" />
        <vers num="2006-02-28" />
        <vers num="initial_2004-02-27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1101" published="2006-03-09" name="CVE-2006-1101" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrated using SV_EXT tag data in the Cube engine, which is not properly handled by getint.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25085" source="XF">sauerbraten-multiple-dos(25085)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0848" source="VUPEN">ADV-2006-0848</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0847" source="VUPEN">ADV-2006-0847</ref>
      <ref url="http://www.securityfocus.com/bid/16986" source="BID">16986</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426867/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Cube engine 2005_08_29</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref>
      <ref url="http://secunia.com/advisories/19111" source="SECUNIA">19111</ref>
      <ref url="http://secunia.com/advisories/19110" source="SECUNIA">19110</ref>
      <ref url="http://aluigi.altervista.org/adv/evilcube-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/evilcube-adv.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml" source="GENTOO">GLSA-200603-10</ref>
      <ref url="http://secunia.com/advisories/19199" source="SECUNIA">19199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sauerbraten" name="cube">
        <vers num="2005-08-09" />
      </prod>
      <prod vendor="sauerbraten" name="sauerbraten">
        <vers num="2006-02-28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1102" published="2006-03-09" name="CVE-2006-1102" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to change to a map (ogz) file whose name contains ".." sequences and has a certain length that prevents the addition of the ".ogz" extension.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0848" source="VUPEN">ADV-2006-0848</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0847" source="VUPEN">ADV-2006-0847</ref>
      <ref url="http://www.securityfocus.com/bid/16986" source="BID">16986</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426867/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Cube engine 2005_08_29</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref>
      <ref url="http://secunia.com/advisories/19111" source="SECUNIA">19111</ref>
      <ref url="http://secunia.com/advisories/19110" source="SECUNIA">19110</ref>
      <ref url="http://aluigi.altervista.org/adv/evilcube-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/evilcube-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25086" source="XF">sauerbraten-sprintf-dos(25086)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml" source="GENTOO">GLSA-200603-10</ref>
      <ref url="http://securityreason.com/securityalert/548" source="SREASON">548</ref>
      <ref url="http://secunia.com/advisories/19199" source="SECUNIA">19199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sauerbraten" name="cube">
        <vers num="2005-08-09" />
      </prod>
      <prod vendor="sauerbraten" name="sauerbraten">
        <vers num="2006-02-28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1103" published="2006-03-09" name="CVE-2006-1103" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault) via a client that does not completely join the game and times out, which results in a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25087" source="XF">sauerbraten-engineserver-dos(25087)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0848" source="VUPEN">ADV-2006-0848</ref>
      <ref url="http://www.securityfocus.com/bid/16986" source="BID">16986</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded" source="BUGTRAQ" adv="1">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref>
      <ref url="http://securityreason.com/securityalert/550" source="SREASON">550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sauerbraten" name="cube">
        <vers num="2005-08-09" />
      </prod>
      <prod vendor="sauerbraten" name="sauerbraten">
        <vers num="2006-02-28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1104" published="2006-03-09" name="CVE-2006-1104" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php; and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header fields as used in the book_vistor function in includes/functions.php.  NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.</descript>
    </desc>
    <sols>
      <sol source="nvd">These vulnerabilities may affect all versions of Pixelpost.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25046" source="XF">pixelpost-functions-sql-injection(25046)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25044" source="XF">pixelpost-index-sql-injection(25044)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0823" source="VUPEN">ADV-2006-0823</ref>
      <ref url="http://www.securityfocus.com/bid/16964" source="BID">16964</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded" source="BUGTRAQ" adv="1">20060304 Pixel Post Multiple Vulnerabilities</ref>
      <ref url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19" source="MISC" adv="1">http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19</ref>
      <ref url="http://forum.pixelpost.org/showthread.php?t=3535" source="MISC">http://forum.pixelpost.org/showthread.php?t=3535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelpost" name="pixelpost">
        <vers num="1.4.3" />
        <vers num="1.5_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1105" published="2006-03-09" name="CVE-2006-1105" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function.  NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may affect all versions of Pixelpost.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25048" source="XF">pixelpost-phpinfo-obtain-information(25048)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0823" source="VUPEN">ADV-2006-0823</ref>
      <ref url="http://www.securityfocus.com/bid/16964" source="BID">16964</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded" source="BUGTRAQ" adv="1">20060304 Pixel Post Multiple Vulnerabilities</ref>
      <ref url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19" source="MISC" adv="1">http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19</ref>
      <ref url="http://forum.pixelpost.org/showthread.php?t=3535" source="MISC">http://forum.pixelpost.org/showthread.php?t=3535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelpost" name="pixelpost">
        <vers num="1.4.3" />
        <vers num="1.5_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1106" published="2006-03-09" name="CVE-2006-1106" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) message, (2) name, (3) url, and (4) email parameters when commenting on a post.  NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25047" source="XF">pixelpost-functions-xss(25047)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0823" source="VUPEN">ADV-2006-0823</ref>
      <ref url="http://www.securityfocus.com/bid/16964" source="BID">16964</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded" source="BUGTRAQ" adv="1">20060304 Pixel Post Multiple Vulnerabilities</ref>
      <ref url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19" source="MISC">http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19</ref>
      <ref url="http://forum.pixelpost.org/showthread.php?t=3535" source="MISC">http://forum.pixelpost.org/showthread.php?t=3535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelpost" name="pixelpost">
        <vers num="1.4.3" />
        <vers num="1.5_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1107" published="2006-03-09" name="CVE-2006-1107" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the nick parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects NMDeluxe versions 1.0 and previous.
</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25069" source="XF" patch="1">nmdeluxe-news-xss(25069)</ref>
      <ref url="http://secunia.com/advisories/19117" source="SECUNIA" patch="1" adv="1">19117</ref>
      <ref url="http://nmdeluxe.com/index.php" source="CONFIRM" patch="1">http://nmdeluxe.com/index.php</ref>
      <ref url="http://evuln.com/vulns/93/summary.html" source="MISC" patch="1">http://evuln.com/vulns/93/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0860" source="VUPEN">ADV-2006-0860</ref>
      <ref url="http://www.securityfocus.com/bid/17017" source="BID">17017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428002/100/0/threaded" source="BUGTRAQ">20060317 [eVuln] NMDeluxe XSS &amp; SQL Injection Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/595" source="SREASON">595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nmdeluxe" name="nmdeluxe">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1108" published="2006-03-09" name="CVE-2006-1108" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affcts NMDeluxe versions 1.0 and previous.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25070" source="XF" patch="1">nmdeluxe-news-sql-injection(25070)</ref>
      <ref url="http://secunia.com/advisories/19117" source="SECUNIA" patch="1" adv="1">19117</ref>
      <ref url="http://nmdeluxe.com/index.php" source="CONFIRM" patch="1">http://nmdeluxe.com/index.php</ref>
      <ref url="http://evuln.com/vulns/93/summary.html" source="MISC" patch="1">http://evuln.com/vulns/93/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0860" source="VUPEN">ADV-2006-0860</ref>
      <ref url="http://www.securityfocus.com/bid/17017" source="BID">17017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428002/100/0/threaded" source="BUGTRAQ">20060317 [eVuln] NMDeluxe XSS &amp; SQL Injection Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/595" source="SREASON">595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nmdeluxe" name="nmdeluxe">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1109" published="2006-03-09" name="CVE-2006-1109" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: it is not clear whether this report is associated with a specific product.  If not, then it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25045" source="XF">totalecommerce-index-sql-injection(25045)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0840" source="VUPEN">ADV-2006-0840</ref>
      <ref url="http://www.securityfocus.com/bid/16960" source="BID">16960</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426765/100/0/threaded" source="BUGTRAQ" adv="1">20060304 Advisory: TotalECommerce (index.asp id) Remote SQL InjectionVulnerability.</ref>
      <ref url="http://www.nukedx.com/?viewdoc=18" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=18</ref>
      <ref url="http://secunia.com/advisories/19103" source="SECUNIA" adv="1">19103</ref>
      <ref url="http://securityreason.com/securityalert/530" source="SREASON">530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="totalecommerce" name="totalecommerce">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1110" published="2006-03-09" name="CVE-2006-1110" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16938" source="BID">16938</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426650/100/0/threaded" source="BUGTRAQ" adv="1">20060302 AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref>
      <ref url="http://www.osvdb.org/23610" source="OSVDB">23610</ref>
      <ref url="http://secunia.com/advisories/19096" source="SECUNIA" adv="1">19096</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25035" source="XF">aztekforum-multiple-xss(25035)</ref>
      <ref url="http://milw0rm.com/exploits/1547" source="MILW0RM">1547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1111" published="2006-03-09" name="CVE-2006-1111" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16938" source="BID">16938</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426650/100/0/threaded" source="BUGTRAQ" adv="1">20060302 AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref>
      <ref url="http://www.osvdb.org/23611" source="OSVDB">23611</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25036" source="XF">aztekforum-info-disclosure(25036)</ref>
      <ref url="http://milw0rm.com/exploits/1547" source="MILW0RM">1547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1112" published="2006-03-09" name="CVE-2006-1112" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16938" source="BID">16938</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426650/100/0/threaded" source="BUGTRAQ" adv="1">20060302 AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref>
      <ref url="http://www.osvdb.org/23612" source="OSVDB">23612</ref>
      <ref url="http://securityreason.com/securityalert/539" source="SREASON">539</ref>
      <ref url="http://milw0rm.com/exploits/1547" source="MILW0RM">1547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1113" published="2006-03-09" name="CVE-2006-1113" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Loudblog versions 0.41 and previous.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19172" source="SECUNIA" patch="1" adv="1">19172</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0878" source="VUPEN">ADV-2006-0878</ref>
      <ref url="http://www.securityfocus.com/bid/17023" source="BID">17023</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426973/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Loudblog 0.41 SQL Injection, Local file read/include</ref>
      <ref url="http://loudblog.de/forum/viewtopic.php?id=590" source="CONFIRM">http://loudblog.de/forum/viewtopic.php?id=590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25101" source="XF">loudblog-podcast-sql-injection(25101)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gerrit_van_aaken" name="loudblog">
        <vers num="0.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1114" published="2006-03-09" name="CVE-2006-1114" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and trailing %00 (NULL) byte in the (1) template and (2) page parameters in (a) index.php, and the (3) language parameter in (b) inc/backend_settings.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Loudblog versions 0.41 and previous.</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19172" source="SECUNIA" patch="1" adv="1">19172</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0878" source="VUPEN">ADV-2006-0878</ref>
      <ref url="http://www.securityfocus.com/bid/17023" source="BID">17023</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426973/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Loudblog 0.41 SQL Injection, Local file read/include</ref>
      <ref url="http://loudblog.de/forum/viewtopic.php?id=590" source="CONFIRM">http://loudblog.de/forum/viewtopic.php?id=590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25103" source="XF">loudblog-index-directory-traversal(25103)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gerrit_van_aaken" name="loudblog">
        <vers num="0.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1115" published="2006-03-09" name="CVE-2006-1115" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25060" source="XF" patch="1">ncipher-hsm-weak-key(25060)</ref>
      <ref url="http://www.securityfocus.com/bid/17006" source="BID" patch="1">17006</ref>
      <ref url="http://www.ncipher.com/resources/95/sa12_insecure_generation_of_diffiehellman_keys" source="CONFIRM" patch="1" adv="1">http://www.ncipher.com/resources/95/sa12_insecure_generation_of_diffiehellman_keys</ref>
      <ref url="http://securitytracker.com/id?1015719" source="SECTRACK" patch="1" adv="1">1015719</ref>
      <ref url="http://secunia.com/advisories/19137" source="SECUNIA" patch="1" adv="1">19137</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0862" source="VUPEN">ADV-2006-0862</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427146/100/0/threaded" source="BUGTRAQ">20060308 nCipher Advisory #12: Insecure Generation of Diffie-Hellman keys</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="chil">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="mscapi_csp">
        <vers num="5.50" />
        <vers num="5.54" />
      </prod>
      <prod vendor="ncipher" name="ncipher_software_cd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1116" published="2006-03-09" name="CVE-2006-1116" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17011" source="BID" patch="1">17011</ref>
      <ref url="http://www.ncipher.com/resources/96/sa13_cbcmac_iv_misleading_programming_interface" source="CONFIRM" patch="1" adv="1">http://www.ncipher.com/resources/96/sa13_cbcmac_iv_misleading_programming_interface</ref>
      <ref url="http://securitytracker.com/id?1015718" source="SECTRACK" patch="1" adv="1">1015718</ref>
      <ref url="http://secunia.com/advisories/19137" source="SECUNIA" patch="1" adv="1">19137</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0862" source="VUPEN">ADV-2006-0862</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25062" source="XF">ncipher-ncore-bypass-security(25062)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427150/100/0/threaded" source="BUGTRAQ">20060308 nCipher Advisory #13: CBC-MAC IV misleading programming interface</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="ncore">
        <vers num="2.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1117" published="2006-03-09" name="CVE-2006-1117" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17012" source="BID" patch="1">17012</ref>
      <ref url="http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security" source="CONFIRM" patch="1" adv="1">http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security</ref>
      <ref url="http://securitytracker.com/id?1015718" source="SECTRACK" patch="1" adv="1">1015718</ref>
      <ref url="http://secunia.com/advisories/19137" source="SECUNIA" patch="1" adv="1">19137</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0862" source="VUPEN">ADV-2006-0862</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25063" source="XF">ncipher-firmware-weak-security(25063)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427151/100/0/threaded" source="BUGTRAQ">20060309 nCipher Advisory #14: Presence of flaws in firmware security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="dse200_document_sealing_engine">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="ncore">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="nforce">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="securedb">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="time_source_master_clock">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="nethsm">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.12_cam5" />
      </prod>
      <prod vendor="ncipher" name="nshield">
        <vers num="" />
      </prod>
      <prod vendor="ncipher" name="payshield">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1118" published="2006-03-09" name="CVE-2006-1118" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25073" source="XF" patch="1">bmail-gbkcharacterset-sql-injection(25073)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=144412&amp;release_id=399256" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=144412&amp;release_id=399256</ref>
      <ref url="http://secunia.com/advisories/19147" source="SECUNIA" patch="1" adv="1">19147</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0863" source="VUPEN">ADV-2006-0863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmail" name="bmail">
        <vers num="pr9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1119" published="2006-03-09" name="CVE-2006-1119" modified="2011-07-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25277" source="XF">cpanel-fantastico-path-disclosure(25277)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426957/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Cpanel Path Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netenberg" name="fantastico_de_luxe">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1120" published="2006-03-09" name="CVE-2006-1120" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4) images parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7) subject, (8) body, and (9) mid parameters to (c) forums.php; (10) subject and (11) message parameters to (d) inbox.php; (12) subject_color and (13) email parameters to (e) lostpassword.php; and the (14) c_name, (15) content_inicial, and (16) cid parameters to (f) mycontents.php.  NOTE: the calendar.php/day vector is already subsumed by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and search.php/q parameters for calendar.php are already subsumed by CVE-2004-2511.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427175/100/0/threaded" source="BUGTRAQ" adv="1">20060309 DCP Portal: Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-001.txt" source="MISC" adv="1">http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-001.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25279" source="XF">dcpportal-multiple-scripts-xss(25279)</ref>
      <ref url="http://www.securityfocus.com/bid/17050" source="BID">17050</ref>
      <ref url="http://www.osvdb.org/23981" source="OSVDB">23981</ref>
      <ref url="http://www.osvdb.org/23980" source="OSVDB">23980</ref>
      <ref url="http://www.osvdb.org/23979" source="OSVDB">23979</ref>
      <ref url="http://www.osvdb.org/23978" source="OSVDB">23978</ref>
      <ref url="http://www.osvdb.org/23977" source="OSVDB">23977</ref>
      <ref url="http://www.osvdb.org/23976" source="OSVDB">23976</ref>
      <ref url="http://securityreason.com/securityalert/392" source="SREASON">392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codeworx_technologies" name="dcp-portal">
        <vers num="3.7" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.5.1" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
        <vers num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1121" published="2006-03-09" name="CVE-2006-1121" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16961" source="BID">16961</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426759/100/0/threaded" source="BUGTRAQ" adv="1">20060304 [KAPDA::#30] - CuteNews1.4.1 Cross_Site_Scripting Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015726" source="SECTRACK" adv="1">1015726</ref>
      <ref url="http://kapda.ir/advisory-277.html" source="MISC" adv="1">http://kapda.ir/advisory-277.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25052" source="XF">cutenews-index-script-xss(25052)</ref>
      <ref url="http://securityreason.com/securityalert/531" source="SREASON">531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1122" published="2006-03-09" name="CVE-2006-1122" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25214" source="XF">d2kblog-default-msg-xss(25214)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0896" source="VUPEN">ADV-2006-0896</ref>
      <ref url="http://www.securityfocus.com/bid/17035" source="BID">17035</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427103/100/0/threaded" source="BUGTRAQ" adv="1">20060308 [KAPDA::#32] - d2kBlog 1.0.3 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23771" source="OSVDB">23771</ref>
      <ref url="http://secunia.com/advisories/19177" source="SECUNIA" adv="1">19177</ref>
      <ref url="http://securityreason.com/securityalert/559" source="SREASON">559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d2ksoft" name="d2kblog">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1123" published="2006-03-09" name="CVE-2006-1123" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0896" source="VUPEN">ADV-2006-0896</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427103/100/0/threaded" source="BUGTRAQ" adv="1">20060308 [KAPDA::#32] - d2kBlog 1.0.3 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19177" source="SECUNIA" adv="1">19177</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25215" source="XF">d2kblog-memname-sql-injection(25215)</ref>
      <ref url="http://www.securityfocus.com/bid/17035" source="BID">17035</ref>
      <ref url="http://www.osvdb.org/23770" source="OSVDB">23770</ref>
      <ref url="http://securityreason.com/securityalert/559" source="SREASON">559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d2ksoft" name="d2kblog">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1124" published="2006-03-09" name="CVE-2006-1124" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25072" source="XF">revilloc-user-bo(25072)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0867" source="VUPEN">ADV-2006-0867</ref>
      <ref url="http://www.securityfocus.com/bid/16997" source="BID">16997</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427192/100/0/threaded" source="BUGTRAQ" adv="1">20060309 RevilloC MailServer 1.x "USER" Command Handling Remote Buffer Overflow Exploit</ref>
      <ref url="http://www.osvdb.org/23735" source="OSVDB" adv="1">23735</ref>
      <ref url="http://www.morx.org/rev.txt" source="MISC">http://www.morx.org/rev.txt</ref>
      <ref url="http://securitytracker.com/id?1015739" source="SECTRACK">1015739</ref>
      <ref url="http://secunia.com/advisories/19119" source="SECUNIA" adv="1">19119</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0910.html" source="FULLDISC">20060307 RevilloC mail server USER command heap overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="revilloc_solutions" name="revilloc_mailserver">
        <vers num="1.21" />
        <vers num="proxy_1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1125" published="2006-03-09" name="CVE-2006-1125" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Grisoft AVG Free 7.1, and other versions including 7.0.308, sets Everyone/Full Control permissions for certain update files including (1) upd_vers.cfg, (2) incavi.avm, and (3) unspecified drivers, which might allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16952" source="BID" patch="1">16952</ref>
      <ref url="http://secunia.com/advisories/19118" source="SECUNIA" patch="1">19118</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0845" source="VUPEN">ADV-2006-0845</ref>
      <ref url="http://www.dslreports.com/forum/remark,15601404" source="MISC">http://www.dslreports.com/forum/remark,15601404</ref>
      <ref url="http://securitytracker.com/id?1015728" source="SECTRACK" adv="1">1015728</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25139" source="XF">avg-update-gain-privilieges(25139)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0631.html" source="BUGTRAQ">20060303 AVG 7 granting Everyone Full Control to updated files... even its drivers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grisoft" name="avg_antivirus">
        <vers num="7.0" />
        <vers num="7.0.251" />
        <vers num="7.0.323" />
        <vers num="7.1.308" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1126" published="2006-03-09" name="CVE-2006-1126" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTE_ADDR.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00106-03022006" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00106-03022006</ref>
      <ref url="http://securitytracker.com/id?1015717" source="SECTRACK" patch="1" adv="1">1015717</ref>
      <ref url="http://secunia.com/advisories/19104" source="SECUNIA" patch="1" adv="1">19104</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html" source="BUGTRAQ" patch="1" adv="1">20060303 Gallery 2 Multiple Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0813" source="VUPEN">ADV-2006-0813</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25120" source="XF">gallery-header-spoofing(25120)</ref>
      <ref url="http://gallery.menalto.com/gallery_2.0.3_released" source="CONFIRM">http://gallery.menalto.com/gallery_2.0.3_released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1127" published="2006-03-09" name="CVE-2006-1127" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16940" source="BID" patch="1">16940</ref>
      <ref url="http://securitytracker.com/id?1015717" source="SECTRACK" patch="1">1015717</ref>
      <ref url="http://secunia.com/advisories/19104" source="SECUNIA" patch="1" adv="1">19104</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0813" source="VUPEN">ADV-2006-0813</ref>
      <ref url="http://www.osvdb.org/23596" source="OSVDB">23596</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00106-03022006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00106-03022006</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html" source="BUGTRAQ">20060303 Gallery 2 Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25117" source="XF">gallery-getremotehostaddress-xss(25117)</ref>
      <ref url="http://gallery.menalto.com/gallery_2.0.3_released" source="CONFIRM">http://gallery.menalto.com/gallery_2.0.3_released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_alpha" />
        <vers num="2.0_alpha1" />
        <vers num="2.0_alpha2" />
        <vers num="2.0_alpha3" />
        <vers num="2.0_alpha4" />
        <vers num="2.0_beta1" />
        <vers num="2.0_beta2" />
        <vers num="2.0_beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1128" published="2006-03-09" name="CVE-2006-1128" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015717" source="SECTRACK" patch="1">1015717</ref>
      <ref url="http://secunia.com/advisories/19104" source="SECUNIA" patch="1" adv="1">19104</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0813" source="VUPEN">ADV-2006-0813</ref>
      <ref url="http://www.osvdb.org/23597" source="OSVDB">23597</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00106-03022006" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00106-03022006</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html" source="BUGTRAQ">20060303 Gallery 2 Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25118" source="XF">gallery-sessionid-bypass-security(25118)</ref>
      <ref url="http://www.securityfocus.com/bid/16948" source="BID">16948</ref>
      <ref url="http://gallery.menalto.com/gallery_2.0.3_released" source="CONFIRM">http://gallery.menalto.com/gallery_2.0.3_released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_alpha" />
        <vers num="2.0_alpha1" />
        <vers num="2.0_alpha2" />
        <vers num="2.0_alpha3" />
        <vers num="2.0_alpha4" />
        <vers num="2.0_beta1" />
        <vers num="2.0_beta2" />
        <vers num="2.0_beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1129" published="2006-03-09" name="CVE-2006-1129" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in config.php in EKINboard 1.0.3 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16861" source="BID" patch="1">16861</ref>
      <ref url="http://www.ekinboard.com/patch_for_1.0.3.txt" source="MISC" patch="1">http://www.ekinboard.com/patch_for_1.0.3.txt</ref>
      <ref url="http://secunia.com/advisories/19045" source="SECUNIA" patch="1" adv="1">19045</ref>
      <ref url="http://evuln.com/vulns/88/summary.html" source="MISC" patch="1">http://evuln.com/vulns/88/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24922" source="XF">ekinboard-config-sql-injection(24922)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0758" source="VUPEN">ADV-2006-0758</ref>
      <ref url="http://www.osvdb.org/23547" source="OSVDB">23547</ref>
      <ref url="http://www.ekinboard.com/forums/v1/viewtopic.php?id=469" source="CONFIRM">http://www.ekinboard.com/forums/v1/viewtopic.php?id=469</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427073/100/0/threaded" source="BUGTRAQ">20060308 [eVuln] EKINboard 'img' BBCode XSS &amp; Cookie 'username' SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekinboard" name="ekinboard">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1130" published="2006-03-09" name="CVE-2006-1130" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in EKINboard 1.0.3 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16861" source="BID" patch="1">16861</ref>
      <ref url="http://www.ekinboard.com/patch_for_1.0.3.txt" source="MISC" patch="1">http://www.ekinboard.com/patch_for_1.0.3.txt</ref>
      <ref url="http://www.ekinboard.com/forums/v1/viewtopic.php?id=469" source="CONFIRM" patch="1">http://www.ekinboard.com/forums/v1/viewtopic.php?id=469</ref>
      <ref url="http://secunia.com/advisories/19045" source="SECUNIA" patch="1" adv="1">19045</ref>
      <ref url="http://evuln.com/vulns/88/summary.html" source="MISC" patch="1">http://evuln.com/vulns/88/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24921" source="XF">ekinboard-bbcode-xss(24921)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0758" source="VUPEN">ADV-2006-0758</ref>
      <ref url="http://www.osvdb.org/23546" source="OSVDB">23546</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427073/100/0/threaded" source="BUGTRAQ">20060308 [eVuln] EKINboard 'img' BBCode XSS &amp; Cookie 'username' SQL Injection Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/558" source="SREASON">558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekinboard" name="ekinboard">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1131" published="2006-03-09" name="CVE-2006-1131" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the comment_title parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0837" source="VUPEN">ADV-2006-0837</ref>
      <ref url="http://secunia.com/advisories/19101" source="SECUNIA" adv="1">19101</ref>
      <ref url="http://kiki91.altervista.org/exploit/bitweaver_1.2.1_XSS.txt" source="MISC" adv="1">http://kiki91.altervista.org/exploit/bitweaver_1.2.1_XSS.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25053" source="XF">bitweaver-titlefield-xss(25053)</ref>
      <ref url="http://www.securityfocus.com/bid/16973" source="BID">16973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitweaver" name="bitweaver">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1132" published="2006-03-09" name="CVE-2006-1132" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show.php in vbzoom 1.11 allow remote attackers to execute arbitrary SQL commands via the MainID parameter. NOTE: the SubjectID vector is already covered by CVE-2005-4729.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16955" source="BID">16955</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded" source="BUGTRAQ">20060306 SQL injection &amp; XSS IN vbzoom v1.11</ref>
      <ref url="http://securityreason.com/securityalert/552" source="SREASON">552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbzoom" name="vbzoom">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1133" published="2006-03-09" name="CVE-2006-1133" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parameter to (1) comment.php or (2) contact.php.  NOTE: the profile.php/UserName vector is already covered by CVE-2005-2441.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded" source="BUGTRAQ">20060306 SQL injection &amp; XSS IN vbzoom v1.11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25090" source="XF">vbzoom-comment-contact-xss(25090)</ref>
      <ref url="http://www.securityfocus.com/bid/16969" source="BID">16969</ref>
      <ref url="http://www.securityfocus.com/bid/16956" source="BID">16956</ref>
      <ref url="http://www.osvdb.org/23813" source="OSVDB">23813</ref>
      <ref url="http://www.osvdb.org/23812" source="OSVDB">23812</ref>
      <ref url="http://securityreason.com/securityalert/552" source="SREASON">552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbzoom" name="vbzoom">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1134" published="2006-03-09" name="CVE-2006-1134" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0820" source="VUPEN">ADV-2006-0820</ref>
      <ref url="http://www.securityfocus.com/bid/17107" source="BID">17107</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427623/100/0/threaded" source="BUGTRAQ">20060314 [eVuln] CyBoards PHP Lite SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/23692" source="OSVDB">23692</ref>
      <ref url="http://www.gold-sonata.com/forums/read.php?board=1&amp;id=17271" source="MISC">http://www.gold-sonata.com/forums/read.php?board=1&amp;id=17271</ref>
      <ref url="http://secunia.com/advisories/19135" source="SECUNIA" adv="1">19135</ref>
      <ref url="http://evuln.com/vulns/91/description.html" source="MISC">http://evuln.com/vulns/91/description.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25061" source="XF">cyboards-processpost-sql-injection(25061)</ref>
      <ref url="http://www.securityfocus.com/bid/16987" source="BID">16987</ref>
      <ref url="http://securityreason.com/securityalert/582" source="SREASON">582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_smith" name="cyboards_php_lite">
        <vers num="1.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1135" published="2006-03-09" name="CVE-2006-1135" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) username parameter to comments_do.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0883" source="VUPEN">ADV-2006-0883</ref>
      <ref url="http://secunia.com/advisories/19151" source="SECUNIA" adv="1">19151</ref>
      <ref url="http://kiki91.altervista.org/exploit/sBlog_0.72_xss.txt" source="MISC">http://kiki91.altervista.org/exploit/sBlog_0.72_xss.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25111" source="XF">sblog-username-xss(25111)</ref>
      <ref url="http://www.securityfocus.com/bid/17044" source="BID">17044</ref>
      <ref url="http://www.osvdb.org/23760" source="OSVDB">23760</ref>
      <ref url="http://www.osvdb.org/23759" source="OSVDB">23759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sblog" name="sblog">
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1136" published="2006-03-09" name="CVE-2006-1136" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the PostScript file interpreter code for Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0857" source="VUPEN">ADV-2006-0857</ref>
      <ref url="http://www.osvdb.org/23724" source="OSVDB">23724</ref>
      <ref url="http://securitytracker.com/id?1015738" source="SECTRACK">1015738</ref>
      <ref url="http://secunia.com/advisories/19146" source="SECUNIA" adv="1">19146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25172" source="XF">xerox-postscript-interpreter-dos(25172)</ref>
      <ref url="http://www.securityfocus.com/bid/17014" source="BID">17014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="copycentre_c65">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c75">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c90">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="workcentre_65">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_75">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_90">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1137" published="2006-03-09" name="CVE-2006-1137" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allow remote attackers to cause an unspecified denial of service via a crafted PostScript file that will (1) "navigate through the directory" or (2) a "file sent to expose TCP/IP ports".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0857" source="VUPEN">ADV-2006-0857</ref>
      <ref url="http://www.osvdb.org/23726" source="OSVDB">23726</ref>
      <ref url="http://www.osvdb.org/23725" source="OSVDB">23725</ref>
      <ref url="http://securitytracker.com/id?1015738" source="SECTRACK">1015738</ref>
      <ref url="http://secunia.com/advisories/19146" source="SECUNIA" adv="1">19146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25174" source="XF">xerox-postscript-tcpip-dos(25174)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25173" source="XF">xerox-postscript-navigate-dos(25173)</ref>
      <ref url="http://www.securityfocus.com/bid/17014" source="BID">17014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="copycentre_c65">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c75">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c90">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="workcentre_65">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_75">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_90">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1138" published="2006-03-09" name="CVE-2006-1138" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the web server code in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows remote attackers to cause a denial of service (memory corruption) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0857" source="VUPEN">ADV-2006-0857</ref>
      <ref url="http://www.osvdb.org/23727" source="OSVDB">23727</ref>
      <ref url="http://securitytracker.com/id?1015738" source="SECTRACK">1015738</ref>
      <ref url="http://secunia.com/advisories/19146" source="SECUNIA" adv="1">19146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25175" source="XF">xerox-web-corruption-dos(25175)</ref>
      <ref url="http://www.securityfocus.com/bid/17014" source="BID">17014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="copycentre_c65">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c75">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c90">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="workcentre_65">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_75">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_90">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1139" published="2006-03-09" name="CVE-2006-1139" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the ESS/ Network Controller in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, causes the Immediate Image Overwrite feature to fail after a power loss, which could leave data exposed to attack.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0857" source="VUPEN">ADV-2006-0857</ref>
      <ref url="http://www.osvdb.org/23728" source="OSVDB">23728</ref>
      <ref url="http://securitytracker.com/id?1015738" source="SECTRACK">1015738</ref>
      <ref url="http://secunia.com/advisories/19146" source="SECUNIA" adv="1">19146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25176" source="XF">xerox-image-overwrite-dos(25176)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="copycentre_c65">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c75">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="copycentre_c90">
        <vers prev="1" num="1.001.02.0715" />
        <vers prev="1" num="1.001.02.073" />
      </prod>
      <prod vendor="xerox" name="workcentre_65">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_75">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
      <prod vendor="xerox" name="workcentre_90">
        <vers prev="1" num="1.001.02.0715" edition="" />
        <vers prev="1" num="1.001.02.0715" edition=":pro" />
        <vers prev="1" num="1.001.02.073" edition="" />
        <vers prev="1" num="1.001.02.073" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1140" published="2006-03-10" name="CVE-2006-1140" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.x128.net/redblog-05-remote-sql-injection.txt" source="MISC">http://www.x128.net/redblog-05-remote-sql-injection.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0894" source="VUPEN">ADV-2006-0894</ref>
      <ref url="http://secunia.com/advisories/19181" source="SECUNIA" adv="1">19181</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25122" source="XF">redblog-catid-sql-injection(25122)</ref>
      <ref url="http://www.securityfocus.com/bid/17041" source="BID">17041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redblog" name="redblog">
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1141" published="2006-03-10" name="CVE-2006-1141" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25065" source="XF" patch="1">qmialadmin-qmailadmin-bo(25065)</ref>
      <ref url="http://www.securityfocus.com/bid/16994" source="BID" patch="1">16994</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=6691&amp;release_id=395211" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=6691&amp;release_id=395211</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0852" source="VUPEN">ADV-2006-0852</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/qmailadmin/qmailadmin/qmailadmin.c?r1=1.6.2.10&amp;r2=1.6.2.11" source="MISC">http://cvs.sourceforge.net/viewcvs.py/qmailadmin/qmailadmin/qmailadmin.c?r1=1.6.2.10&amp;r2=1.6.2.11</ref>
      <ref url="http://www.osvdb.org/23705" source="OSVDB">23705</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200611-15.xml" source="GENTOO">GLSA-200611-15</ref>
      <ref url="http://secunia.com/advisories/23019" source="SECUNIA">23019</ref>
      <ref url="http://secunia.com/advisories/19262" source="SECUNIA">19262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="qmailadmin">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.3" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1142" published="2006-03-10" name="CVE-2006-1142" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Ravenous Web Server before 0.7.1 allows remote attackers to access arbitrary rvplg files, with unknown impact.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=131871&amp;release_id=399092" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=131871&amp;release_id=399092</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0859" source="VUPEN">ADV-2006-0859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25191" source="XF">ravenous-rvplg-unauth-access(25191)</ref>
      <ref url="http://www.securityfocus.com/bid/17013" source="BID">17013</ref>
      <ref url="http://www.osvdb.org/23706" source="OSVDB">23706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solido_systems" name="ravenous_web_server">
        <vers num="0.2.0" />
        <vers num="0.4.0" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.9" />
        <vers num="0.6.0" />
        <vers num="0.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1143" published="2006-03-10" name="CVE-2006-1143" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment_body parameter, as used by the comment field, when posting a comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426828/100/0/threaded" source="BUGTRAQ">20060305 FTPoed Blog Engine =>v1.1 HTML Injection Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015725" source="SECTRACK">1015725</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25138" source="XF">ftpoed-comment-xss(25138)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpoed" name="ftpoed_blog_engine">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1144" published="2006-03-10" name="CVE-2006-1144" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0886" source="VUPEN">ADV-2006-0886</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426931/100/0/threaded" source="BUGTRAQ">20060306 histhost v1.0.0 xss and possible rmdir</ref>
      <ref url="http://secunia.com/advisories/19155" source="SECUNIA" adv="1">19155</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25105" source="XF">hithost-viewuser-deleteuser-xss(25105)</ref>
      <ref url="http://www.securityfocus.com/bid/17025" source="BID">17025</ref>
      <ref url="http://www.osvdb.org/23758" source="OSVDB">23758</ref>
      <ref url="http://www.osvdb.org/23757" source="OSVDB">23757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_ravenscroft" name="hithost">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1145" published="2006-03-10" name="CVE-2006-1145" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code via unspecified vectors when the server sends crafted messages to the clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0882" source="VUPEN">ADV-2006-0882</ref>
      <ref url="http://www.securityfocus.com/bid/17028" source="BID">17028</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426984/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref>
      <ref url="http://www.osvdb.org/23747" source="OSVDB">23747</ref>
      <ref url="http://secunia.com/advisories/19144" source="SECUNIA" adv="1">19144</ref>
      <ref url="http://aluigi.altervista.org/adv/aa2k6x-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/aa2k6x-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25199" source="XF">alien-safe-cprintf-format-string(25199)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0147.html" source="FULLDISC">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cor_entertainment" name="alien_arena_2006">
        <vers num="gold_5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1146" published="2006-03-10" name="CVE-2006-1146" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code by sending a long message to the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0882" source="VUPEN">ADV-2006-0882</ref>
      <ref url="http://www.securityfocus.com/bid/17028" source="BID">17028</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426984/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref>
      <ref url="http://www.osvdb.org/23748" source="OSVDB">23748</ref>
      <ref url="http://secunia.com/advisories/19144" source="SECUNIA" adv="1">19144</ref>
      <ref url="http://aluigi.altervista.org/adv/aa2k6x-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/aa2k6x-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25200" source="XF">alien-cmd-sa-f-bo(25200)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0147.html" source="FULLDISC">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cor_entertainment" name="alien_arena_2006">
        <vers num="gold_5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1147" published="2006-03-10" name="CVE-2006-1147" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, weapon, or model name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0882" source="VUPEN">ADV-2006-0882</ref>
      <ref url="http://www.securityfocus.com/bid/17028" source="BID">17028</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426984/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref>
      <ref url="http://www.osvdb.org/23749" source="OSVDB">23749</ref>
      <ref url="http://secunia.com/advisories/19144" source="SECUNIA" adv="1">19144</ref>
      <ref url="http://aluigi.altervista.org/adv/aa2k6x-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/aa2k6x-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25201" source="XF">alien-com-sprintf-dos(25201)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0147.html" source="FULLDISC">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cor_entertainment" name="alien_arena_2006">
        <vers num="gold_5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1148" published="2006-03-10" name="CVE-2006-1148" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow remote attackers to execute arbitrary code via an HTTP GET request with a long (1) parameter name or (2) value in a URL, which triggers the overflow in the nextCGIarg function in servhs.cpp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17040" source="BID" patch="1">17040</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427160/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060309 INFIGO-2006-03-01: PeerCast streaming server remote buffer overflow</ref>
      <ref url="http://www.infigo.hr/in_focus/INFIGO-2006-03-01" source="MISC" patch="1" adv="1">http://www.infigo.hr/in_focus/INFIGO-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25113" source="XF">peercast-url-bo(25113)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0900" source="VUPEN" adv="1">ADV-2006-0900</ref>
      <ref url="http://www.peercast.org/forum/viewtopic.php?t=3346" source="CONFIRM">http://www.peercast.org/forum/viewtopic.php?t=3346</ref>
      <ref url="http://www.osvdb.org/23777" source="OSVDB">23777</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200603-17.xml" source="GENTOO">GLSA-200603-17</ref>
      <ref url="http://secunia.com/advisories/19291" source="SECUNIA" adv="1">19291</ref>
      <ref url="http://secunia.com/advisories/19169" source="SECUNIA">19169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peercast" name="peercast">
        <vers num="0.1211" />
        <vers num="0.1212" />
        <vers prev="1" num="0.1215" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1149" published="2006-03-10" name="CVE-2006-1149" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25082" source="XF">owl-intranet-owlapi-file-include(25082)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0868" source="VUPEN">ADV-2006-0868</ref>
      <ref url="http://www.osvdb.org/23734" source="OSVDB">23734</ref>
      <ref url="http://secunia.com/advisories/19142" source="SECUNIA" adv="1">19142</ref>
      <ref url="http://milw0rm.com/exploits/1561" source="MILW0RM">1561</ref>
      <ref url="http://www.securityfocus.com/bid/17021" source="BID">17021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.6" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.8" />
        <vers num="0.82" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1150" published="2006-03-10" name="CVE-2006-1150" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0846" source="VUPEN">ADV-2006-0846</ref>
      <ref url="http://www.securityfocus.com/bid/16982" source="BID">16982</ref>
      <ref url="http://secunia.com/advisories/19134" source="SECUNIA" adv="1">19134</ref>
      <ref url="http://aluigi.altervista.org/adv/tegob1-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/tegob1-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25165" source="XF">teg-nickname-offbyone-dos(25165)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teg" name="tenes_empanadas_graciela">
        <vers num="0.11.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1151" published="2006-03-10" name="CVE-2006-1151" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427165/100/0/threaded" source="BUGTRAQ">20060309 M-Phorum Cross Site Scripting</ref>
      <ref url="http://secunia.com/advisories/19121" source="SECUNIA" adv="1">19121</ref>
      <ref url="http://biyosecurity.be/bugs/mphorum.txt" source="MISC">http://biyosecurity.be/bugs/mphorum.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25312" source="XF">mphorum-index-xss(25312)</ref>
      <ref url="http://www.securityfocus.com/bid/25394" source="BID">25394</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/477253/100/0/threaded" source="BUGTRAQ">20070821 Vulnerabilities digest</ref>
      <ref url="http://www.osvdb.org/23951" source="OSVDB">23951</ref>
      <ref url="http://securityvulns.com/source13951.html" source="MISC">http://securityvulns.com/source13951.html</ref>
      <ref url="http://securityvulns.com/Ldocument750.html" source="MISC">http://securityvulns.com/Ldocument750.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="m_phorum" name="m_phorum">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1152" published="2006-03-10" name="CVE-2006-1152" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in M-Phorum 0.2 allows remote attackers to include arbitrary files via the go parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0827" source="VUPEN">ADV-2006-0827</ref>
      <ref url="http://www.securityfocus.com/bid/16977" source="BID">16977</ref>
      <ref url="http://secunia.com/advisories/19121" source="SECUNIA" adv="1">19121</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25102" source="XF">mphorum-index-file-include(25102)</ref>
      <ref url="http://www.osvdb.org/23740" source="OSVDB">23740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="m_phorum" name="m_phorum">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1153" published="2006-03-10" name="CVE-2006-1153" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load parameter, when performing a Shoutbox action through Invision Power Board (IPB).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25074" source="XF">d2shoutbox-index-sql-injection(25074)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0865" source="VUPEN">ADV-2006-0865</ref>
      <ref url="http://www.securityfocus.com/bid/16984" source="BID">16984</ref>
      <ref url="http://secunia.com/advisories/19132" source="SECUNIA" adv="1">19132</ref>
      <ref url="http://milw0rm.com/exploits/1556" source="MILW0RM">1556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d2-shoutbox" name="d2-shoutbox">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1154" published="2006-03-10" name="CVE-2006-1154" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable.  NOTE: 2.1.4 was also reported to be vulnerable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31121" source="XF">fantasticnews-configscriptpath-file-include(31121)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25064" source="XF">fantasticnews-archive-file-include(25064)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3513" source="VUPEN" adv="1">ADV-2006-3513</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0826" source="VUPEN">ADV-2006-0826</ref>
      <ref url="http://www.securityfocus.com/bid/21796" source="BID">21796</ref>
      <ref url="http://www.securityfocus.com/bid/16985" source="BID">16985</ref>
      <ref url="http://www.milw0rm.com/exploits/3027" source="MILW0RM">3027</ref>
      <ref url="http://sx02.coresec.de/advisories/152.txt" source="MISC">http://sx02.coresec.de/advisories/152.txt</ref>
      <ref url="http://secunia.com/advisories/23519" source="SECUNIA">23519</ref>
      <ref url="http://secunia.com/advisories/21807" source="SECUNIA" adv="1">21807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fscripts" name="fantastic_news">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1155" published="2006-03-12" name="CVE-2006-1155" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to inject arbitrary web script or HTML via the Error parameter in (1) login.asp and (2) default.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.manastungare.com/projects/site-membership/" source="CONFIRM" patch="1">http://www.manastungare.com/projects/site-membership/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0884" source="VUPEN">ADV-2006-0884</ref>
      <ref url="http://secunia.com/advisories/19156" source="SECUNIA" adv="1">19156</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25109" source="XF">manas-tungare-login-default-xss(25109)</ref>
      <ref url="http://www.securityfocus.com/bid/17045" source="BID">17045</ref>
      <ref url="http://www.osvdb.org/23754" source="OSVDB">23754</ref>
      <ref url="http://www.osvdb.org/23753" source="OSVDB">23753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manas_tungare" name="site_membership_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1156" published="2006-03-12" name="CVE-2006-1156" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.manastungare.com/projects/site-membership/" source="CONFIRM" patch="1">http://www.manastungare.com/projects/site-membership/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0884" source="VUPEN">ADV-2006-0884</ref>
      <ref url="http://secunia.com/advisories/19156" source="SECUNIA" adv="1">19156</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25110" source="XF">manas-tungare-login-sql-injection(25110)</ref>
      <ref url="http://www.securityfocus.com/bid/17045" source="BID">17045</ref>
      <ref url="http://www.osvdb.org/23755" source="OSVDB">23755</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manas_tungare" name="site_membership_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1157" published="2006-03-12" name="CVE-2006-1157" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Subject field (possibly messaggio parameter) when posting a new message in post.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0901" source="VUPEN">ADV-2006-0901</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427171/100/0/threaded" source="BUGTRAQ" adv="1">20060309 ADP Forum 2.0,* script &amp;#304;njection</ref>
      <ref url="http://biyosecurity.be/bugs/adpforum2.txt" source="MISC">http://biyosecurity.be/bugs/adpforum2.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25189" source="XF">adp-forum-subject-xss(25189)</ref>
      <ref url="http://www.securityfocus.com/bid/17047" source="BID">17047</ref>
      <ref url="http://www.osvdb.org/23961" source="OSVDB">23961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adp" name="adp_forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1158" published="2006-03-12" name="CVE-2006-1158" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kerio.com/kms_history.html" source="CONFIRM" patch="1">http://www.kerio.com/kms_history.html</ref>
      <ref url="http://secunia.com/advisories/19150" source="SECUNIA" patch="1" adv="1">19150</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25150" source="XF">kerio-mailserver-imap-dos(25150)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0898" source="VUPEN">ADV-2006-0898</ref>
      <ref url="http://www.securityfocus.com/bid/17043" source="BID">17043</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427471/100/0/threaded" source="BUGTRAQ">20060313 Kerio MailServer bugfun</ref>
      <ref url="http://www.osvdb.org/23772" source="OSVDB">23772</ref>
      <ref url="http://securitytracker.com/id?1015748" source="SECTRACK">1015748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.6.4" />
        <vers num="5.6.5" />
        <vers num="5.7.0" />
        <vers num="5.7.1" />
        <vers num="5.7.10" />
        <vers num="5.7.2" />
        <vers num="5.7.3" />
        <vers num="5.7.4" />
        <vers num="5.7.5" />
        <vers num="5.7.6" />
        <vers num="5.7.7" />
        <vers num="5.7.8" />
        <vers num="5.7.9" />
        <vers num="6.0" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.1.3_patch_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1159" published="2006-03-12" name="CVE-2006-1159" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25135" source="XF">easyfilesharing-logging-dos(25135)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0912" source="VUPEN">ADV-2006-0912</ref>
      <ref url="http://www.securityfocus.com/bid/17046" source="BID">17046</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427158/100/0/threaded" source="BUGTRAQ" adv="1">20060309 Easy File Sharing Web Server Multiple Vulnerablilities</ref>
      <ref url="http://www.osvdb.org/23792" source="OSVDB">23792</ref>
      <ref url="http://secunia.com/advisories/19178" source="SECUNIA" adv="1">19178</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efs_software" name="efs_web_server">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1160" published="2006-03-12" name="CVE-2006-1160" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or uploading a file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25136" source="XF">easyfilesharing-description-xss(25136)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0912" source="VUPEN">ADV-2006-0912</ref>
      <ref url="http://www.securityfocus.com/bid/17046" source="BID">17046</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427158/100/0/threaded" source="BUGTRAQ" adv="1">20060309 Easy File Sharing Web Server Multiple Vulnerablilities</ref>
      <ref url="http://www.osvdb.org/23793" source="OSVDB">23793</ref>
      <ref url="http://secunia.com/advisories/19178" source="SECUNIA" adv="1">19178</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efs_software" name="efs_web_server">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1161" published="2006-03-12" name="CVE-2006-1161" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17046" source="BID">17046</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427158/100/0/threaded" source="BUGTRAQ" adv="1">20060309 Easy File Sharing Web Server Multiple Vulnerablilities</ref>
      <ref url="http://www.osvdb.org/23791" source="OSVDB">23791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39994" source="XF">easyfilesharing-startup-file-upload(39994)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efs_software" name="efs_web_server">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1162" published="2006-03-12" name="CVE-2006-1162" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a ..  (dot dot) in the op parameter, as demonstrated by inserting malicious Email parameters into list.gtdat, then accessing list.gtdat using the op parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0899" source="VUPEN">ADV-2006-0899</ref>
      <ref url="http://secunia.com/advisories/19165" source="SECUNIA" adv="1">19165</ref>
      <ref url="http://hamid.ir/security/nodez.txt" source="MISC">http://hamid.ir/security/nodez.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25119" source="XF">nodez-op-file-include(25119)</ref>
      <ref url="http://www.securityfocus.com/bid/17066" source="BID">17066</ref>
      <ref url="http://www.osvdb.org/23774" source="OSVDB">23774</ref>
      <ref url="http://securitytracker.com/id?1015747" source="SECTRACK">1015747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nodez" name="nodez">
        <vers num="4.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1163" published="2006-03-12" name="CVE-2006-1163" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Nodez 4.6.1.1 allows remote attackers to inject arbitrary web script or HTML via the op parameter.  NOTE: it is possible that this issue is resultant from the directory traversal vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0899" source="VUPEN">ADV-2006-0899</ref>
      <ref url="http://secunia.com/advisories/19165" source="SECUNIA" adv="1">19165</ref>
      <ref url="http://hamid.ir/security/nodez.txt" source="MISC">http://hamid.ir/security/nodez.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25121" source="XF">nodez-op-xss(25121)</ref>
      <ref url="http://www.securityfocus.com/bid/17066" source="BID">17066</ref>
      <ref url="http://www.osvdb.org/23776" source="OSVDB">23776</ref>
      <ref url="http://securitytracker.com/id?1015747" source="SECTRACK">1015747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nodez" name="nodez">
        <vers num="4.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1164" published="2006-03-12" name="CVE-2006-1164" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://hamid.ir/security/nodez.txt" source="MISC">http://hamid.ir/security/nodez.txt</ref>
      <ref url="http://www.securityfocus.com/bid/17066" source="BID">17066</ref>
      <ref url="http://www.osvdb.org/23775" source="OSVDB">23775</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nodez" name="nodez">
        <vers num="4.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1165" published="2006-03-12" name="CVE-2006-1165" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19186" source="SECUNIA" patch="1" adv="1">19186</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0909" source="VUPEN">ADV-2006-0909</ref>
      <ref url="http://wiki.splitbrain.org/wiki%3Achanges" source="CONFIRM">http://wiki.splitbrain.org/wiki%3Achanges</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25137" source="XF">dokuwiki-mediamanger-xss(25137)</ref>
      <ref url="http://www.securityfocus.com/bid/17065" source="BID">17065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andreas_gohr" name="dokuwiki">
        <vers num="release_2004-07-04" />
        <vers num="release_2004-07-07" />
        <vers num="release_2004-07-12" />
        <vers num="release_2004-07-21" />
        <vers num="release_2004-07-25" />
        <vers num="release_2004-08-08" />
        <vers num="release_2004-08-15a" />
        <vers num="release_2004-08-22" />
        <vers num="release_2004-09-12" />
        <vers num="release_2004-09-25" />
        <vers num="release_2004-09-30" />
        <vers num="release_2004-10-19" />
        <vers num="release_2004-11-01" />
        <vers num="release_2004-11-02" />
        <vers num="release_2004-11-10" />
        <vers num="release_2005-01-14" />
        <vers num="release_2005-01-15" />
        <vers num="release_2005-01-16a" />
        <vers num="release_2005-02-06" />
        <vers num="release_2005-02-18" />
        <vers num="release_2005-05-07" />
        <vers num="release_2005-07-01" />
        <vers num="release_2005-07-13" />
        <vers num="release_2005-09-19" />
        <vers num="release_2005-09-22" />
        <vers num="release_2006-03-05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1166" published="2006-03-12" name="CVE-2006-1166" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.gnu.org/archive/html/monotone-devel/2006-03/msg00062.html" source="MLIST" patch="1">[Monotone-devel] 20060308 [ANNOUNCE] Monotone 0.25.2 -- security fix release</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0990" source="VUPEN">ADV-2006-0990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25294" source="XF">monotone-mt-lua-code-execution(25294)</ref>
      <ref url="http://www.securityfocus.com/bid/17139" source="BID">17139</ref>
      <ref url="http://secunia.com/advisories/19260" source="SECUNIA">19260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monotone" name="monotone">
        <vers num="0.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1167" published="2007-02-06" name="CVE-2006-1167" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information.</descript>
      <descript source="nvd">The attacker must read the contents of the screen after a reboot and before the screen contents can be cleared by anything.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI" patch="1">20060402-01-U</ref>
      <ref url="http://www.osvdb.org/24571" source="OSVDB" adv="1">24571</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1168" published="2006-08-14" name="CVE-2006-1168" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1149" source="DEBIAN" patch="1" adv="1">DSA-1149</ref>
      <ref url="http://secunia.com/advisories/21437" source="SECUNIA" patch="1" adv="1">21437</ref>
      <ref url="http://secunia.com/advisories/21434" source="SECUNIA" patch="1" adv="1">21434</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3234" source="VUPEN">ADV-2006-3234</ref>
      <ref url="http://secunia.com/advisories/21427" source="SECUNIA" adv="1">21427</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9373" source="OVAL">oval:org.mitre.oval:def:9373</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=141728" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=141728</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28315" source="XF">ncompress-decompress-underflow(28315)</ref>
      <ref url="http://www.securityfocus.com/bid/19455" source="BID">19455</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0663.html" source="REDHAT">RHSA-2006:0663</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_20_sr.html" source="SUSE">SUSE-SR:2006:020</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:140" source="MANDRIVA">MDKSA-2006:140</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-226.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-226.htm</ref>
      <ref url="http://securitytracker.com/id?1016836" source="SECTRACK">1016836</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200610-03.xml" source="GENTOO">GLSA-200610-03</ref>
      <ref url="http://secunia.com/advisories/22377" source="SECUNIA">22377</ref>
      <ref url="http://secunia.com/advisories/22296" source="SECUNIA">22296</ref>
      <ref url="http://secunia.com/advisories/22036" source="SECUNIA">22036</ref>
      <ref url="http://secunia.com/advisories/21880" source="SECUNIA">21880</ref>
      <ref url="http://secunia.com/advisories/21467" source="SECUNIA">21467</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc" source="SGI">20060901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncompress" name="ncompress">
        <vers num="4.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1172" published="2006-05-09" name="CVE-2006-1172" modified="2011-03-07" discovered="2006-05-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/25282" source="OSVDB" patch="1">25282</ref>
      <ref url="http://securitytracker.com/id?1016034" source="SECTRACK" patch="1">1016034</ref>
      <ref url="http://secunia.com/advisories/19968" source="SECUNIA" patch="1" adv="1">19968</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1675" source="VUPEN">ADV-2006-1675</ref>
      <ref url="http://www.securityfocus.com/bid/17852" source="BID">17852</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433079/100/0/threaded" source="BUGTRAQ" adv="1">20060505 Cryptomathic ActiveX Buffer Overflow (TDC Digital signature)</ref>
      <ref url="http://cirt.dk/advisories/cirt-43-advisory.pdf" source="MISC" adv="1">http://cirt.dk/advisories/cirt-43-advisory.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26255" source="XF">cryptomathic-primeink-createpkcs10-bo(26255)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tdc" name="cryptomathic_cenroll_activex_control">
        <vers num="1.1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1173" published="2006-06-07" name="CVE-2006-1173" modified="2011-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/146718" source="CERT-VN" adv="1">VU#146718</ref>
      <ref url="http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc" source="CONFIRM" patch="1" adv="1">http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc</ref>
      <ref url="http://www.securityfocus.com/bid/18433" source="BID" patch="1">18433</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1" source="SUNALERT" patch="1" adv="1">102460</ref>
      <ref url="http://secunia.com/advisories/20473" source="SECUNIA" patch="1" adv="1">20473</ref>
      <ref url="http://secunia.com/advisories/15779" source="SECUNIA" patch="1" adv="1">15779</ref>
      <ref url="https://issues.rpath.com/browse/RPL-526" source="CONFIRM">https://issues.rpath.com/browse/RPL-526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27128" source="XF">sendmail-multipart-mime-dos(27128)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3135" source="VUPEN">ADV-2006-3135</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2798" source="VUPEN">ADV-2006-2798</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2390" source="VUPEN">ADV-2006-2390</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2389" source="VUPEN" adv="1">ADV-2006-2389</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2388" source="VUPEN">ADV-2006-2388</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2351" source="VUPEN">ADV-2006-2351</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2189" source="VUPEN">ADV-2006-2189</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442939/100/0/threaded" source="HP">HPSBUX02124</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/442939/100/0/threaded" source="HP">SSRT061159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440744/100/0/threaded" source="BUGTRAQ">20060721 rPSA-2006-0134-1 sendmail sendmail-cf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438330/100/0/threaded" source="BUGTRAQ">20060624 Re: Sendmail MIME DoS vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438241/100/0/threaded" source="BUGTRAQ">20060621 Re: Sendmail MIME DoS vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437928/100/0/threaded" source="BUGTRAQ">20060620 Sendmail MIME DoS vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0515.html" source="REDHAT">RHSA-2006:0515</ref>
      <ref url="http://www.osvdb.org/26197" source="OSVDB">26197</ref>
      <ref url="http://www.openbsd.org/errata38.html#sendmail2" source="OPENBSD">[3.8] 008: SECURITY FIX: June 15, 2006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:104" source="MANDRIVA">MDKSA-2006:104</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml" source="GENTOO">GLSA-200606-19</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html" source="CONFIRM">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html</ref>
      <ref url="http://www.f-secure.com/security/fsc-2006-5.shtml" source="CONFIRM">http://www.f-secure.com/security/fsc-2006-5.shtml</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1155" source="DEBIAN">DSA-1155</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY85930&amp;apar=only" source="AIXAPAR">IY85930</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY85415&amp;apar=only" source="AIXAPAR">IY85415</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.631382" source="SLACKWARE">SSA:2006-166-01</ref>
      <ref url="http://securitytracker.com/id?1016295" source="SECTRACK">1016295</ref>
      <ref url="http://secunia.com/advisories/21647" source="SECUNIA" adv="1">21647</ref>
      <ref url="http://secunia.com/advisories/21612" source="SECUNIA" adv="1">21612</ref>
      <ref url="http://secunia.com/advisories/21327" source="SECUNIA" adv="1">21327</ref>
      <ref url="http://secunia.com/advisories/21160" source="SECUNIA" adv="1">21160</ref>
      <ref url="http://secunia.com/advisories/21042" source="SECUNIA" adv="1">21042</ref>
      <ref url="http://secunia.com/advisories/20782" source="SECUNIA" adv="1">20782</ref>
      <ref url="http://secunia.com/advisories/20726" source="SECUNIA" adv="1">20726</ref>
      <ref url="http://secunia.com/advisories/20694" source="SECUNIA" adv="1">20694</ref>
      <ref url="http://secunia.com/advisories/20684" source="SECUNIA" adv="1">20684</ref>
      <ref url="http://secunia.com/advisories/20683" source="SECUNIA" adv="1">20683</ref>
      <ref url="http://secunia.com/advisories/20679" source="SECUNIA" adv="1">20679</ref>
      <ref url="http://secunia.com/advisories/20675" source="SECUNIA" adv="1">20675</ref>
      <ref url="http://secunia.com/advisories/20673" source="SECUNIA" adv="1">20673</ref>
      <ref url="http://secunia.com/advisories/20654" source="SECUNIA" adv="1">20654</ref>
      <ref url="http://secunia.com/advisories/20651" source="SECUNIA" adv="1">20651</ref>
      <ref url="http://secunia.com/advisories/20650" source="SECUNIA" adv="1">20650</ref>
      <ref url="http://secunia.com/advisories/20641" source="SECUNIA" adv="1">20641</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11253" source="OVAL">oval:org.mitre.oval:def:11253</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html" source="SUSE">SUSE-SA:2006:032</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" source="HP">SSRT061135</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" source="HP">HPSBTU02116</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" source="SGI">20060602-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P" source="SGI">20060601-01-P</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc" source="FREEBSD">FreeBSD-SA-06:17.sendmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.10" />
        <vers num="8.10.1" />
        <vers num="8.10.2" />
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.11.6" />
        <vers num="8.11.7" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
        <vers num="8.12.0" />
        <vers num="8.12.1" />
        <vers num="8.12.10" />
        <vers num="8.12.11" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
        <vers num="8.12.9" />
        <vers num="8.13.0" />
        <vers num="8.13.1" />
        <vers num="8.13.1.2" />
        <vers num="8.13.2" />
        <vers num="8.13.3" />
        <vers num="8.13.4" />
        <vers num="8.13.5" />
        <vers prev="1" num="8.13.6" />
        <vers num="8.8.8" />
        <vers num="8.9.0" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1174" published="2006-05-28" name="CVE-2006-1174" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/312692" source="CERT-VN">VU#312692</ref>
      <ref url="http://www.securityfocus.com/bid/18111" source="BID" patch="1">18111</ref>
      <ref url="http://secunia.com/advisories/20370" source="SECUNIA" patch="1" adv="1">20370</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1357" source="CONFIRM">https://issues.rpath.com/browse/RPL-1357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26958" source="XF">shadow-utils-useradd-file-permission(26958)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN" adv="1">ADV-2007-3229</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2006" source="VUPEN" adv="1">ADV-2006-2006</ref>
      <ref url="http://www.securitytracker.com/id?1018221" source="SECTRACK">1018221</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468336/100/0/threaded" source="BUGTRAQ">20070511 rPSA-2007-0096-1 shadow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0431.html" source="REDHAT">RHSA-2007:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0276.html" source="REDHAT">RHSA-2007:0276</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:090" source="MANDRIVA">MDKSA-2006:090</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200606-02.xml" source="GENTOO">GLSA-200606-02</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-249.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-249.htm</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA" adv="1">27706</ref>
      <ref url="http://secunia.com/advisories/26909" source="SECUNIA" adv="1">26909</ref>
      <ref url="http://secunia.com/advisories/25896" source="SECUNIA" adv="1">25896</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA" adv="1">25894</ref>
      <ref url="http://secunia.com/advisories/25629" source="SECUNIA" adv="1">25629</ref>
      <ref url="http://secunia.com/advisories/25267" source="SECUNIA" adv="1">25267</ref>
      <ref url="http://secunia.com/advisories/25098" source="SECUNIA" adv="1">25098</ref>
      <ref url="http://secunia.com/advisories/20506" source="SECUNIA" adv="1">20506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10807" source="OVAL">oval:org.mitre.oval:def:10807</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="http://cvs.pld.org.pl/shadow/NEWS?rev=1.109" source="CONFIRM">http://cvs.pld.org.pl/shadow/NEWS?rev=1.109</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="shadow-utils">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.4" />
        <vers num="4.0.4.1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers prev="1" num="4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1175" published="2006-05-31" name="CVE-2006-1175" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/378604" source="CERT-VN">VU#378604</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2064" source="VUPEN">ADV-2006-2064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26752" source="XF">wodsftp-activex-unauth-access(26752)</ref>
      <ref url="http://www.securityfocus.com/bid/18192" source="BID">18192</ref>
      <ref url="http://secunia.com/advisories/20361" source="SECUNIA">20361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weonlydo" name="weonlydo_sftp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1176" published="2006-07-07" name="CVE-2006-1176" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Item (SYI), Setup &amp; Test eBay Enhanced Picture Services, Picture Manager Enhanced Uploader, and CARad.com Add Vehicle, allows remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/597721" source="CERT-VN">VU#597721</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27631" source="XF">ebay-epuimagecontrol-bo(27631)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2698" source="VUPEN">ADV-2006-2698</ref>
      <ref url="http://www.securityfocus.com/bid/18921" source="BID">18921</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MIMG-6QKPVH" source="CONFIRM">http://www.kb.cert.org/vuls/id/MIMG-6QKPVH</ref>
      <ref url="http://securitytracker.com/id?1016445" source="SECTRACK">1016445</ref>
      <ref url="http://secunia.com/advisories/20969" source="SECUNIA">20969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ebay" name="enhanced_picture_services">
        <vers prev="1" num="1.0.3.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1178" published="2006-07-28" name="CVE-2006-1178" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/372878" source="CERT-VN" patch="1">VU#372878</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28053" source="XF" patch="1">tamarack-mmsd-packet-dos(28053)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3080" source="VUPEN">ADV-2006-3080</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6RZPUT" source="CONFIRM">http://www.kb.cert.org/vuls/id/JGEI-6RZPUT</ref>
      <ref url="http://www.securityfocus.com/bid/19202" source="BID">19202</ref>
      <ref url="http://securitytracker.com/id?1016734" source="SECTRACK">1016734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tamarack_consulting" name="tamarack_mmsd">
        <vers num="7.991" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1182" published="2006-03-15" name="CVE-2006-1182" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17113" source="BID" patch="1">17113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427730/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060315 Secunia Research: Adobe Document/Graphics Server File URI ResourceAccess</ref>
      <ref url="http://www.adobe.com/support/techdocs/332989.html" source="CONFIRM" patch="1">http://www.adobe.com/support/techdocs/332989.html</ref>
      <ref url="http://securitytracker.com/id?1015769" source="SECTRACK" patch="1" adv="1">1015769</ref>
      <ref url="http://secunia.com/advisories/19229" source="SECUNIA" patch="1" adv="1">19229</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25247" source="XF">adobe-unauth-command-access(25247)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0956" source="VUPEN">ADV-2006-0956</ref>
      <ref url="http://www.osvdb.org/23924" source="OSVDB">23924</ref>
      <ref url="http://securitytracker.com/id?1015768" source="SECTRACK">1015768</ref>
      <ref url="http://securityreason.com/securityalert/588" source="SREASON">588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="document_server">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
      <prod vendor="adobe" name="graphics_server">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1183" published="2006-03-13" name="CVE-2006-1183" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-262-1" source="UBUNTU" patch="1">USN-262-1</ref>
      <ref url="https://launchpad.net/distros/ubuntu/+source/shadow/+bug/34606" source="CONFIRM">https://launchpad.net/distros/ubuntu/+source/shadow/+bug/34606</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0927" source="VUPEN">ADV-2006-0927</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25170" source="XF">ubuntu-installer-password-disclosure(25170)</ref>
      <ref url="http://www.securityfocus.com/bid/17086" source="BID">17086</ref>
      <ref url="http://www.osvdb.org/23868" source="OSVDB">23868</ref>
      <ref url="http://securitytracker.com/id?1015761" source="SECTRACK">1015761</ref>
      <ref url="http://secunia.com/advisories/19200" source="SECUNIA">19200</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1184" published="2006-05-09" name="CVE-2006-1184" modified="2011-03-07" discovered="2005-10-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17905" source="BID" patch="1">17905</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433425/100/0/threaded" source="BUGTRAQ" patch="1">20060509 [EEYEB20051011B] - Microsoft Distributed Transaction Coordinator Denial of Service</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx" source="MS" patch="1">MS06-018</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20060509b.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20060509b.html</ref>
      <ref url="http://secunia.com/advisories/20000" source="SECUNIA" patch="1" adv="1">20000</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1742" source="VUPEN">ADV-2006-1742</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25558" source="XF">msdtc-message-dos(25558)</ref>
      <ref url="http://www.osvdb.org/25336" source="OSVDB">25336</ref>
      <ref url="http://securitytracker.com/id?1016047" source="SECTRACK">1016047</ref>
      <ref url="http://securityreason.com/securityalert/864" source="SREASON">864</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1990" source="OVAL" sig="1">oval:org.mitre.oval:def:1990</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1912" source="OVAL" sig="1">oval:org.mitre.oval:def:1912</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1779" source="OVAL" sig="1">oval:org.mitre.oval:def:1779</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1295" source="OVAL" sig="1">oval:org.mitre.oval:def:1295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="distributed_transaction_coordinator">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1185" published="2006-04-11" name="CVE-2006-1185" modified="2011-03-07" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/503124" source="CERT-VN">VU#503124</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS" patch="1">MS06-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25542" source="XF">ie-html-execute-code(25542)</ref>
      <ref url="http://www.securityfocus.com/bid/17450" source="BID">17450</ref>
      <ref url="http://securitytracker.com/id?1015900" source="SECTRACK">1015900</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA">18957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:787" source="OVAL" sig="1">oval:org.mitre.oval:def:787</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1711" source="OVAL" sig="1">oval:org.mitre.oval:def:1711</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1677" source="OVAL" sig="1">oval:org.mitre.oval:def:1677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="windows_2000_sp4" />
        <vers num="6" edition="" />
        <vers num="6" edition=":windows_xp_professional_64bit" />
        <vers num="6" edition="sp1" />
        <vers num="6" edition="sp1:windows_xpsp1" />
        <vers num="6" edition="windows_2000_sp4" />
        <vers num="6" edition="windows_server_2003_sp1" />
        <vers num="6" edition="windows_server_2003_sp1_itanium_systems" />
        <vers num="6" edition="windows_xp_sp2" />
      </prod>
      <prod vendor="canon" name="network_camera_server_vb101">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1186" published="2006-04-11" name="CVE-2006-1186" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/959049" source="CERT-VN">VU#959049</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA" patch="1" adv="1">18957</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.securityfocus.com/bid/17453" source="BID">17453</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS">MS06-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25545" source="XF">ie-com-activex-execute-code(25545)</ref>
      <ref url="http://securitytracker.com/id?1015900" source="SECTRACK">1015900</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:791" source="OVAL" sig="1">oval:org.mitre.oval:def:791</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1704" source="OVAL" sig="1">oval:org.mitre.oval:def:1704</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1651" source="OVAL" sig="1">oval:org.mitre.oval:def:1651</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1589" source="OVAL" sig="1">oval:org.mitre.oval:def:1589</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1446" source="OVAL" sig="1">oval:org.mitre.oval:def:1446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows_95" />
        <vers num="5.0.1" edition=":windows_nt_4.0" />
        <vers num="5.0.1" edition=":windows_2000" />
        <vers num="5.0.1" edition=":windows_98" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.01" edition="sp1" />
        <vers num="5.01" edition="sp2" />
        <vers num="5.01" edition="sp3" />
        <vers num="5.01" edition="sp4" />
        <vers num="5.01" edition="windows_2000_sp4" />
        <vers num="5.1" />
        <vers num="5.5" edition="preview" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1188" published="2006-04-11" name="CVE-2006-1188" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/824324" source="CERT-VN" patch="1">VU#824324</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS" patch="1">MS06-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435096/30/4710/threaded" source="BUGTRAQ">20060525 [BuHa-Security] MS06-013: HTML Tag Memory Corruption Vulnerability in MS IE 6 SP2</ref>
      <ref url="http://securitytracker.com/id?1015900" source="SECTRACK">1015900</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA">18957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1773" source="OVAL" sig="1">oval:org.mitre.oval:def:1773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1296" source="OVAL" sig="1">oval:org.mitre.oval:def:1296</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1290" source="OVAL" sig="1">oval:org.mitre.oval:def:1290</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1144" source="OVAL" sig="1">oval:org.mitre.oval:def:1144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":mac_os" />
        <vers num="5.2.3" edition="" />
        <vers num="5.2.3" edition=":macintosh" />
        <vers num="5.5" edition="preview" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6" edition="" />
        <vers num="6" edition=":windows_xp_professional_64bit" />
        <vers num="6" edition="sp1" />
        <vers num="6" edition="sp1:windows_xpsp1" />
        <vers num="6" edition="windows_2000_sp4" />
        <vers num="6" edition="windows_server_2003_sp1" />
        <vers num="6" edition="windows_server_2003_sp1_itanium_systems" />
        <vers num="6" edition="windows_xp_sp2" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows_server_2003" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0.2600" />
        <vers num="6.0.2800" />
        <vers num="6.0.2800.1106" />
        <vers num="6.0.2900.2180" />
      </prod>
      <prod vendor="canon" name="network_camera_server_vb101">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1189" published="2006-04-11" name="CVE-2006-1189" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</descript>
    </desc>
    <sols>
      <sol source="nvd">Customers should apply the update immediately.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/341028" source="CERT-VN">VU#341028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25551" source="XF">ie-double-byte-execute-code(25551)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN" adv="1">ADV-2006-1318</ref>
      <ref url="http://www.securityfocus.com/bid/17454" source="BID">17454</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS">MS06-013</ref>
      <ref url="http://securitytracker.com/id?1015900" source="SECTRACK">1015900</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA" adv="1">18957</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0227.html" source="BUGTRAQ">20060411 Microsoft Internet Explorer DBCS Remote Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:792" source="OVAL" sig="1">oval:org.mitre.oval:def:792</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1484" source="OVAL" sig="1">oval:org.mitre.oval:def:1484</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1020" source="OVAL" sig="1">oval:org.mitre.oval:def:1020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.1" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1190" published="2006-04-11" name="CVE-2006-1190" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/959649" source="CERT-VN">VU#959649</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS">MS06-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25552" source="XF">ie-ioleclientsite-execute-code(25552)</ref>
      <ref url="http://www.securityfocus.com/bid/17455" source="BID">17455</ref>
      <ref url="http://securitytracker.com/id?1015900" source="SECTRACK">1015900</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA">18957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:965" source="OVAL" sig="1">oval:org.mitre.oval:def:965</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1783" source="OVAL" sig="1">oval:org.mitre.oval:def:1783</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1735" source="OVAL" sig="1">oval:org.mitre.oval:def:1735</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1541" source="OVAL" sig="1">oval:org.mitre.oval:def:1541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.1" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1191" published="2006-04-11" name="CVE-2006-1191" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS">MS06-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25555" source="XF">ie-popup-zone-bypass(25555)</ref>
      <ref url="http://www.securityfocus.com/bid/17457" source="BID">17457</ref>
      <ref url="http://securitytracker.com/id?1015892" source="SECTRACK">1015892</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA">18957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1710" source="OVAL" sig="1">oval:org.mitre.oval:def:1710</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1251" source="OVAL" sig="1">oval:org.mitre.oval:def:1251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.1" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1192" published="2006-04-11" name="CVE-2006-1192" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17460" source="BID" patch="1">17460</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS" patch="1" adv="1">MS06-013</ref>
      <ref url="http://securitytracker.com/id?1015899" source="SECTRACK" patch="1">1015899</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA" patch="1" adv="1">18957</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25557" source="XF">ie-browser-window-spoofing(25557)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN" adv="1">ADV-2006-1318</ref>
      <ref url="http://securityreason.com/securityalert/670" source="SREASON">670</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1740" source="OVAL" sig="1">oval:org.mitre.oval:def:1740</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1725" source="OVAL" sig="1">oval:org.mitre.oval:def:1725</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1645" source="OVAL" sig="1">oval:org.mitre.oval:def:1645</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1498" source="OVAL" sig="1">oval:org.mitre.oval:def:1498</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1336" source="OVAL" sig="1">oval:org.mitre.oval:def:1336</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="windows_2000_sp4" />
        <vers num="6" edition="" />
        <vers num="6" edition=":windows_xp_professional_64bit" />
        <vers num="6" edition="sp1" />
        <vers num="6" edition="sp1:windows_xpsp1" />
        <vers num="6" edition="windows_2000_sp4" />
        <vers num="6" edition="windows_server_2003_sp1" />
        <vers num="6" edition="windows_server_2003_sp1_itanium_systems" />
        <vers num="6" edition="windows_xp_sp2" />
      </prod>
      <prod vendor="canon" name="network_camera_server_vb101">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1193" published="2006-06-13" name="CVE-2006-1193" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" source="CERT">TA06-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/138188" source="CERT-VN">VU#138188</ref>
      <ref url="http://www.securityfocus.com/bid/18381" source="BID" patch="1">18381</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-029.mspx" source="MS" patch="1" adv="1">MS06-029</ref>
      <ref url="http://securitytracker.com/id?1016280" source="SECTRACK" patch="1">1016280</ref>
      <ref url="http://secunia.com/advisories/20634" source="SECUNIA" patch="1" adv="1">20634</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2326" source="VUPEN">ADV-2006-2326</ref>
      <ref url="http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txt" source="MISC">http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txt</ref>
      <ref url="http://www.osvdb.org/26441" source="OSVDB">26441</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25550" source="XF">exchange-owa-xss(25550)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046892.html" source="FULLDISC">20060614 SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1315" source="OVAL" sig="1">oval:org.mitre.oval:def:1315</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1161" source="OVAL" sig="1">oval:org.mitre.oval:def:1161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1070" source="OVAL" sig="1">oval:org.mitre.oval:def:1070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1194" published="2006-03-13" name="CVE-2006-1194" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0940" source="VUPEN">ADV-2006-0940</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427465/100/0/threaded" source="BUGTRAQ" adv="1">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref>
      <ref url="http://secunia.com/advisories/19208" source="SECUNIA" adv="1">19208</ref>
      <ref url="http://aluigi.altervista.org/adv/enetx-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/enetx-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25157" source="XF">enet-signedness-dos(25157)</ref>
      <ref url="http://www.securityfocus.com/bid/17087" source="BID">17087</ref>
      <ref url="http://www.osvdb.org/23844" source="OSVDB">23844</ref>
      <ref url="http://securitytracker.com/id?1015767" source="SECTRACK">1015767</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043541.html" source="FULLDISC">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enet" name="enet_library">
        <vers prev="1" num="jul_2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1195" published="2006-03-13" name="CVE-2006-1195" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The enet_protocol_handle_send_fragment function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet fragment with a large total data size, which triggers an application abort when memory allocation fails.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0940" source="VUPEN">ADV-2006-0940</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427465/100/0/threaded" source="BUGTRAQ" adv="1">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref>
      <ref url="http://secunia.com/advisories/19208" source="SECUNIA" adv="1">19208</ref>
      <ref url="http://aluigi.altervista.org/adv/enetx-adv.txt" source="MISC">http://aluigi.altervista.org/adv/enetx-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25158" source="XF">enet-packet-dos(25158)</ref>
      <ref url="http://www.securityfocus.com/bid/17087" source="BID">17087</ref>
      <ref url="http://www.osvdb.org/23845" source="OSVDB">23845</ref>
      <ref url="http://securitytracker.com/id?1015767" source="SECTRACK">1015767</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043541.html" source="FULLDISC">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enet" name="enet_library">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1196" published="2006-03-13" name="CVE-2006-1196" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25128" source="XF">qwikiwiki-multiple-scripts-xss(25128)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0910" source="VUPEN">ADV-2006-0910</ref>
      <ref url="http://www.securityfocus.com/bid/17064" source="BID">17064</ref>
      <ref url="http://secunia.com/advisories/19182" source="SECUNIA" adv="1">19182</ref>
      <ref url="http://kiki91.altervista.org/exploit/qwikiwiki_1.0.5_xss.txt" source="MISC">http://kiki91.altervista.org/exploit/qwikiwiki_1.0.5_xss.txt</ref>
      <ref url="http://www.osvdb.org/23789" source="OSVDB">23789</ref>
      <ref url="http://www.osvdb.org/23788" source="OSVDB">23788</ref>
      <ref url="http://www.osvdb.org/23787" source="OSVDB">23787</ref>
      <ref url="http://www.osvdb.org/23786" source="OSVDB">23786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_barrett" name="qwikiwiki">
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1197" published="2006-03-13" name="CVE-2006-1197" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SafeDisc installs the driver service for the secdrv.sys driver with insecure permissions, which allows local users to gain privileges by changing the configuration to reference a malicious program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17070" source="BID">17070</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427410/100/0/threaded" source="BUGTRAQ" adv="1">20060311 Copy protection scheme SafeDisc allows privilege escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25162" source="XF">safedisk-secdrv-gain-privileges(25162)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="safedisc">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1198" published="2006-03-13" name="CVE-2006-1198" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0866" source="VUPEN">ADV-2006-0866</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426935/100/0/threaded" source="BUGTRAQ" adv="1">20060306 IM Lock 2006 - Insecure Registry Permission Vulnerability</ref>
      <ref url="http://secunia.com/advisories/19140" source="SECUNIA" adv="1">19140</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25219" source="XF">imlock-password-weak-encryption(25219)</ref>
      <ref url="http://www.securityfocus.com/bid/16988" source="BID">16988</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comvigo" name="im_lock">
        <vers num="home_2006" />
        <vers num="professional_2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1199" published="2006-03-13" name="CVE-2006-1199" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0885" source="VUPEN">ADV-2006-0885</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426932/100/0/threaded" source="BUGTRAQ" adv="1">20060306 link bank code execution and xss</ref>
      <ref url="http://secunia.com/advisories/19154" source="SECUNIA" adv="1">19154</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25107" source="XF">linkbank-iframe-xss(25107)</ref>
      <ref url="http://www.securityfocus.com/bid/17001" source="BID">17001</ref>
      <ref url="http://www.osvdb.org/23751" source="OSVDB">23751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daverave" name="link_bank">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1200" published="2006-03-13" name="CVE-2006-1200" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being stored in links.txt, which is later used in an include statement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0885" source="VUPEN">ADV-2006-0885</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426932/100/0/threaded" source="BUGTRAQ" adv="1">20060306 link bank code execution and xss</ref>
      <ref url="http://secunia.com/advisories/19154" source="SECUNIA" adv="1">19154</ref>
      <ref url="http://www.securityfocus.com/bid/17004" source="BID">17004</ref>
      <ref url="http://www.osvdb.org/23750" source="OSVDB">23750</ref>
      <ref url="http://securityreason.com/securityalert/553" source="SREASON">553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daverave" name="link_bank">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1201" published="2006-03-13" name="CVE-2006-1201" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a "Recover password" operation (recoverpw.php).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25080" source="XF">phpbannerexchange-recoverpw-dir-traversal(25080)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25071" source="XF">phpbannerexchange-resetpw-dir-traversal(25071)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0869" source="VUPEN">ADV-2006-0869</ref>
      <ref url="http://www.securityfocus.com/bid/16996" source="BID">16996</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426940/100/0/threaded" source="BUGTRAQ" adv="1">20060307 phpBannerExchange 2.0 Directory Traversal Vulnerability</ref>
      <ref url="http://www.osvdb.org/23720" source="OSVDB">23720</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-004-phpbanner.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-004-phpbanner.txt</ref>
      <ref url="http://www.eschew.net/scripts/phpbe/2.0/releasenotes.php" source="CONFIRM">http://www.eschew.net/scripts/phpbe/2.0/releasenotes.php</ref>
      <ref url="http://secunia.com/advisories/19127" source="SECUNIA" adv="1">19127</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0879.html" source="FULLDISC">20060307 phpBannerExchange 2.0 Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eschew.net" name="phpbannerexchange">
        <vers num="2.0" />
        <vers num="2.0_update_1" />
        <vers num="2.0_update_2" />
        <vers num="2.0_update_3" />
        <vers num="2.0_update_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1202" published="2006-03-13" name="CVE-2006-1202" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0897" source="VUPEN">ADV-2006-0897</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427081/100/0/threaded" source="BUGTRAQ">20060308 textfileBB &lt;= 1.0 Multiple XSS</ref>
      <ref url="http://secunia.com/advisories/19149" source="SECUNIA" adv="1">19149</ref>
      <ref url="http://notlegal.ws/textfilebbmessanger.txt" source="MISC">http://notlegal.ws/textfilebbmessanger.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25091" source="XF">textbb-messanger-xss(25091)</ref>
      <ref url="http://www.securityfocus.com/bid/17029" source="BID">17029</ref>
      <ref url="http://securitytracker.com/id?1015744" source="SECTRACK">1015744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jcink.com" name="textfilebb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1203" published="2006-03-13" name="CVE-2006-1203" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in common.php in txtForum 1.0.4-dev and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the skin parameter to login.php, and possibly other parameters to other PHP scripts, related to include statements in common.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427188/100/0/threaded" source="BUGTRAQ" adv="1">20060309 txtForum: Script Injection Vulnerability</ref>
      <ref url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-004.txt" source="MISC" adv="1">http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-004.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25131" source="XF">txtforum-login-file-include(25131)</ref>
      <ref url="http://www.securityfocus.com/bid/17061" source="BID">17061</ref>
      <ref url="http://www.osvdb.org/23952" source="OSVDB">23952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="txtforum" name="txtforum">
        <vers prev="1" num="1.0.4_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1204" published="2006-03-13" name="CVE-2006-1204" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in txtForum 1.0.4-dev and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prev, (2) next, and (3) rand5 parameters in (a) index.php; the (4) r_username and (5) r_loc parameters in (b) new_topic.php; the (6) r_num, (7) r_family_name, (8) r_icq, (9) r_yahoo, (10) r_aim, (11) r_homepage, (12) r_interests, (13) r_about, (14) selected1, (15) selected0, (16) signature_selected1, (17) signature_selected0, (18) smile_selected1, (19) smile_selected0, (20) ubb_selected1, and (21) ubb_selected0 parameters in (c) profile.php; the (22) quote and (23) tid parameters in (d) reply.php; and the (24) tid, (25) sticked, and (26) mid parameters in (e) view_topic.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427186/100/0/threaded" source="BUGTRAQ" adv="1">20060309 txtForum: Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-003.txt" source="MISC" adv="1">http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-003.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25132" source="XF">txtforum-multiple-xss(25132)</ref>
      <ref url="http://www.securityfocus.com/bid/17054" source="BID">17054</ref>
      <ref url="http://www.osvdb.org/23957" source="OSVDB">23957</ref>
      <ref url="http://www.osvdb.org/23956" source="OSVDB">23956</ref>
      <ref url="http://www.osvdb.org/23955" source="OSVDB">23955</ref>
      <ref url="http://www.osvdb.org/23954" source="OSVDB">23954</ref>
      <ref url="http://www.osvdb.org/23953" source="OSVDB">23953</ref>
    </refs>
    <vuln_soft>
      <prod vendor="txtforum" name="txtforum">
        <vers prev="1" num="1.0.4_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1205" published="2006-03-13" name="CVE-2006-1205" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message parameters in (b) upload.php, the (5) errormsg parameter in (c) addcat.php, (d) edituser.php, (e) adduser.php, and (f) editcat.php, the (6) trackback_url parameter in (g) add.php, (7) id parameter in (h) deluser.php, (8) cat_id parameter in (i) delcat.php, and (9) post_id parameter in (j) del.php, as reachable from admin.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25134" source="XF">mybloggie-index-admin-xss(25134)</ref>
      <ref url="http://www.securityfocus.com/bid/17048" source="BID">17048</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427182/100/0/threaded" source="BUGTRAQ" adv="1">20060309 MyBloggie: Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-002.txt" source="MISC" adv="1">http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-002.txt</ref>
      <ref url="http://www.osvdb.org/23992" source="OSVDB">23992</ref>
      <ref url="http://www.osvdb.org/23991" source="OSVDB">23991</ref>
      <ref url="http://www.osvdb.org/23990" source="OSVDB">23990</ref>
      <ref url="http://www.osvdb.org/23989" source="OSVDB">23989</ref>
      <ref url="http://www.osvdb.org/23988" source="OSVDB">23988</ref>
      <ref url="http://www.osvdb.org/23987" source="OSVDB">23987</ref>
      <ref url="http://www.osvdb.org/23986" source="OSVDB">23986</ref>
      <ref url="http://www.osvdb.org/23975" source="OSVDB">23975</ref>
      <ref url="http://www.osvdb.org/23974" source="OSVDB">23974</ref>
      <ref url="http://www.osvdb.org/23973" source="OSVDB">23973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1206" published="2006-03-13" name="CVE-2006-1206" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17024" source="BID" patch="1">17024</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25075" source="XF">dropbear-connection-dos(25075)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426999/100/0/threaded" source="BUGTRAQ" adv="1">20060307 Dropbear SSH server Denial of Service</ref>
      <ref url="http://securitytracker.com/id?1015742" source="SECTRACK">1015742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_johnston" name="dropbear_ssh_server">
        <vers num="0.28" />
        <vers num="0.29" />
        <vers num="0.30" />
        <vers num="0.31" />
        <vers num="0.32" />
        <vers num="0.33" />
        <vers num="0.34" />
        <vers num="0.35" />
        <vers num="0.36" />
        <vers num="0.37" />
        <vers num="0.38" />
        <vers num="0.39" />
        <vers num="0.40" />
        <vers num="0.41" />
        <vers num="0.42" />
        <vers num="0.43" />
        <vers num="0.44" />
        <vers num="0.45" />
        <vers num="0.46" />
        <vers num="0.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1207" published="2006-03-13" name="CVE-2006-1207" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427215/100/0/threaded" source="BUGTRAQ">20060309 PHP Upload Center Download users password hashes And phpshell Upload</ref>
      <ref url="http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html" source="MISC">http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html</ref>
      <ref url="http://www.blogcu.com/Liz0ziM/317250/" source="MISC">http://www.blogcu.com/Liz0ziM/317250/</ref>
      <ref url="http://biyosecurity.be/bugs/phpuploadcenter2.txt" source="MISC">http://biyosecurity.be/bugs/phpuploadcenter2.txt</ref>
      <ref url="http://www.osvdb.org/23627" source="OSVDB">23627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_korostel" name="php_upload_center">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1208" published="2006-03-13" name="CVE-2006-1208" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0817" source="VUPEN">ADV-2006-0817</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427215/100/0/threaded" source="BUGTRAQ">20060309 PHP Upload Center Download users password hashes And phpshell Upload</ref>
      <ref url="http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html" source="MISC">http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html</ref>
      <ref url="http://www.osvdb.org/23626" source="OSVDB">23626</ref>
      <ref url="http://www.blogcu.com/Liz0ziM/317250/" source="MISC">http://www.blogcu.com/Liz0ziM/317250/</ref>
      <ref url="http://secunia.com/advisories/19107" source="SECUNIA" adv="1">19107</ref>
      <ref url="http://biyosecurity.be/bugs/phpuploadcenter2.txt" source="MISC">http://biyosecurity.be/bugs/phpuploadcenter2.txt</ref>
      <ref url="http://securityreason.com/securityalert/564" source="SREASON">564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_korostel" name="php_upload_center">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1209" published="2006-03-13" name="CVE-2006-1209" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427216/100/0/threaded" source="BUGTRAQ">20060309 PHP Advanced Transfer Manager Download users password hashes</ref>
      <ref url="http://www.blogcu.com/Liz0ziM/316652/" source="MISC">http://www.blogcu.com/Liz0ziM/316652/</ref>
      <ref url="http://biyosecurity.be/bugs/patm.txt" source="MISC">http://biyosecurity.be/bugs/patm.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25127" source="XF">phpatm-password-hash-disclosure(25127)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437513/100/200/threaded" source="BUGTRAQ">20060613 Re: PHP Advanced Transfer Manager Download users password hashes</ref>
      <ref url="http://securityreason.com/securityalert/565" source="SREASON">565</ref>
      <ref url="http://secunia.com/advisories/17134" source="SECUNIA">17134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bugada_andrea" name="php_advanced_transfer_manager">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1210" published="2006-03-13" name="CVE-2006-1210" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427155/100/0/threaded" source="BUGTRAQ" adv="1">20060308 Remote access to NeuSecure/Netcool backend database via web interface credentials leakage</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25270" source="XF">netcool-neusecure-ns-unauth-access(25270)</ref>
      <ref url="http://www.securityfocus.com/bid/17032" source="BID">17032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micromuse" name="netcool_neusecure">
        <vers num="3.0.236" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1211" published="2006-03-13" name="CVE-2006-1211" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Netcool/NeuSecure application layer and perform unauthorized database actions.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427155/100/0/threaded" source="BUGTRAQ" adv="1">20060308 Remote access to NeuSecure/Netcool backend database via web interface credentials leakage</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25270" source="XF">netcool-neusecure-ns-unauth-access(25270)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micromuse" name="netcool_neusecure">
        <vers num="3.0.236" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1212" published="2006-03-13" name="CVE-2006-1212" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability.  NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use a "page" parameter or variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25180" source="XF">corenews-index-command-execution(25180)</ref>
      <ref url="http://www.securityfocus.com/bid/17067" source="BID">17067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427387/100/0/threaded" source="BUGTRAQ">20060309 CoreNews 2.0.1 Remote Command Exucetion</ref>
      <ref url="http://web.archive.org/web/20050323212004/www.coreslawn.de/?show=downloads&amp;cat_id=1" source="MISC">http://web.archive.org/web/20050323212004/www.coreslawn.de/?show=downloads&amp;cat_id=1</ref>
      <ref url="http://www.osvdb.org/24080" source="OSVDB">24080</ref>
      <ref url="http://securityreason.com/securityalert/754" source="SREASON">754</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000602.html" source="VIM">20060313 Oddness - CoreNews 2.0.1 Remote Command Exucetion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corenews" name="corenews">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1213" published="2006-03-13" name="CVE-2006-1213" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0911" source="VUPEN">ADV-2006-0911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427326/100/0/threaded" source="BUGTRAQ">20060309 Advisory: Jiros Banner Experience Pro Remote Privilege Escalation.</ref>
      <ref url="http://www.nukedx.com/?viewdoc=19" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=19</ref>
      <ref url="http://secunia.com/advisories/19184" source="SECUNIA" adv="1">19184</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25169" source="XF">jbspro-security-bypass(25169)</ref>
      <ref url="http://www.securityfocus.com/bid/17060" source="BID">17060</ref>
      <ref url="http://www.osvdb.org/23780" source="OSVDB">23780</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0211.html" source="FULLDISC">20060309 Advisory: Jiros Banner Experience Pro Remote Privilege Escalation.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jiro" name="banner_system">
        <vers num="1.0_experience" />
        <vers num="1.0_professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1214" published="2006-03-13" name="CVE-2006-1214" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, as demonstrated by "TKL - q\x08Q *\x08PoC."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23778" source="OSVDB" patch="1">23778</ref>
      <ref url="http://secunia.com/advisories/19188" source="SECUNIA" patch="1" adv="1">19188</ref>
      <ref url="http://forums.unrealircd.com/viewtopic.php?t=2985" source="MISC" patch="1">http://forums.unrealircd.com/viewtopic.php?t=2985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25130" source="XF">unrealircd-server-link-dos(25130)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0908" source="VUPEN">ADV-2006-0908</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427213/100/0/threaded" source="BUGTRAQ">20060309 UnrealIRCd3.2.3 Server-Link Denial of Service</ref>
      <ref url="http://www.securityfocus.com/bid/17057" source="BID">17057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unreal" name="unrealircd">
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1215" published="2006-03-13" name="CVE-2006-1215" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter.  NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16959" source="BID">16959</ref>
      <ref url="http://www.securityfocus.com/archive/1/426816/30/0/threaded" source="BUGTRAQ">20060304 Re: Wbb 2.3. xss</ref>
      <ref url="http://www.securityfocus.com/archive/1/426766" source="BUGTRAQ">20060304 Wbb 2.3. xss</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25156" source="XF">wbb-misc-xss(25156)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1216" published="2006-03-13" name="CVE-2006-1216" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18997" source="SECUNIA" patch="1" adv="1">18997</ref>
      <ref url="http://www.securityfocus.com/bid/16970" source="BID">16970</ref>
      <ref url="http://www.securityfocus.com/archive/1/426829" source="BUGTRAQ" adv="1">20060304 [KAPDA::#31] - Runcms 1.x Cross_Site_Scripting vulnerability in bigshow.php</ref>
      <ref url="http://www.kapda.ir/advisory-280.html" source="MISC" adv="1">http://www.kapda.ir/advisory-280.html</ref>
      <ref url="http://www.osvdb.org/23823" source="OSVDB">23823</ref>
      <ref url="http://securityreason.com/securityalert/474" source="SREASON">474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.3a" />
        <vers num="1.3a2" />
        <vers num="1.3a5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1217" published="2006-03-13" name="CVE-2006-1217" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in DSPoll 1.1 allows remote attackers to execute arbitrary SQL commands via the pollid parameter to (1) results.php, (2) topolls.php, (3) pollit.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0932" source="VUPEN">ADV-2006-0932</ref>
      <ref url="http://secunia.com/advisories/19209" source="SECUNIA" adv="1">19209</ref>
      <ref url="http://evuln.com/vulns/96/summary.html" source="MISC" adv="1">http://evuln.com/vulns/96/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25192" source="XF">dspoll-pollid-sql-injection(25192)</ref>
      <ref url="http://www.securityfocus.com/bid/17103" source="BID">17103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428663/100/0/threaded" source="BUGTRAQ">20060324 [eVuln] DSPoll Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23881" source="OSVDB">23881</ref>
      <ref url="http://www.osvdb.org/23880" source="OSVDB">23880</ref>
      <ref url="http://www.osvdb.org/23879" source="OSVDB">23879</ref>
      <ref url="http://securitytracker.com/id?1015758" source="SECTRACK">1015758</ref>
      <ref url="http://securityreason.com/securityalert/622" source="SREASON">622</ref>
      <ref url="http://securityreason.com/securityalert/620" source="SREASON">620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dsportal" name="dspoll">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1218" published="2006-03-13" name="CVE-2006-1218" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17031" source="BID" patch="1">17031</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972993.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972993.htm</ref>
      <ref url="http://secunia.com/advisories/19163" source="SECUNIA" patch="1" adv="1">19163</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0879" source="VUPEN">ADV-2006-0879</ref>
      <ref url="http://www.osvdb.org/23752" source="OSVDB">23752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="bordermanager">
        <vers num="3.8" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1219" published="2006-03-13" name="CVE-2006-1219" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19175" source="SECUNIA" patch="1" adv="1">19175</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25129" source="XF">gallery-multiple-index-file-include(25129)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0895" source="VUPEN">ADV-2006-0895</ref>
      <ref url="http://milw0rm.com/exploits/1566" source="MILW0RM">1566</ref>
      <ref url="http://gallery.menalto.com/2.0.4_and_2.1_rc_2a_update" source="CONFIRM">http://gallery.menalto.com/2.0.4_and_2.1_rc_2a_update</ref>
      <ref url="http://www.securityfocus.com/bid/17051" source="BID">17051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0_alpha" />
        <vers num="2.0_alpha1" />
        <vers num="2.0_alpha2" />
        <vers num="2.0_alpha3" />
        <vers num="2.0_alpha4" />
        <vers num="2.0_beta1" />
        <vers num="2.0_beta2" />
        <vers num="2.0_beta3" />
        <vers num="2.1_rc1" />
        <vers num="2.1_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1220" published="2006-03-13" name="CVE-2006-1220" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17056" source="BID">17056</ref>
      <ref url="http://www.felinemenace.org/~nemo/" source="MISC">http://www.felinemenace.org/~nemo/</ref>
      <ref url="http://www.osvdb.org/28453" source="OSVDB">28453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1221" published="2006-03-14" name="CVE-2006-1221" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm's own folders before other folders that are specified in a user's PATH, which might allow local users to execute code as SYSTEM by placing malicious DLLs into a folder that has insecure permissions, but is searched before ZoneAlarm's folder.  NOTE: since this issue is dependent on the existence of a vulnerability in a separate product (weak permissions of executables or libraries, or the execution of malicious code), perhaps it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0947" source="VUPEN">ADV-2006-0947</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427309/100/0/threaded" source="BUGTRAQ" adv="1">20060309 Statement Regarding Reported Local Escalation of Privileges Vulnerability for ZoneAlarm</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427145/100/0/threaded" source="BUGTRAQ">20060309 Re: 18 ways to escalate privileges in Zone Labs ZoneAlarm Security Suite build 6.1.744.000</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427122/100/0/threaded" source="BUGTRAQ">20060308 18 ways to escalate privileges in Zone Labs ZoneAlarm Security Suite build 6.1.744.000</ref>
      <ref url="http://securitytracker.com/id?1015743" source="SECTRACK">1015743</ref>
      <ref url="http://reedarvin.thearvins.com/20060308-01.html" source="MISC">http://reedarvin.thearvins.com/20060308-01.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25097" source="XF">zonealarm-path-gain-privileges(25097)</ref>
      <ref url="http://www.securityfocus.com/bid/17037" source="BID">17037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm_security_suite">
        <vers num="6.1.744.000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1222" published="2006-03-14" name="CVE-2006-1222" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17075" source="BID" patch="1">17075</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427466/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060312 [INetCop Security Advisory] zeroboard IP session bypass XSS vulnerability</ref>
      <ref url="http://secunia.com/advisories/19214" source="SECUNIA" patch="1" adv="1">19214</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042872.html" source="FULLDISC" patch="1" adv="1">20060312 [INetCop Security Advisory] zeroboard IP session bypass XSS vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0944" source="VUPEN">ADV-2006-0944</ref>
      <ref url="http://www.nzeo.com/bbs/zboard.php?id=cgi_bugreport2&amp;no=5406" source="CONFIRM">http://www.nzeo.com/bbs/zboard.php?id=cgi_bugreport2&amp;no=5406</ref>
      <ref url="http://www.inetcop.org/upfiles/33INCSA.2006-0x82-029-zeroboard.pdf" source="MISC" adv="1">http://www.inetcop.org/upfiles/33INCSA.2006-0x82-029-zeroboard.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25212" source="XF">zeroboard-multiple-fields-xss(25212)</ref>
      <ref url="http://www.osvdb.org/23847" source="OSVDB">23847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2" />
        <vers num="4.1_pl3" />
        <vers num="4.1_pl4" />
        <vers num="4.1_pl5" />
        <vers num="4.1_pl6" />
        <vers num="4.1_pl7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1223" published="2006-03-14" name="CVE-2006-1223" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0942" source="VUPEN">ADV-2006-0942</ref>
      <ref url="http://www.securityfocus.com/bid/17072" source="BID">17072</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427406/100/0/threaded" source="BUGTRAQ">20060311 Jupiter CMS &lt;= 1.1.5 multiple XSS attack vectors.</ref>
      <ref url="http://secunia.com/advisories/19215" source="SECUNIA" adv="1">19215</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25241" source="XF">jupitercm-bbcodetag-xss(25241)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430903/100/0/threaded" source="BUGTRAQ">20060412 Re: Jupiter CMS &lt;= 1.1.5 multiple XSS attack vectors.</ref>
      <ref url="http://www.osvdb.org/23839" source="OSVDB">23839</ref>
      <ref url="http://www.jupiterportal.com/index.php?n=modules/forum&amp;a=3&amp;d=11&amp;o=5&amp;q=313" source="CONFIRM">http://www.jupiterportal.com/index.php?n=modules/forum&amp;a=3&amp;d=11&amp;o=5&amp;q=313</ref>
      <ref url="http://securityreason.com/securityalert/572" source="SREASON">572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.4" />
        <vers prev="1" num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1224" published="2006-03-14" name="CVE-2006-1224" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25141" source="XF" patch="1">guppy-dwnld-file-deletion(25141)</ref>
      <ref url="http://www.securityfocus.com/bid/17068" source="BID" patch="1">17068</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427329/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060310 [KAPDA::#33] - GuppY &lt;= 4.5.11 Remote DoS vulnerability</ref>
      <ref url="http://www.kapda.ir/advisory-291.html" source="MISC" patch="1" adv="1">http://www.kapda.ir/advisory-291.html</ref>
      <ref url="http://www.freeguppy.org/?lng=en" source="CONFIRM" patch="1">http://www.freeguppy.org/?lng=en</ref>
      <ref url="http://securitytracker.com/id?1015753" source="SECTRACK" patch="1" adv="1">1015753</ref>
      <ref url="http://secunia.com/advisories/19222" source="SECUNIA" patch="1" adv="1">19222</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0936" source="VUPEN">ADV-2006-0936</ref>
      <ref url="http://www.osvdb.org/23993" source="OSVDB">23993</ref>
      <ref url="http://www.osvdb.org/23846" source="OSVDB">23846</ref>
      <ref url="http://securityreason.com/securityalert/569" source="SREASON">569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guppy" name="guppy">
        <vers num="2.4" />
        <vers num="2.4_p1" />
        <vers num="2.4_p3" />
        <vers num="2.4_p4" />
        <vers num="4.5" />
        <vers num="4.5.10" />
        <vers num="4.5.11" />
        <vers num="4.5.3" />
        <vers num="4.5.3a" />
        <vers num="4.5.4" />
        <vers num="4.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1225" published="2006-03-14" name="CVE-2006-1225" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427591/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060314 [DRUPAL-SA-2006-004] Drupal 4.6.6 / 4.5.8 fixes mail header injection issue</ref>
      <ref url="http://secunia.com/advisories/19245" source="SECUNIA" patch="1" adv="1">19245</ref>
      <ref url="http://drupal.org/node/53806" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/53806</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25206" source="XF">drupal-header-data-manipulation(25206)</ref>
      <ref url="http://www.securityfocus.com/bid/17104" source="BID">17104</ref>
      <ref url="http://www.osvdb.org/23912" source="OSVDB">23912</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1007" source="DEBIAN">DSA-1007</ref>
      <ref url="http://securityreason.com/securityalert/579" source="SREASON">579</ref>
      <ref url="http://secunia.com/advisories/19257" source="SECUNIA">19257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1226" published="2006-03-14" name="CVE-2006-1226" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427588/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060314 [DRUPAL-SA-2006-002] Drupal 4.6.6 / 4.5.8 fixes XSS issue</ref>
      <ref url="http://secunia.com/advisories/19245" source="SECUNIA" patch="1" adv="1">19245</ref>
      <ref url="http://drupal.org/node/53803" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/53803</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25202" source="XF">drupal-undisclosed-xss(25202)</ref>
      <ref url="http://www.securityfocus.com/bid/17104" source="BID">17104</ref>
      <ref url="http://www.osvdb.org/23910" source="OSVDB">23910</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1007" source="DEBIAN">DSA-1007</ref>
      <ref url="http://securityreason.com/securityalert/581" source="SREASON">581</ref>
      <ref url="http://secunia.com/advisories/19257" source="SECUNIA">19257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1227" published="2006-03-14" name="CVE-2006-1227" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25197" source="XF" patch="1">drupal-menumodule-bypass-security(25197)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427587/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060314 [DRUPAL-SA-2006-001] Drupal 4.6.6 / 4.5.8 fixes access control issue</ref>
      <ref url="http://www.osvdb.org/23909" source="OSVDB" patch="1">23909</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1007" source="DEBIAN" patch="1" adv="1">DSA-1007</ref>
      <ref url="http://secunia.com/advisories/19257" source="SECUNIA" patch="1" adv="1">19257</ref>
      <ref url="http://secunia.com/advisories/19245" source="SECUNIA" patch="1" adv="1">19245</ref>
      <ref url="http://drupal.org/node/53796" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/53796</ref>
      <ref url="http://www.securityfocus.com/bid/17104" source="BID">17104</ref>
      <ref url="http://securityreason.com/securityalert/578" source="SREASON">578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.5.4" />
        <vers num="4.5.5" />
        <vers num="4.5.6" />
        <vers num="4.5.7" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.6.2" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="4.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1228" published="2006-03-14" name="CVE-2006-1228" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Drupal versions 4.6.x before 4.6.6, as well as versions 4.5.x before 4.5.8</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427589/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060314 [DRUPAL-SA-2006-003] Drupal 4.6.6 / 4.5.8 fixes session fixation issue</ref>
      <ref url="http://secunia.com/advisories/19245" source="SECUNIA" patch="1" adv="1">19245</ref>
      <ref url="http://drupal.org/node/53805" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/53805</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25205" source="XF">drupal-login-session-hijacking(25205)</ref>
      <ref url="http://www.securityfocus.com/bid/17104" source="BID">17104</ref>
      <ref url="http://www.osvdb.org/23911" source="OSVDB">23911</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1007" source="DEBIAN">DSA-1007</ref>
      <ref url="http://securityreason.com/securityalert/580" source="SREASON">580</ref>
      <ref url="http://secunia.com/advisories/19257" source="SECUNIA">19257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1229" published="2006-03-14" name="CVE-2006-1229" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may affect all versions of Hosting Controller previous to 6.1 Hotfix 2.9 as well.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25140" source="XF">hosting-controller-search-sql-injection(25140)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0914" source="VUPEN">ADV-2006-0914</ref>
      <ref url="http://www.osvdb.org/23802" source="OSVDB">23802</ref>
      <ref url="http://secunia.com/advisories/19191" source="SECUNIA" adv="1">19191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="6.1_hotfix_2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1230" published="2006-03-14" name="CVE-2006-1230" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter.  NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25181" source="XF">vcard-create-xss(25181)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0945" source="VUPEN" adv="1">ADV-2006-0945</ref>
      <ref url="http://www.securityfocus.com/bid/22819" source="BID">22819</ref>
      <ref url="http://www.securityfocus.com/bid/17073" source="BID">17073</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461922/100/0/threaded" source="BUGTRAQ">20070304 XSS Remote In vCard 2.6 (c)2002</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435310/100/0/threaded" source="BUGTRAQ">20060527 multiple Xss exploits in : vCard 2.9</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427408/100/0/threaded" source="BUGTRAQ" adv="1">20060311 XSS in vCard</ref>
      <ref url="http://www.osvdb.org/23838" source="OSVDB">23838</ref>
      <ref url="http://securitytracker.com/id?1016183" source="SECTRACK">1016183</ref>
      <ref url="http://secunia.com/advisories/19216" source="SECUNIA" adv="1">19216</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belchior_foundry" name="vcard">
        <vers num="2.6" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1231" published="2006-03-14" name="CVE-2006-1231" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17034" source="BID">17034</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427084/100/0/threaded" source="BUGTRAQ" adv="1">20060307 capi4hylafax insecure manipulation with tmp files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114176689513438&amp;w=2" source="FULLDISC">20060307 capi4hylafax insecure manipulation with tmp files</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25262" source="XF">capi4hylafax-c2faxrecvdbgdatafile-symlink(25262)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="julian_pawlowski" name="capi4hylafax">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1232" published="2006-03-14" name="CVE-2006-1232" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">"magic_quotes_gpc" parameter must be disabled in order for this vulnerability to be exploited.  This vulnerability may affect DSPortal, DSDownload versions previous to 1.0 as well.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0934" source="VUPEN">ADV-2006-0934</ref>
      <ref url="http://secunia.com/advisories/19202" source="SECUNIA" adv="1">19202</ref>
      <ref url="http://evuln.com/vulns/99/summary.html" source="MISC">http://evuln.com/vulns/99/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25193" source="XF">dsdownload-multiple-sql-injection(25193)</ref>
      <ref url="http://www.securityfocus.com/bid/17116" source="BID">17116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428808/100/0/threaded" source="BUGTRAQ">20060325 [eVuln] DSDownload Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23887" source="OSVDB">23887</ref>
      <ref url="http://www.osvdb.org/23886" source="OSVDB">23886</ref>
      <ref url="http://securitytracker.com/id?1015755" source="SECTRACK">1015755</ref>
      <ref url="http://securityreason.com/securityalert/626" source="SREASON">626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dsportal" name="dsdownload">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1233" published="2006-03-14" name="CVE-2006-1233" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0939" source="VUPEN">ADV-2006-0939</ref>
      <ref url="http://www.securityfocus.com/bid/17076" source="BID">17076</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427479/100/0/threaded" source="BUGTRAQ">20060312 WMNews Cross Site Scripting</ref>
      <ref url="http://secunia.com/advisories/19204" source="SECUNIA" adv="1">19204</ref>
      <ref url="http://biyosecurity.be/bugs/wmnews.txt" source="MISC">http://biyosecurity.be/bugs/wmnews.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25210" source="XF">wmnews-multiple-scripts-xss(25210)</ref>
      <ref url="http://www.osvdb.org/23842" source="OSVDB">23842</ref>
      <ref url="http://www.osvdb.org/23841" source="OSVDB">23841</ref>
      <ref url="http://www.osvdb.org/23840" source="OSVDB">23840</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mikael_software" name="wmnews">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1234" published="2006-03-14" name="CVE-2006-1234" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25190" source="XF">dscounter-index-sql-injection(25190)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0933" source="VUPEN">ADV-2006-0933</ref>
      <ref url="http://www.securityfocus.com/bid/17112" source="BID">17112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428807/100/0/threaded" source="BUGTRAQ">20060325 [eVuln] DSCounter 'X-Forwarded-For' SQL Injection Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015756" source="SECTRACK">1015756</ref>
      <ref url="http://secunia.com/advisories/19206" source="SECUNIA" adv="1">19206</ref>
      <ref url="http://evuln.com/vulns/98/summary.html" source="MISC" adv="1">http://evuln.com/vulns/98/summary.html</ref>
      <ref url="http://www.osvdb.org/23882" source="OSVDB">23882</ref>
      <ref url="http://securityreason.com/securityalert/627" source="SREASON">627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dsportal" name="dscounter">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1235" published="2006-03-14" name="CVE-2006-1235" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable.  NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25106" source="XF">hithost-deleteuser-directory-deletion(25106)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427631/100/0/threaded" source="BUGTRAQ">20060314 Re: histhost v1.0.0 xss and possible rmdir</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426931/100/0/threaded" source="BUGTRAQ">20060306 histhost v1.0.0 xss and possible rmdir</ref>
      <ref url="http://secunia.com/advisories/19155" source="SECUNIA" adv="1">19155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_ravenscroft" name="hithost">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1236" published="2006-03-14" name="CVE-2006-1236" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0951" source="VUPEN">ADV-2006-0951</ref>
      <ref url="http://www.securityfocus.com/bid/17093" source="BID">17093</ref>
      <ref url="http://www.milw0rm.com/exploits/1582" source="MILW0RM">1582</ref>
      <ref url="http://secunia.com/advisories/19237" source="SECUNIA" adv="1">19237</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?rev=1.86&amp;view=log" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?rev=1.86&amp;view=log</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25252" source="XF">crossfire-setup-bo(25252)</ref>
      <ref url="http://www.osvdb.org/23904" source="OSVDB">23904</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1009" source="DEBIAN">DSA-1009</ref>
      <ref url="http://secunia.com/advisories/19276" source="SECUNIA">19276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crossfire" name="crossfire">
        <vers num="1.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1237" published="2006-03-15" name="CVE-2006-1237" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25188" source="XF">dsnewsletter-email-sql-injection(25188)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0931" source="VUPEN">ADV-2006-0931</ref>
      <ref url="http://www.securityfocus.com/bid/17111" source="BID">17111</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428664/100/0/threaded" source="BUGTRAQ">20060324 [eVuln] DSNewsletter SQL Injection Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015757" source="SECTRACK">1015757</ref>
      <ref url="http://secunia.com/advisories/19207" source="SECUNIA" adv="1">19207</ref>
      <ref url="http://evuln.com/vulns/97/summary.html" source="MISC" adv="1">http://evuln.com/vulns/97/summary.html</ref>
      <ref url="http://www.osvdb.org/23885" source="OSVDB">23885</ref>
      <ref url="http://www.osvdb.org/23884" source="OSVDB">23884</ref>
      <ref url="http://www.osvdb.org/23883" source="OSVDB">23883</ref>
      <ref url="http://securityreason.com/securityalert/623" source="SREASON">623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dsportal" name="dsnewsletter">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1238" published="2006-03-15" name="CVE-2006-1238" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25194" source="XF">dslogin-index-sql-injection(25194)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25194" source="XF">dslogin-index-bypass-authentication(25194)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0953" source="VUPEN">ADV-2006-0953</ref>
      <ref url="http://www.securityfocus.com/bid/17262" source="BID">17262</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428902/100/0/threaded" source="BUGTRAQ">20060327 [eVuln] DSLogin Authentication Bypass Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015754" source="SECTRACK">1015754</ref>
      <ref url="http://secunia.com/advisories/19201" source="SECUNIA" adv="1">19201</ref>
      <ref url="http://evuln.com/vulns/100/summary.html" source="MISC" adv="1">http://evuln.com/vulns/100/summary.html</ref>
      <ref url="http://www.osvdb.org/23896" source="OSVDB">23896</ref>
      <ref url="http://securityreason.com/securityalert/637" source="SREASON">637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dsportal" name="dslogin">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1239" published="2006-03-15" name="CVE-2006-1239" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25195" source="XF">gemini-createissue-xss(25195)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0954" source="VUPEN">ADV-2006-0954</ref>
      <ref url="http://www.osvdb.org/23907" source="OSVDB">23907</ref>
      <ref url="http://secunia.com/advisories/19049" source="SECUNIA" adv="1">19049</ref>
      <ref url="http://www.securityfocus.com/bid/17092" source="BID">17092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="countersoft" name="gemini">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1240" published="2006-03-15" name="CVE-2006-1240" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17077" source="BID" patch="1">17077</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427480/100/0/threaded" source="BUGTRAQ" adv="1">20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25282" source="XF">firebird-fbinetserver-fbserver-bo(25282)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043546.html" source="FULLDISC">20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1241" published="2006-03-15" name="CVE-2006-1241" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.</descript>
    </desc>
    <sols>
      <sol source="nvd">The problems are fixed in the current 1.5.3 version of the Firebird binary distribution.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17077" source="BID" patch="1">17077</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427480/100/0/threaded" source="BUGTRAQ">20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25282" source="XF">firebird-fbinetserver-fbserver-bo(25282)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043546.html" source="FULLDISC">20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.5.2.4731" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1242" published="2006-03-15" name="CVE-2006-1242" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which bypasses intended protections against such attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19402" source="SECUNIA" patch="1" adv="1">19402</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1140" source="VUPEN">ADV-2006-1140</ref>
      <ref url="http://www.securityfocus.com/bid/17109" source="BID">17109</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427893/100/0/threaded" source="BUGTRAQ">20060316 Re: Linux zero IP ID vulnerability?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427753/100/0/threaded" source="BUGTRAQ">20060315 Re: Linux zero IP ID vulnerability?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427622/100/0/threaded" source="BUGTRAQ">20060314 Linux zero IP ID vulnerability?</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10317" source="OVAL">oval:org.mitre.oval:def:10317</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428605/30/6210/threaded" source="BUGTRAQ">20060323 Re: Linux zero IP ID vulnerability?</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0437.html" source="REDHAT">RHSA-2006:0437</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086" source="MANDRIVA">MDKSA-2006:086</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21983" source="SECUNIA">21983</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/21136" source="SECUNIA">21136</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/20157" source="SECUNIA">20157</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA">19955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.32" edition="pre1" />
        <vers num="2.4.32" edition="pre2" />
        <vers num="2.4.33" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1243" published="2006-03-15" name="CVE-2006-1243" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25322" source="XF">simplephpblog-install05-file-include(25322)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1007" source="VUPEN">ADV-2006-1007</ref>
      <ref url="http://www.securityfocus.com/bid/17102" source="BID">17102</ref>
      <ref url="http://secunia.com/advisories/19270" source="SECUNIA">19270</ref>
      <ref url="http://milw0rm.com/exploits/1581" source="MILW0RM">1581</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-November/001138.html" source="VIM">Vendor ACK for CVE-2006-1243 (older Simple PHP Blog)</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=564904" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=564904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_palmo" name="simple_php_blog">
        <vers num="0.4.0" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers prev="1" num="0.4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1244" published="2006-03-15" name="CVE-2006-1244" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc.  NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed.  Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-998" source="DEBIAN" patch="1" adv="1">DSA-998</ref>
      <ref url="http://www.debian.org/security/2006/dsa-984" source="DEBIAN" patch="1" adv="1">DSA-984</ref>
      <ref url="http://www.debian.org/security/2006/dsa-983" source="DEBIAN" patch="1" adv="1">DSA-983</ref>
      <ref url="http://www.debian.org/security/2006/dsa-982" source="DEBIAN" patch="1" adv="1">DSA-982</ref>
      <ref url="http://www.debian.org/security/2006/dsa-979" source="DEBIAN" patch="1" adv="1">DSA-979</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1019" source="DEBIAN" patch="1" adv="1">DSA-1019</ref>
      <ref url="http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gz" source="MISC" patch="1">http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gz</ref>
      <ref url="http://secunia.com/advisories/19644" source="SECUNIA" patch="1" adv="1">19644</ref>
      <ref url="http://secunia.com/advisories/19364" source="SECUNIA" patch="1" adv="1">19364</ref>
      <ref url="http://secunia.com/advisories/19164" source="SECUNIA" patch="1" adv="1">19164</ref>
      <ref url="http://secunia.com/advisories/19091" source="SECUNIA" patch="1" adv="1">19091</ref>
      <ref url="http://secunia.com/advisories/19065" source="SECUNIA" patch="1" adv="1">19065</ref>
      <ref url="http://secunia.com/advisories/19021" source="SECUNIA" patch="1" adv="1">19021</ref>
      <ref url="http://secunia.com/advisories/18948" source="SECUNIA" patch="1" adv="1">18948</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-270-1" source="UBUNTU">USN-270-1</ref>
      <ref url="http://www.securityfocus.com/bid/16748" source="BID">16748</ref>
      <ref url="http://www.osvdb.org/23834" source="OSVDB">23834</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gpdf">
        <vers num="2.8.2" />
      </prod>
      <prod vendor="libextractor" name="libextractor">
        <vers num="0.3.11" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.3.8" />
        <vers num="0.3.9" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1_pl1" />
        <vers num="3.0_pl2" />
        <vers num="3.0_pl3" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1245" published="2006-03-16" name="CVE-2006-1245" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT" adv="1">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/984473" source="CERT-VN" adv="1">VU#984473</ref>
      <ref url="http://www.securityfocus.com/bid/17131" source="BID" patch="1">17131</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS" patch="1">MS06-013</ref>
      <ref url="http://securitytracker.com/id?1015794" source="SECTRACK" patch="1">1015794</ref>
      <ref url="http://secunia.com/advisories/19269" source="SECUNIA" patch="1" adv="1">19269</ref>
      <ref url="http://secunia.com/advisories/18957" source="SECUNIA" patch="1" adv="1">18957</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25292" source="XF">ie-mshtml-bo(25292)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428810/100/0/threaded" source="BUGTRAQ">20060325 Re: [optimized PoC] Remote overflow in MSIE script action handlers (mshtml.dll)</ref>
      <ref url="http://www.osvdb.org/23964" source="OSVDB">23964</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0855.html" source="BUGTRAQ">20060316 Remote overflow in MSIE script action handlers (mshtml.dll)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/453554/100/0/threaded" source="BUGTRAQ">20061205 Re: MS Internet Explorer 6.0 (mshtml.dll) Denial of Service Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/453436/100/0/threaded" source="BUGTRAQ">20061203 MS Internet Explorer 6.0 (mshtml.dll) Denial of Service Exploit</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1766" source="OVAL" sig="1">oval:org.mitre.oval:def:1766</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1632" source="OVAL" sig="1">oval:org.mitre.oval:def:1632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1599" source="OVAL" sig="1">oval:org.mitre.oval:def:1599</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1569" source="OVAL" sig="1">oval:org.mitre.oval:def:1569</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1451" source="OVAL" sig="1">oval:org.mitre.oval:def:1451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1246" published="2006-03-17" name="CVE-2006-1246" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.nsfocus.com/english/homepage/research/0602.htm" source="MISC" patch="1" adv="1">http://www.nsfocus.com/english/homepage/research/0602.htm</ref>
      <ref url="http://secunia.com/advisories/19235" source="SECUNIA" patch="1" adv="1">19235</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25849" source="XF">aix-mklvcopy-code-execution(25849)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25299" source="XF">aix-bosrtelvm-gain-privileges(25299)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0957" source="VUPEN" adv="1">ADV-2006-0957</ref>
      <ref url="http://www.securityfocus.com/bid/17115" source="BID">17115</ref>
      <ref url="http://www.osvdb.org/23921" source="OSVDB">23921</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY82739" source="AIXAPAR">IY82739</ref>
      <ref url="http://securitytracker.com/id?1015786" source="SECTRACK">1015786</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000641.html" source="VIM">20060323 IBM changing significant details?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1247" published="2006-04-19" name="CVE-2006-1247" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17576" source="BID" patch="1">17576</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0603.htm" source="MISC" patch="1" adv="1">http://www.nsfocus.com/english/homepage/research/0603.htm</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY82357" source="AIXAPAR" patch="1">IY82357</ref>
      <ref url="http://secunia.com/advisories/19656" source="SECUNIA" patch="1" adv="1">19656</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25848" source="XF">aix-rm-mlcache-file-overwrite(25848)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1389" source="VUPEN" adv="1">ADV-2006-1389</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431848/100/0/threaded" source="BUGTRAQ">20060424 NSFOCUS SA2006-02 : IBM AIX mklvcopy Local Privilege Escalation Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431846/100/0/threaded" source="BUGTRAQ">20060424 NSFOCUS SA2006-03 : IBM AIX rm_mlcache_file Local Race Condition Vulnerability</ref>
      <ref url="http://www.osvdb.org/24706" source="OSVDB">24706</ref>
      <ref url="http://securitytracker.com/id?1015952" source="SECTRACK">1015952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.0.50" />
        <vers num="5.2.0.54" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3.0" />
        <vers num="5.3.0.10" />
        <vers num="5.3.0.20" />
        <vers num="5.3_l" />
        <vers num="5.3_ml03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1248" published="2006-03-17" name="CVE-2006-1248" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0997" source="VUPEN">ADV-2006-0997</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00614838" source="HP">HPSBUX02102</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25311" source="XF">hpux-usermod-unauthorized-access(25311)</ref>
      <ref url="http://www.securityfocus.com/bid/17143" source="BID">17143</ref>
      <ref url="http://securitytracker.com/id?1015834" source="SECTRACK">1015834</ref>
      <ref url="http://securitytracker.com/id?1015782" source="SECTRACK">1015782</ref>
      <ref url="http://secunia.com/advisories/19305" source="SECUNIA">19305</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00614838" source="HP">SSRT051078</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:785" source="OVAL" sig="1">oval:org.mitre.oval:def:785</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:772" source="OVAL" sig="1">oval:org.mitre.oval:def:772</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1098" source="OVAL" sig="1">oval:org.mitre.oval:def:1098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1249" published="2006-03-18" name="CVE-2006-1249" modified="2011-03-07" discovered="2006-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/570689" source="CERT-VN">VU#570689</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26398" source="XF">quicktime-flashpix-overflow(26398)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN">ADV-2006-1778</ref>
      <ref url="http://www.securityfocus.com/bid/17074" source="BID">17074</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433850/100/0/threaded" source="BUGTRAQ">20060511 [EEYEB-20060307] Apple QuickTime FPX Integer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://www.eeye.com/html/research/upcoming/20060307b.html" source="MISC">http://www.eeye.com/html/research/upcoming/20060307b.html</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE">APPLE-SA-2006-05-11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="6.0.1" />
        <vers num="6.0.2" />
      </prod>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1250" published="2006-03-18" name="CVE-2006-1250" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0858" source="VUPEN">ADV-2006-0858</ref>
      <ref url="http://www.magicwinmail.net/changelog.asp" source="CONFIRM">http://www.magicwinmail.net/changelog.asp</ref>
      <ref url="http://www.securityfocus.com/bid/17009" source="BID">17009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="winmail">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1251" published="2006-03-18" name="CVE-2006-1251" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17110" source="BID" patch="1">17110</ref>
      <ref url="http://marc.merlins.org/linux/exim/files/sa-exim-cvs/Changelog.html" source="CONFIRM" patch="1">http://marc.merlins.org/linux/exim/files/sa-exim-cvs/Changelog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25286" source="XF">saexim-greylistclean-file-deletion(25286)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0941" source="VUPEN" adv="1">ADV-2006-0941</ref>
      <ref url="http://secunia.com/advisories/19225" source="SECUNIA" adv="1">19225</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345071" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sa-exim" name="sa-exim">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1252" published="2006-03-18" name="CVE-2006-1252" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17059" source="BID">17059</ref>
      <ref url="http://www.milw0rm.com/exploits/1570" source="MILW0RM">1570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="light_weight_calendar" name="light_weight_calendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1253" published="2006-03-18" name="CVE-2006-1253" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19221" source="SECUNIA" patch="1" adv="1">19221</ref>
      <ref url="http://www.glftpd.com/files/docs/changelog" source="CONFIRM">http://www.glftpd.com/files/docs/changelog</ref>
      <ref url="http://www.securityfocus.com/bid/17118" source="BID">17118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glftpd" name="glftpd">
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.23" />
        <vers num="1.24" />
        <vers num="1.25" />
        <vers num="1.26" />
        <vers num="1.27" />
        <vers num="1.28" />
        <vers num="1.29" />
        <vers num="1.29.1" />
        <vers num="1.30" />
        <vers num="1.31" />
        <vers num="1.32" />
        <vers num="2.0" />
        <vers num="2.01_rc1" />
        <vers num="2.01_rc2" />
        <vers num="2.01_rc3" />
        <vers num="2.01_rc4" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
        <vers num="2.0_rc5" />
        <vers num="2.0_rc6" />
        <vers num="2.0_rc7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1254" published="2006-03-18" name="CVE-2006-1254" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19223" source="SECUNIA" patch="1" adv="1">19223</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25325" source="XF">borderware-mxtreme-web-admin(25325)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0972" source="VUPEN" adv="1">ADV-2006-0972</ref>
      <ref url="http://www.securityfocus.com/bid/17140" source="BID">17140</ref>
      <ref url="http://www.osvdb.org/23939" source="OSVDB">23939</ref>
      <ref url="http://securitytracker.com/id?1015787" source="SECTRACK">1015787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borderware" name="mxtreme">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1255" published="2006-03-18" name="CVE-2006-1255" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25290" source="XF">mercur-imap-bo(25290)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0977" source="VUPEN">ADV-2006-0977</ref>
      <ref url="http://www.securityfocus.com/bid/17138" source="BID">17138</ref>
      <ref url="http://www.osvdb.org/23950" source="OSVDB">23950</ref>
      <ref url="http://secunia.com/advisories/19267" source="SECUNIA" adv="1">19267</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043972.html" source="FULLDISC">20060316 Re: Mercur IMAPD 5.0 SP3 DoS Exploit or more?</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043972.html" source="FULLDISC">20060316 Re: Mercur IMAPD 5.0 SP3 DoS Exploit or more?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercur" name="mercur_messaging">
        <vers prev="1" num="2005_5.0_sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1256" published="2006-03-18" name="CVE-2006-1256" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability can only be exploited if the "magic_quotes_gpc" parameter is set to 'off'.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17136" source="BID" patch="1">17136</ref>
      <ref url="http://www.boysen.be/en/" source="CONFIRM" patch="1">http://www.boysen.be/en/</ref>
      <ref url="http://secunia.com/advisories/19268" source="SECUNIA" patch="1" adv="1">19268</ref>
      <ref url="http://evuln.com/vulns/104/summary.html" source="MISC" patch="1">http://evuln.com/vulns/104/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0974" source="VUPEN">ADV-2006-0974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25293" source="XF">skullsplitter-guestbook-xss(25293)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429254/100/0/threaded" source="BUGTRAQ">20060329 [eVuln] Skull-Splitter's PHP Guestbook XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/23941" source="OSVDB">23941</ref>
      <ref url="http://securityreason.com/securityalert/650" source="SREASON">650</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000613.html" source="VIM">20060318 Vendor ACK for Skull-Splitter Guestbook XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skullsplitter" name="php_guestbook">
        <vers prev="1" num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1257" published="2006-03-18" name="CVE-2006-1257" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17134" source="BID" patch="1">17134</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427974/100/0/threaded" source="BUGTRAQ" patch="1">20060316 Microsoft Commerce Server 2002: Logon as known user with a false password</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25330" source="XF">mscs-authfiles-authentication-bypass(25330)</ref>
      <ref url="http://www.osvdb.org/24121" source="OSVDB">24121</ref>
      <ref url="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp" source="CONFIRM">http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp</ref>
      <ref url="http://securityreason.com/securityalert/594" source="SREASON">594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commerce_server">
        <vers num="2002" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1258" published="2006-03-18" name="CVE-2006-1258" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" source="CONFIRM" patch="1">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</ref>
      <ref url="http://secunia.com/advisories/19277" source="SECUNIA" patch="1" adv="1">19277</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0991" source="VUPEN">ADV-2006-0991</ref>
      <ref url="http://www.securityfocus.com/bid/17142" source="BID">17142</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25305" source="XF">phpmyadmin-settheme-xss(25305)</ref>
      <ref url="http://www.osvdb.org/23943" source="OSVDB">23943</ref>
      <ref url="http://securitytracker.com/id?1015776" source="SECTRACK">1015776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.8.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1259" published="2006-03-18" name="CVE-2006-1259" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Maian Support 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) pass parameter to admin/index.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.  This vulnerability may affect earlier versions of Maian, Support as well.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0992" source="VUPEN">ADV-2006-0992</ref>
      <ref url="http://secunia.com/advisories/19275" source="SECUNIA" adv="1">19275</ref>
      <ref url="http://evuln.com/vulns/103/summary.html" source="MISC">http://evuln.com/vulns/103/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25300" source="XF">maiansupport-adminindex-sql-injection(25300)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429098/100/0/threaded" source="BUGTRAQ">20060328 [eVuln] Maian Support Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/23944" source="OSVDB">23944</ref>
      <ref url="http://securityreason.com/securityalert/645" source="SREASON">645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian" name="support">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1260" published="2006-03-18" name="CVE-2006-1260" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25239" source="XF" patch="1">horde-servicesgo-information-disclosure(25239)</ref>
      <ref url="http://www.securityfocus.com/bid/17117" source="BID" patch="1">17117</ref>
      <ref url="http://www.osvdb.org/23918" source="OSVDB" patch="1">23918</ref>
      <ref url="http://securitytracker.com/id?1015771" source="SECTRACK" patch="1">1015771</ref>
      <ref url="http://secunia.com/advisories/19246" source="SECUNIA" patch="1" adv="1">19246</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043657.html" source="FULLDISC" patch="1" adv="1">20060315 CodeScan Advisory: Unauthenticated Arbitrary File Read in Horde v3.09 and prior</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0959" source="VUPEN">ADV-2006-0959</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427710/100/0/threaded" source="BUGTRAQ">20060315 CodeScan Advisory: Unauthenticated Arbitrary File Read in Horde v3.09 and prior</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml" source="GENTOO">GLSA-200604-02</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1034" source="DEBIAN">DSA-1034</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1033" source="DEBIAN">DSA-1033</ref>
      <ref url="http://securityreason.com/securityalert/590" source="SREASON">590</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
      <ref url="http://secunia.com/advisories/19692" source="SECUNIA">19692</ref>
      <ref url="http://secunia.com/advisories/19619" source="SECUNIA">19619</ref>
      <ref url="http://secunia.com/advisories/19528" source="SECUNIA">19528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.3" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.4_rc1" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.4_rc1" />
        <vers num="3.0.4_rc2" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1261" published="2006-03-18" name="CVE-2006-1261" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25235" source="XF" patch="1">aspportal-multiple-xss(25235)</ref>
      <ref url="http://secunia.com/advisories/19247" source="SECUNIA" patch="1" adv="1">19247</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114243660409338&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20060315 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1517.html" source="FULLDISC" patch="1" adv="1">20060314 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref>
      <ref url="http://www.securityfocus.com/bid/17114" source="BID">17114</ref>
      <ref url="http://www.osvdb.org/23920" source="OSVDB">23920</ref>
      <ref url="http://www.aspportal.net/content/news/News_Item.asp?content_ID=32" source="CONFIRM">http://www.aspportal.net/content/news/News_Item.asp?content_ID=32</ref>
      <ref url="http://securitytracker.com/id?1015772" source="SECTRACK">1015772</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspportal" name="aspportal">
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1262" published="2006-03-18" name="CVE-2006-1262" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ASPPortal 3.00 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25234" source="XF" patch="1">aspportal-multiple-scripts-sql-injection(25234)</ref>
      <ref url="http://secunia.com/advisories/19247" source="SECUNIA" patch="1" adv="1">19247</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114243660409338&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20060315 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1517.html" source="FULLDISC" patch="1" adv="1">20060314 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref>
      <ref url="http://www.securityfocus.com/bid/17114" source="BID">17114</ref>
      <ref url="http://www.osvdb.org/23919" source="OSVDB">23919</ref>
      <ref url="http://www.aspportal.net/content/news/News_Item.asp?content_ID=32" source="CONFIRM">http://www.aspportal.net/content/news/News_Item.asp?content_ID=32</ref>
      <ref url="http://securitytracker.com/id?1015772" source="SECTRACK">1015772</ref>
      <ref url="http://securityreason.com/securityalert/592" source="SREASON">592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspportal" name="aspportal">
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1263" published="2006-03-18" name="CVE-2006-1263" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17069" source="BID" patch="1">17069</ref>
      <ref url="http://wordpress.org/development/2006/03/security-202/" source="CONFIRM" patch="1">http://wordpress.org/development/2006/03/security-202/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="0.6.2" edition="beta_2" />
        <vers num="0.6.2.1" edition="beta_2" />
        <vers num="0.7" />
        <vers num="0.71" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
        <vers num="1.5.1.3" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1264" published="2006-03-18" name="CVE-2006-1264" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17119" source="BID">17119</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427729/100/0/threaded" source="BUGTRAQ" adv="1">20060315 [eVuln] discussion - xhawk.net BBCode 'img' XSS &amp; SQL Injection Vulnerabilities</ref>
      <ref url="http://evuln.com/vulns/92/summary.html" source="MISC">http://evuln.com/vulns/92/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25236" source="XF">discussion-bbcode-xss(25236)</ref>
      <ref url="http://www.osvdb.org/23970" source="OSVDB">23970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xhawk.net" name="discussion">
        <vers num="2.0_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1265" published="2006-03-18" name="CVE-2006-1265" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427729/100/0/threaded" source="BUGTRAQ" adv="1">20060315 [eVuln] discussion - xhawk.net BBCode 'img' XSS &amp; SQL Injection Vulnerabilities</ref>
      <ref url="http://evuln.com/vulns/92/summary.html" source="MISC">http://evuln.com/vulns/92/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25237" source="XF">discussion-class-sql-injection(25237)</ref>
      <ref url="http://www.securityfocus.com/bid/17121" source="BID">17121</ref>
      <ref url="http://www.osvdb.org/23971" source="OSVDB">23971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xhawk.net" name="discussion">
        <vers num="2.0_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1266" published="2006-03-18" name="CVE-2006-1266" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23916" source="OSVDB" adv="1">23916</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000605.html" source="VIM">20060314 vendor dispute: VCS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25339" source="XF">vpmi-servicerequests-xss(25339)</ref>
      <ref url="http://www.securityfocus.com/bid/17172" source="BID">17172</ref>
      <ref url="http://secunia.com/advisories/19297" source="SECUNIA">19297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_communication_services" name="vpmi_enterprise">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1267" published="2006-03-18" name="CVE-2006-1267" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427751/100/0/threaded" source="BUGTRAQ" adv="1">20060314 Invision Power Board v2.1.4 - session hijacking</ref>
      <ref url="http://www.securityfocus.com/archive/1/427847/100/0/threaded" source="BUGTRAQ" adv="1">20060316 Re: Invision Power Board v2.1.4 - session hijacking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1268" published="2006-03-18" name="CVE-2006-1268" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Internet Key Exchange implementation in Funkwerk X2300 7.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite.  NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19233" source="SECUNIA" patch="1" adv="1">19233</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0958" source="VUPEN">ADV-2006-0958</ref>
      <ref url="http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7201p09/readme_721p9.pdf" source="CONFIRM">http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7201p09/readme_721p9.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/17124" source="BID">17124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="funkwerk" name="x2300">
        <vers num="7.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1269" published="2006-03-18" name="CVE-2006-1269" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive creation.  NOTE: since this issue is local and not setuid, the set of attack scenarios is limited, although is reasonable to expect that there are some situations in which the zoo user might automatically list attacker-controlled filenames to add to the zoo archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183426" source="MISC" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183426</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-12.xml" source="GENTOO" patch="1">GLSA-200603-12</ref>
      <ref url="http://secunia.com/advisories/19250" source="SECUNIA" patch="1" adv="1">19250</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0969" source="VUPEN">ADV-2006-0969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25264" source="XF">zoo-parse-bo(25264)</ref>
      <ref url="http://www.securityfocus.com/bid/17126" source="BID">17126</ref>
      <ref url="http://secunia.com/advisories/19254" source="SECUNIA">19254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rahul_dhesi" name="zoo">
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1270" published="2006-03-18" name="CVE-2006-1270" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in zones.php in Inprotect 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Description field.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">A remote attacker must have "Manage Zones and Server" permissions on Inprotect to exploit this vulnerability.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25280" source="XF">inprotect-zones-xss(25280)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0970" source="VUPEN">ADV-2006-0970</ref>
      <ref url="http://www.securityfocus.com/bid/17141" source="BID">17141</ref>
      <ref url="http://secunia.com/advisories/19248" source="SECUNIA" adv="1">19248</ref>
      <ref url="http://www.osvdb.org/23936" source="OSVDB">23936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inprotect" name="inprotect">
        <vers prev="1" num="0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1271" published="2006-03-18" name="CVE-2006-1271" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in OxyNews allows remote attackers to execute arbitrary SQL commands via the oxynews_comment_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0976" source="VUPEN">ADV-2006-0976</ref>
      <ref url="http://www.securityfocus.com/bid/17132" source="BID">17132</ref>
      <ref url="http://secunia.com/advisories/19255" source="SECUNIA" adv="1">19255</ref>
      <ref url="http://biyosecurity.be/bugs/oxynews.txt" source="MISC">http://biyosecurity.be/bugs/oxynews.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25301" source="XF">oxynews-index-sql-injection(25301)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428057/100/0/threaded" source="BUGTRAQ">20060316 Oxynews Sql &amp;#304;njection</ref>
      <ref url="http://www.osvdb.org/23940" source="OSVDB">23940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oxynews" name="oxynews">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1272" published="2006-03-18" name="CVE-2006-1272" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in member.php in MyBulletin Board (MyBB) 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) aim, (2) yahoo, (3) msn, or (4) website field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17097" source="BID">17097</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427746/100/0/threaded" source="BUGTRAQ">20060314 [[KAPDA::#35] MyBB 1.0.3~member.php~XSS Attack in contact details</ref>
      <ref url="http://www.osvdb.org/23935" source="OSVDB">23935</ref>
      <ref url="http://kapda.ir/advisory-297.html" source="MISC" adv="1">http://kapda.ir/advisory-297.html</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=7368" source="MISC">http://community.mybboard.net/showthread.php?tid=7368</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25263" source="XF">mybb-member-xss(25263)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1273" published="2006-03-19" name="CVE-2006-1273" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">** DISPUTED **  Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source.  NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extension," and Mozilla also confirmed that this is not an issue in Firefox itself.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428159/100/0/threaded" source="BUGTRAQ">20060318 Re: Re: Remote overflow in MSIE script action handlers (mshtml.dll)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427977/100/0/threaded" source="BUGTRAQ" adv="1">20060317 Re: Re: Remote overflow in MSIE script action handlers (mshtml.dll)</ref>
      <ref url="http://securityreason.com/securityalert/593" source="SREASON">593</ref>
      <ref url="http://osvdb.org/31833" source="OSVDB">31833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.7" />
        <vers num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1274" published="2006-03-19" name="CVE-2006-1274" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display scan reports.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17071" source="BID" patch="1">17071</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0948" source="VUPEN">ADV-2006-0948</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427412/100/0/threaded" source="BUGTRAQ" adv="1">20060311 AntiVir PersonalEdition Classic: Local Privilige Escalation</ref>
      <ref url="http://secunia.com/advisories/19217" source="SECUNIA" adv="1">19217</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042868.html" source="FULLDISC" adv="1">20060311 AntiVir PersonalEdition Classic: Local Privilige Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25244" source="XF">antivir-notepad-gain-privilege(25244)</ref>
      <ref url="http://www.osvdb.org/23843" source="OSVDB">23843</ref>
      <ref url="http://securityreason.com/securityalert/573" source="SREASON">573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avira" name="antivir_personal">
        <vers num="" edition=":premium" />
        <vers num="7" edition="" />
        <vers num="7" edition=":classic" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1275" published="2006-03-19" name="CVE-2006-1275" modified="2011-10-18" discovered="2006-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) trailing ' (apostrophe) character on the ID attribute in a PLAYER XML tag, (2) joining with a long ID attribute or non-trailing ' characters, which causes a &lt;none> name to be assigned, and then disconnecting, or (3) a long CDATA message attribute, which prevents closing tags from being added to the string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25164" source="XF">ggzgaminzone-xml-dos(25164)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0935" source="VUPEN" adv="1">ADV-2006-0935</ref>
      <ref url="http://www.securityfocus.com/bid/17094" source="BID">17094</ref>
      <ref url="http://www.osvdb.org/23848" source="OSVDB">23848</ref>
      <ref url="http://secunia.com/advisories/19212" source="SECUNIA" adv="1">19212</ref>
      <ref url="http://aluigi.altervista.org/adv/ggzcdos-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/ggzcdos-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ggz_gaming_zone" name="ggz_gaming_zone">
        <vers num="0.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1276" published="2006-03-19" name="CVE-2006-1276" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0913" source="VUPEN">ADV-2006-0913</ref>
      <ref url="http://secunia.com/advisories/19195" source="SECUNIA" adv="1">19195</ref>
      <ref url="http://evuln.com/vulns/94/summary.html" source="MISC">http://evuln.com/vulns/94/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25177" source="XF">simplenews-admin-bypass-security(25177)</ref>
      <ref url="http://www.securityfocus.com/bid/17186" source="BID">17186</ref>
      <ref url="http://www.securityfocus.com/archive/1/428427" source="BUGTRAQ">20060322 [eVuln] PHP SimpleNEWS, PHP SimpleNEWS MySQL - Authentication Bypass Vulnerability</ref>
      <ref url="http://www.osvdb.org/23803" source="OSVDB">23803</ref>
      <ref url="http://securityreason.com/securityalert/613" source="SREASON">613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="himpfen_consulting" name="php_simplenews">
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1277" published="2006-03-19" name="CVE-2006-1277" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, and (3) login parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0943" source="VUPEN">ADV-2006-0943</ref>
      <ref url="http://www.securityfocus.com/bid/17090" source="BID">17090</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428659/100/0/threaded" source="BUGTRAQ">20060324 [eVuln] @1 File Store Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23850" source="OSVDB">23850</ref>
      <ref url="http://securitytracker.com/id?1015826" source="SECTRACK">1015826</ref>
      <ref url="http://secunia.com/advisories/19224" source="SECUNIA" adv="1">19224</ref>
      <ref url="http://evuln.com/vulns/95/summary.html" source="MISC">http://evuln.com/vulns/95/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25182" source="XF">filestore-signup-xss(25182)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upoint" name="at1_file_store">
        <vers prev="1" num="2006.03.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1278" published="2006-03-19" name="CVE-2006-1278" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php.  NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/43724" source="XF">filestorepro-download-file-include(43724)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43718" source="XF">filestorepro-id-sql-injection(43718)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25183" source="XF">filestore-multiple-sql-injection(25183)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0943" source="VUPEN" adv="1">ADV-2006-0943</ref>
      <ref url="http://www.securityfocus.com/bid/30182" source="BID">30182</ref>
      <ref url="http://www.securityfocus.com/bid/17090" source="BID">17090</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428659/100/0/threaded" source="BUGTRAQ">20060324 [eVuln] @1 File Store Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24106" source="OSVDB">24106</ref>
      <ref url="http://www.osvdb.org/23864" source="OSVDB">23864</ref>
      <ref url="http://www.osvdb.org/23863" source="OSVDB">23863</ref>
      <ref url="http://www.osvdb.org/23862" source="OSVDB">23862</ref>
      <ref url="http://www.osvdb.org/23861" source="OSVDB">23861</ref>
      <ref url="http://www.osvdb.org/23860" source="OSVDB">23860</ref>
      <ref url="http://www.osvdb.org/23859" source="OSVDB">23859</ref>
      <ref url="http://www.osvdb.org/23858" source="OSVDB">23858</ref>
      <ref url="http://www.osvdb.org/23857" source="OSVDB">23857</ref>
      <ref url="http://www.osvdb.org/23856" source="OSVDB">23856</ref>
      <ref url="http://www.osvdb.org/23855" source="OSVDB">23855</ref>
      <ref url="http://www.osvdb.org/23854" source="OSVDB">23854</ref>
      <ref url="http://www.osvdb.org/23853" source="OSVDB">23853</ref>
      <ref url="http://www.osvdb.org/23852" source="OSVDB">23852</ref>
      <ref url="http://www.osvdb.org/23851" source="OSVDB">23851</ref>
      <ref url="http://www.milw0rm.com/exploits/6040" source="MILW0RM">6040</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-August/002246.html" source="VIM">20090825 @1 File Store PRO SQL injection - the old gray dupe</ref>
      <ref url="http://securitytracker.com/id?1015826" source="SECTRACK">1015826</ref>
      <ref url="http://securityreason.com/securityalert/619" source="SREASON">619</ref>
      <ref url="http://secunia.com/advisories/31063" source="SECUNIA" adv="1">31063</ref>
      <ref url="http://secunia.com/advisories/19224" source="SECUNIA" adv="1">19224</ref>
      <ref url="http://osvdb.org/47018" source="OSVDB">47018</ref>
      <ref url="http://osvdb.org/47017" source="OSVDB">47017</ref>
      <ref url="http://evuln.com/vulns/95/summary.html" source="MISC">http://evuln.com/vulns/95/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upoint" name="@1_file_store">
        <vers num="2006.03.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1279" published="2006-03-19" name="CVE-2006-1279" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0946" source="VUPEN">ADV-2006-0946</ref>
      <ref url="http://www.securityfocus.com/bid/17177" source="BID">17177</ref>
      <ref url="http://www.osvdb.org/23865" source="OSVDB">23865</ref>
      <ref url="http://secunia.com/advisories/19211" source="SECUNIA" adv="1">19211</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356555" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25285" source="XF">cgisession-cgisess-information-disclosure(25285)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sherzod_ruzmetov" name="cgi_session">
        <vers prev="1" num="4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1280" published="2006-03-19" name="CVE-2006-1280" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0946" source="VUPEN">ADV-2006-0946</ref>
      <ref url="http://www.osvdb.org/23867" source="OSVDB">23867</ref>
      <ref url="http://www.osvdb.org/23866" source="OSVDB">23866</ref>
      <ref url="http://secunia.com/advisories/19211" source="SECUNIA" adv="1">19211</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356555" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25283" source="XF">cgisession-driver-files-insecure-permissions(25283)</ref>
      <ref url="http://www.securityfocus.com/bid/17099" source="BID">17099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sherzod_ruzmetov" name="cgi_session">
        <vers prev="1" num="4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1281" published="2006-03-19" name="CVE-2006-1281" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272.  NOTE: 1.10 was later reported to be vulnerable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19213" source="SECUNIA" patch="1" adv="1">19213</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=7368" source="CONFIRM" patch="1">http://community.mybboard.net/showthread.php?tid=7368</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25266" source="XF">mybb-member-url-xss(25266)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0971" source="VUPEN">ADV-2006-0971</ref>
      <ref url="http://www.securityfocus.com/bid/17492" source="BID">17492</ref>
      <ref url="http://www.securityfocus.com/bid/17097" source="BID">17097</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427744/100/0/threaded" source="BUGTRAQ" adv="1">20060314 [KAPDA::#35] - MyBB1.0.4~member.php~XSS after login</ref>
      <ref url="http://www.osvdb.org/23935" source="OSVDB">23935</ref>
      <ref url="http://myimei.com/security/2006-03-09/mybb104memberphpxss-after-login.html" source="MISC">http://myimei.com/security/2006-03-09/mybb104memberphpxss-after-login.html</ref>
      <ref url="http://kapda.ir/advisory-296.html" source="MISC" adv="1">http://kapda.ir/advisory-296.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="1.10" />
        <vers num="rc1" />
        <vers num="rc2" />
        <vers num="rc3" />
        <vers num="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1282" published="2006-03-19" name="CVE-2006-1282" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://kapda.ir/advisory-295.html" source="MISC" patch="1" adv="1">http://kapda.ir/advisory-295.html</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=7368" source="CONFIRM" patch="1">http://community.mybboard.net/showthread.php?tid=7368</ref>
      <ref url="http://www.securityfocus.com/bid/17097" source="BID">17097</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427747/100/0/threaded" source="BUGTRAQ" adv="1">20060314 [KAPDA::#34] - MyBB1.0.4~redirectfunction()~HeaderInjection</ref>
      <ref url="http://myimei.com/security/2006-03-10/mybb104redirectfunctionheaderinjection.html" source="MISC">http://myimei.com/security/2006-03-10/mybb104redirectfunctionheaderinjection.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25267" source="XF">mybb-crlf-header-injection(25267)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="rc1" />
        <vers num="rc2" />
        <vers num="rc3" />
        <vers num="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1283" published="2006-03-23" name="CVE-2006-1283" modified="2011-08-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">opiepasswd in One-Time Passwords in Everything (OPIE) in FreeBSD 4.10-RELEASE-p22 through 6.1-STABLE before 20060322 uses the getlogin function to determine the invoking user account, which might allow local users to configure OPIE access to the root account and possibly gain root privileges if a root shell is permitted by the configuration of the wheel group or sshd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17194" source="BID" patch="1">17194</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:12.opie.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-06:12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25397" source="XF">bsd-opie-unauthorized-privileges(25397)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1074" source="VUPEN" adv="1">ADV-2006-1074</ref>
      <ref url="http://www.osvdb.org/24067" source="OSVDB">24067</ref>
      <ref url="http://securitytracker.com/id?1015817" source="SECTRACK">1015817</ref>
      <ref url="http://secunia.com/advisories/19347" source="SECUNIA" adv="1">19347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1" edition="stable" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7" />
        <vers num="2.1.7.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="3.0" edition="releng" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" edition="stable" />
        <vers num="3.5.1" edition="release" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p7" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="releng" />
        <vers num="5.3" edition="stable" />
        <vers num="5.4" edition="pre-release" />
        <vers num="5.4" edition="release" />
        <vers num="5.4" edition="releng" />
        <vers num="5.4" edition="stable" />
        <vers num="6.0" edition="release" />
        <vers num="6.0" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1284" published="2006-03-19" name="CVE-2006-1284" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0870" source="VUPEN">ADV-2006-0870</ref>
      <ref url="http://www.securityfocus.com/bid/17018" source="BID">17018</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html</ref>
      <ref url="http://secunia.com/advisories/19171" source="SECUNIA" adv="1">19171</ref>
      <ref url="http://securitytracker.com/id?1015733" source="SECTRACK">1015733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="ghost_solutions_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="norton_ghost">
        <vers num="8.0" />
        <vers num="8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1285" published="2006-03-19" name="CVE-2006-1285" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="3.2" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.1" CVSS_base_score="3.2">
    <desc>
      <descript source="cve">SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to Symantec Ghost 8.3 that is shipped as a part of Symantec Ghost Solutions Suite 1.1.</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0870" source="VUPEN">ADV-2006-0870</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html</ref>
      <ref url="http://secunia.com/advisories/19171" source="SECUNIA" adv="1">19171</ref>
      <ref url="http://www.securityfocus.com/bid/17019" source="BID">17019</ref>
      <ref url="http://securitytracker.com/id?1015733" source="SECTRACK">1015733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="ghost_solutions_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="norton_ghost">
        <vers num="8.0" />
        <vers num="8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1286" published="2006-03-19" name="CVE-2006-1286" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to Symantec Ghost 8.3 that is shipped as a part of Symantec Ghost Solutions Suite 1.1.
</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0870" source="VUPEN">ADV-2006-0870</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html</ref>
      <ref url="http://secunia.com/advisories/19171" source="SECUNIA" adv="1">19171</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25089" source="XF">ghost-dbisqlc-bo(25089)</ref>
      <ref url="http://securitytracker.com/id?1015733" source="SECTRACK">1015733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="ghost_solutions_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="norton_ghost">
        <vers num="8.0" />
        <vers num="8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1287" published="2006-03-19" name="CVE-2006-1287" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=206790" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=206790</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0861" source="VUPEN">ADV-2006-0861</ref>
      <ref url="http://secunia.com/advisories/19141" source="SECUNIA">19141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.4" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1288" published="2006-03-19" name="CVE-2006-1288" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=204627" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=204627</ref>
      <ref url="http://forums.invisionpower.com/index.php?act=Attach&amp;type=post&amp;id=9642" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?act=Attach&amp;type=post&amp;id=9642</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0861" source="VUPEN">ADV-2006-0861</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25100" source="XF">invision-multiple-sql-injection(25100)</ref>
      <ref url="http://secunia.com/advisories/19141" source="SECUNIA">19141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.4" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1289" published="2006-03-19" name="CVE-2006-1289" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, (3) team, (4) level, (5) status, (6) teamname, and (7) teamlead parameters in (a) auth.php; the (8) username, (9) action, and (10) filter parameters in (b) authuser.php; the (11) username parameter in (c) utils.php; the (12) id and (13) date parameters in (d) traffic.php; the (14) username parameter in (e) userstatistics.php; and the (15) USERNAME and (16) PASSWORD parameters in a cookie to (f) chgpwd.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0968" source="VUPEN">ADV-2006-0968</ref>
      <ref url="http://www.ush.it/team/ascii/hack-milkeway/milkeyway.txt" source="MISC">http://www.ush.it/team/ascii/hack-milkeway/milkeyway.txt</ref>
      <ref url="http://www.securityfocus.com/bid/17127" source="BID">17127</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427890/100/0/threaded" source="BUGTRAQ" adv="1">20060316 Milkeyway Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25287" source="XF">milkeyway-admin-sql-injection(25287)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25281" source="XF">milkeyway-multiple-sql-injection(25281)</ref>
      <ref url="http://www.ush.it/team/ascii/hack-milkeway/advisory.txt" source="MISC">http://www.ush.it/team/ascii/hack-milkeway/advisory.txt</ref>
      <ref url="http://www.osvdb.org/23931" source="OSVDB">23931</ref>
      <ref url="http://www.osvdb.org/23929" source="OSVDB">23929</ref>
      <ref url="http://www.osvdb.org/23928" source="OSVDB">23928</ref>
      <ref url="http://www.osvdb.org/23927" source="OSVDB">23927</ref>
      <ref url="http://www.osvdb.org/23925" source="OSVDB">23925</ref>
      <ref url="http://securitytracker.com/id?1015778" source="SECTRACK">1015778</ref>
      <ref url="http://secunia.com/advisories/19258" source="SECUNIA">19258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="milkeyway" name="milkeyway_captive_portal">
        <vers num="0.1" />
        <vers num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1290" published="2006-03-19" name="CVE-2006-1290" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters in (b) userstatistics.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0968" source="VUPEN">ADV-2006-0968</ref>
      <ref url="http://www.ush.it/team/ascii/hack-milkeway/milkeyway.txt" source="MISC">http://www.ush.it/team/ascii/hack-milkeway/milkeyway.txt</ref>
      <ref url="http://www.securityfocus.com/bid/17127" source="BID">17127</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427890/100/0/threaded" source="BUGTRAQ" adv="1">20060316 Milkeyway Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25288" source="XF">milkeyway-multiple-xss(25288)</ref>
      <ref url="http://www.ush.it/team/ascii/hack-milkeway/advisory.txt" source="MISC">http://www.ush.it/team/ascii/hack-milkeway/advisory.txt</ref>
      <ref url="http://www.osvdb.org/23933" source="OSVDB">23933</ref>
      <ref url="http://www.osvdb.org/23932" source="OSVDB">23932</ref>
      <ref url="http://securitytracker.com/id?1015778" source="SECTRACK">1015778</ref>
      <ref url="http://secunia.com/advisories/19258" source="SECUNIA">19258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="milkeyway" name="milkeyway_captive_portal">
        <vers num="0.1" />
        <vers num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1291" published="2006-03-19" name="CVE-2006-1291" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1019" source="VUPEN">ADV-2006-1019</ref>
      <ref url="http://www.securityfocus.com/bid/17129" source="BID">17129</ref>
      <ref url="http://www.milw0rm.com/exploits/1586" source="MILW0RM">1586</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/php-iCalendar-221.upload.php" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/php-iCalendar-221.upload.php</ref>
      <ref url="http://secunia.com/advisories/19285" source="SECUNIA">19285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_icalendar" name="php_icalendar">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0a2" />
        <vers num="2.0b" />
        <vers num="2.0c" />
        <vers num="2.1" />
        <vers prev="1" num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1292" published="2006-03-19" name="CVE-2006-1292" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1019" source="VUPEN">ADV-2006-1019</ref>
      <ref url="http://www.milw0rm.com/exploits/1585" source="MILW0RM">1585</ref>
      <ref url="http://www.securityfocus.com/bid/17125" source="BID">17125</ref>
      <ref url="http://secunia.com/advisories/19285" source="SECUNIA">19285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_icalendar" name="php_icalendar">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0a2" />
        <vers num="2.0b" />
        <vers num="2.0c" />
        <vers num="2.1" />
        <vers prev="1" num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1293" published="2006-03-19" name="CVE-2006-1293" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1013" source="VUPEN">ADV-2006-1013</ref>
      <ref url="http://www.securityfocus.com/bid/17128" source="BID">17128</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428075/100/0/threaded" source="BUGTRAQ">20060318 Contrexx CMS Xss Vuln</ref>
      <ref url="http://www.contrexx.com/?section=news&amp;cmd=details&amp;newsid=54" source="MISC">http://www.contrexx.com/?section=news&amp;cmd=details&amp;newsid=54</ref>
      <ref url="http://www.contrexx.com/?section=media1&amp;act=download&amp;path=/media/archive1/Opensource/Bugfixes/contrexx_1.0.8/&amp;file=contrexx_v1.0.8_bugfix_27-02-06.zip" source="MISC">http://www.contrexx.com/?section=media1&amp;act=download&amp;path=/media/archive1/Opensource/Bugfixes/contrexx_1.0.8/&amp;file=contrexx_v1.0.8_bugfix_27-02-06.zip</ref>
      <ref url="http://soot.shabgard.org/Contrexx-CMS.txt" source="MISC">http://soot.shabgard.org/Contrexx-CMS.txt</ref>
      <ref url="http://secunia.com/advisories/19294" source="SECUNIA" adv="1">19294</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25332" source="XF">contrexx-index-xss(25332)</ref>
      <ref url="http://securityreason.com/securityalert/599" source="SREASON">599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astalavista_it_engineering" name="contrexx">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.7" />
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1294" published="2006-03-19" name="CVE-2006-1294" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1020" source="VUPEN">ADV-2006-1020</ref>
      <ref url="http://www.securityfocus.com/bid/17120" source="BID">17120</ref>
      <ref url="http://www.milw0rm.com/exploits/1587" source="MILW0RM">1587</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25338" source="XF">knowledgebasepublisher-dir-file-include(25338)</ref>
      <ref url="http://www.osvdb.org/24002" source="OSVDB">24002</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=402179&amp;group_id=144153" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=402179&amp;group_id=144153</ref>
      <ref url="http://secunia.com/advisories/19298" source="SECUNIA">19298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knowledgebasepublisher" name="knowledgebasepublisher">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1295" published="2006-03-19" name="CVE-2006-1295" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone.spip.org/trac/spip-zone/changeset/1672" source="CONFIRM" patch="1">http://zone.spip.org/trac/spip-zone/changeset/1672</ref>
      <ref url="http://www.zone-h.fr/advisories/read/id=1105" source="MISC">http://www.zone-h.fr/advisories/read/id=1105</ref>
      <ref url="http://www.silitix.com/spip-xss.html" source="MISC">http://www.silitix.com/spip-xss.html</ref>
      <ref url="http://www.securityfocus.com/bid/17130" source="BID">17130</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25389" source="XF">spip-research-xss(25389)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers num="1.8.2e" />
        <vers num="1.8.2g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1296" published="2006-03-19" name="CVE-2006-1296" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Beagle 0.2.2.1 might allow local users to gain privileges via a malicious beagle-info program in the current working directory, or possibly directories specified in the PATH.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25303" source="XF">beagle-beagle-status-privilege-escalation(25303)</ref>
      <ref url="http://www.securityfocus.com/bid/17195" source="BID">17195</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00047.html" source="FEDORA">FEDORA-2006-188</ref>
      <ref url="http://www.osvdb.org/23942" source="OSVDB">23942</ref>
      <ref url="http://secunia.com/advisories/19336" source="SECUNIA">19336</ref>
      <ref url="http://secunia.com/advisories/19278" source="SECUNIA" adv="1">19278</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=357392" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=357392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beagle-project" name="beagle">
        <vers num="0.2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1297" published="2006-03-19" name="CVE-2006-1297" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.03.17a.html" source="CONFIRM" patch="1">http://www.symantec.com/avcenter/security/Content/2006.03.17a.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25309" source="XF">backupexec-app-memory-dos(25309)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0995" source="VUPEN">ADV-2006-0995</ref>
      <ref url="http://www.securityfocus.com/bid/17098" source="BID">17098</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428016/100/0/threaded" source="BUGTRAQ" adv="1">20060317 Symantec Security Advisory SYM06-004</ref>
      <ref url="http://securitytracker.com/id?1015784" source="SECTRACK">1015784</ref>
      <ref url="http://secunia.com/advisories/19242" source="SECUNIA" adv="1">19242</ref>
      <ref url="http://securityreason.com/securityalert/597" source="SREASON">597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="netware_server_9.1" />
        <vers num="netware_server_9.2" />
      </prod>
      <prod vendor="symantec_veritas" name="backup_exec_remote_agent">
        <vers num="netware_server_9.1" />
        <vers num="netware_server_9.2" />
        <vers num="unix_linux_server_10.1" />
        <vers num="windows_server_10.0" />
        <vers num="windows_server_10.1" />
        <vers num="windows_server_9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1298" published="2006-03-19" name="CVE-2006-1298" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Backup Exec 9.1 for Windows Servers rev. 4691, when the job log mode is Full Detailed (aka Full Details), allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted filename on a machine that is backed up by Backup Exec.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability can only be exploited if the 'job log' mode is set to "Full Detailed" (aka Full Details).  Other older versions of Windows Server (those that have been End-Of-Life'd) should be upgraded to the latest patch of one of the current versions listed above.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17096" source="BID" patch="1">17096</ref>
      <ref url="http://support.veritas.com/docs/282254" source="CONFIRM" patch="1" adv="1">http://support.veritas.com/docs/282254</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25310" source="XF">backupexec-bengine-format-string(25310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0996" source="VUPEN">ADV-2006-0996</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.03.17b.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.03.17b.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428223/100/0/threaded" source="BUGTRAQ">20060320 Symantec Security Advisory, SYM06-005</ref>
      <ref url="http://securitytracker.com/id?1015785" source="SECTRACK">1015785</ref>
      <ref url="http://secunia.com/advisories/19242" source="SECUNIA">19242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":windows_servers" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1300" published="2006-07-11" name="CVE-2006-1300" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18920" source="BID" patch="1">18920</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-033.mspx" source="MS" patch="1">MS06-033</ref>
      <ref url="http://securitytracker.com/id?1016465" source="SECTRACK" patch="1">1016465</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2751" source="VUPEN">ADV-2006-2751</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26802" source="XF">ms-aspnet-appcode-information-disclosure(26802)</ref>
      <ref url="http://www.osvdb.org/27153" source="OSVDB">27153</ref>
      <ref url="http://secunia.com/advisories/20999" source="SECUNIA">20999</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:419" source="OVAL" sig="1">oval:org.mitre.oval:def:419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1301" published="2006-07-13" name="CVE-2006-1301" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx" source="MS" patch="1" adv="1">MS06-037</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2755" source="VUPEN" adv="1">ADV-2006-2755</ref>
      <ref url="http://www.securityfocus.com/bid/18853" source="BID">18853</ref>
      <ref url="http://securitytracker.com/id?1016472" source="SECTRACK">1016472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:557" source="OVAL" sig="1">oval:org.mitre.oval:def:557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1302" published="2006-07-13" name="CVE-2006-1302" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18885" source="BID" patch="1">18885</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx" source="MS" patch="1">MS06-037</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2755" source="VUPEN">ADV-2006-2755</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439914/100/0/threaded" source="BUGTRAQ">20060712 NSFOCUS SA2006-05 : Microsoft Excel SELECTION Record Memory Corruption Vulnerability</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0605.htm" source="MISC" adv="1">http://www.nsfocus.com/english/homepage/research/0605.htm</ref>
      <ref url="http://securitytracker.com/id?1016472" source="SECTRACK">1016472</ref>
      <ref url="http://securityreason.com/securityalert/1238" source="SREASON">1238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:379" source="OVAL" sig="1">oval:org.mitre.oval:def:379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1303" published="2006-06-13" name="CVE-2006-1303" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/959049" source="CERT-VN">VU#959049</ref>
      <ref url="http://www.securityfocus.com/bid/18328" source="BID" patch="1">18328</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx" source="MS" patch="1" adv="1">MS06-021</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26774" source="XF">ie-wmm2fxadll-execute-code(26774)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-018.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-018.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2319" source="VUPEN" adv="1">ADV-2006-2319</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437041/100/0/threaded" source="BUGTRAQ">20060613 ZDI-06-018: Microsoft Internet Explorer DXImageTransform ActiveX Memory Corruption Vulnerability</ref>
      <ref url="http://www.osvdb.org/26442" source="OSVDB">26442</ref>
      <ref url="http://securitytracker.com/id?1016291" source="SECTRACK">1016291</ref>
      <ref url="http://secunia.com/advisories/20595" source="SECUNIA" adv="1">20595</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2017" source="OVAL" sig="1">oval:org.mitre.oval:def:2017</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1973" source="OVAL" sig="1">oval:org.mitre.oval:def:1973</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1928" source="OVAL" sig="1">oval:org.mitre.oval:def:1928</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1830" source="OVAL" sig="1">oval:org.mitre.oval:def:1830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1767" source="OVAL" sig="1">oval:org.mitre.oval:def:1767</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1135" source="OVAL" sig="1">oval:org.mitre.oval:def:1135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows_95" />
        <vers num="5.0.1" edition=":windows_2000" />
        <vers num="5.0.1" edition=":windows_98" />
        <vers num="5.0.1" edition=":windows_nt_4.0" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1304" published="2006-07-13" name="CVE-2006-1304" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18888" source="BID" patch="1">18888</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx" source="MS" patch="1">MS06-037</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2755" source="VUPEN">ADV-2006-2755</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439909/100/0/threaded" source="BUGTRAQ">20060712 NSFOCUS SA2006-06 : Microsoft Excel COLINFO Record Buffer Overflow Vulnerability</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0606.htm" source="MISC" adv="1">http://www.nsfocus.com/english/homepage/research/0606.htm</ref>
      <ref url="http://securitytracker.com/id?1016472" source="SECTRACK">1016472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:545" source="OVAL" sig="1">oval:org.mitre.oval:def:545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1305" published="2006-12-31" name="CVE-2006-1305" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/617436" source="CERT-VN">VU#617436</ref>
      <ref url="http://www.securityfocus.com/bid/21937" source="BID" patch="1">21937</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" source="MS" patch="1" adv="1">MS07-003</ref>
      <ref url="http://securitytracker.com/id?1017488" source="SECTRACK" patch="1">1017488</ref>
      <ref url="http://secunia.com/advisories/23674" source="SECUNIA" patch="1" adv="1">23674</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0104" source="VUPEN" adv="1">ADV-2007-0104</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.osvdb.org/31253" source="OSVDB">31253</ref>
      <ref url="http://osvdb.org/ref/24/24081-outlook1.txt" source="MISC">http://osvdb.org/ref/24/24081-outlook1.txt</ref>
      <ref url="http://linuxbox.org/pipermail/funsec/2006-March/005208.html" source="MLIST">[funsec] 20060308 DOSing Outlook 2003</ref>
      <ref url="http://blogs.securiteam.com/index.php/archives/347" source="MISC">http://blogs.securiteam.com/index.php/archives/347</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:122" source="OVAL" sig="1">oval:org.mitre.oval:def:122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1306" published="2006-07-13" name="CVE-2006-1306" modified="2011-03-07" discovered="2006-05-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18886" source="BID" patch="1">18886</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx" source="MS" patch="1" adv="1">MS06-037</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2755" source="VUPEN" adv="1">ADV-2006-2755</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439884/100/0/threaded" source="BUGTRAQ" adv="1">20060712 Microsoft Excel Array Index Error Remote Code Execution</ref>
      <ref url="http://secway.org/advisory/AD20060711.txt" source="MISC" adv="1">http://secway.org/advisory/AD20060711.txt</ref>
      <ref url="http://securitytracker.com/id?1016472" source="SECTRACK">1016472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:950" source="OVAL" sig="1">oval:org.mitre.oval:def:950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1308" published="2006-07-13" name="CVE-2006-1308" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18890" source="BID" patch="1">18890</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx" source="MS" patch="1">MS06-037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27464" source="XF">excel-fngroupcount-bo(27464)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2755" source="VUPEN" adv="1">ADV-2006-2755</ref>
      <ref url="http://securitytracker.com/id?1016472" source="SECTRACK">1016472</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047837.html" source="FULLDISC">20060712 Microsoft Excel Could Allow Remote Code Execution by Malformed FNGROUPCOUNT value Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:243" source="OVAL" sig="1">oval:org.mitre.oval:def:243</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1309" published="2006-07-13" name="CVE-2006-1309" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx" source="MS" patch="1" adv="1">MS06-037</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2755" source="VUPEN" adv="1">ADV-2006-2755</ref>
      <ref url="http://www.securityfocus.com/bid/18910" source="BID">18910</ref>
      <ref url="http://securitytracker.com/id?1016472" source="SECTRACK">1016472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:752" source="OVAL" sig="1">oval:org.mitre.oval:def:752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac_os_x" />
        <vers num="x" edition="" />
        <vers num="x" edition=":mac_os_x" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1311" published="2007-02-13" name="CVE-2006-1311" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/368132" source="CERT-VN">VU#368132</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-013.mspx" source="MS" patch="1" adv="1">MS07-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0582" source="VUPEN">ADV-2007-0582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/30592" source="XF">ms-richedit-code-execution(30592)</ref>
      <ref url="http://www.securitytracker.com/id?1017641" source="SECTRACK">1017641</ref>
      <ref url="http://www.securitytracker.com/id?1017640" source="SECTRACK">1017640</ref>
      <ref url="http://www.securityfocus.com/bid/21876" source="BID">21876</ref>
      <ref url="http://www.osvdb.org/31886" source="OSVDB">31886</ref>
      <ref url="http://secunia.com/advisories/24152" source="SECUNIA">24152</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1090" source="OVAL" sig="1">oval:org.mitre.oval:def:1090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="learning_essentials">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.5" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1313" published="2006-06-13" name="CVE-2006-1313" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" source="CERT">TA06-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/390044" source="CERT-VN">VU#390044</ref>
      <ref url="http://www.securityfocus.com/bid/18359" source="BID" patch="1">18359</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-023.mspx" source="MS" patch="1" adv="1">MS06-023</ref>
      <ref url="http://secunia.com/advisories/20620" source="SECUNIA" patch="1" adv="1">20620</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26805" source="XF">ms-jscript-code-execution(26805)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2321" source="VUPEN">ADV-2006-2321</ref>
      <ref url="http://www.osvdb.org/26434" source="OSVDB">26434</ref>
      <ref url="http://securitytracker.com/id?1016283" source="SECTRACK">1016283</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2003" source="OVAL" sig="1">oval:org.mitre.oval:def:2003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1785" source="OVAL" sig="1">oval:org.mitre.oval:def:1785</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1644" source="OVAL" sig="1">oval:org.mitre.oval:def:1644</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1067" source="OVAL" sig="1">oval:org.mitre.oval:def:1067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_edition" edition="sp1" />
        <vers num="datacenter_edition_64-bit" edition="sp1" />
        <vers num="enterprise_64-bit" />
        <vers num="enterprise_edition" edition="sp1" />
        <vers num="enterprise_edition_64-bit" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":enterprise" />
        <vers num="standard" edition="sp1" />
        <vers num="standard_64-bit" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1314" published="2006-07-11" name="CVE-2006-1314" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/189140" source="CERT-VN">VU#189140</ref>
      <ref url="http://www.tippingpoint.com/security/advisories/TSRT-06-02.html" source="MISC" patch="1" adv="1">http://www.tippingpoint.com/security/advisories/TSRT-06-02.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-035.mspx" source="MS" patch="1" adv="1">MS06-035</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2753" source="VUPEN">ADV-2006-2753</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26818" source="XF">win-mailslot-bo(26818)</ref>
      <ref url="http://www.securityfocus.com/bid/18863" source="BID">18863</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439773/100/0/threaded" source="BUGTRAQ">20060711 TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability</ref>
      <ref url="http://www.osvdb.org/27154" source="OSVDB">27154</ref>
      <ref url="http://securityreason.com/securityalert/1212" source="SREASON">1212</ref>
      <ref url="http://secunia.com/advisories/21007" source="SECUNIA">21007</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:600" source="OVAL" sig="1">oval:org.mitre.oval:def:600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="r2" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1315" published="2006-07-11" name="CVE-2006-1315" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/333636" source="CERT-VN">VU#333636</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-035.mspx" source="MS" patch="1" adv="1">MS06-035</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2753" source="VUPEN">ADV-2006-2753</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26820" source="XF">win-smb-information-disclosure(26820)</ref>
      <ref url="http://www.securityfocus.com/bid/18891" source="BID">18891</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439881/100/0/threaded" source="BUGTRAQ">20060711 SMB Information Disclosure Vulnerability</ref>
      <ref url="http://www.osvdb.org/27155" source="OSVDB">27155</ref>
      <ref url="http://securitytracker.com/id?1016467" source="SECTRACK">1016467</ref>
      <ref url="http://secunia.com/advisories/21007" source="SECUNIA">21007</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3" source="OVAL" sig="1">oval:org.mitre.oval:def:3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="server_service">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1316" published="2006-07-11" name="CVE-2006-1316" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/580036" source="CERT-VN">VU#580036</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-038.mspx" source="MS" patch="1">MS06-038</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27607" source="XF">office-string-parse-bo(27607)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2756" source="VUPEN" adv="1">ADV-2006-2756</ref>
      <ref url="http://www.securityfocus.com/bid/18912" source="BID">18912</ref>
      <ref url="http://www.osvdb.org/27148" source="OSVDB">27148</ref>
      <ref url="http://securitytracker.com/id?1016469" source="SECTRACK">1016469</ref>
      <ref url="http://secunia.com/advisories/21012" source="SECUNIA" adv="1">21012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:918" source="OVAL" sig="1">oval:org.mitre.oval:def:918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1319" published="2006-03-20" name="CVE-2006-1319" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes chpst to assign permissions for the root group due to inconsistent bit sizes for the gid_t type.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may be relevant only to Debian GNU/Linux implementations on little endian i386 machines.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356016" source="CONFIRM" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25419" source="XF">runit-chpst-gain-privileges(25419)</ref>
      <ref url="http://www.securityfocus.com/bid/17179" source="BID">17179</ref>
      <ref url="http://secunia.com/advisories/19323" source="SECUNIA">19323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runit" name="runit">
        <vers num="1.3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1320" published="2006-03-20" name="CVE-2006-1320" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346322" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346322</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25424" source="XF">debian-rssh-rsync-rdist-bypass-security(25424)</ref>
      <ref url="http://www.securityfocus.com/bid/18999" source="BID">18999</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1109" source="DEBIAN">DSA-1109</ref>
      <ref url="http://secunia.com/advisories/21087" source="SECUNIA">21087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rssh" name="rssh">
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1321" published="2006-03-20" name="CVE-2006-1321" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.</descript>
    </desc>
    <sols>
      <sol source="nvd">Versions before 1.0 are named "linbot" instead of "webcheck".</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ch.tudelft.nl/~arthur/webcheck/news.html#20060130" source="CONFIRM" patch="1">http://ch.tudelft.nl/~arthur/webcheck/news.html#20060130</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25428" source="XF">webcheck-content-xss(25428)</ref>
      <ref url="http://www.securityfocus.com/bid/17212" source="BID">17212</ref>
      <ref url="http://secunia.com/advisories/19309" source="SECUNIA">19309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcheck" name="webcheck">
        <vers num="1.9.0" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers prev="1" num="1.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1322" published="2006-03-20" name="CVE-2006-1322" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2973435.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2973435.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25289" source="XF">netware-nwftpd-mdtm-dos(25289)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0975" source="VUPEN">ADV-2006-0975</ref>
      <ref url="http://www.securityfocus.com/bid/17137" source="BID">17137</ref>
      <ref url="http://www.osvdb.org/23949" source="OSVDB">23949</ref>
      <ref url="http://securitytracker.com/id?1015781" source="SECTRACK">1015781</ref>
      <ref url="http://secunia.com/advisories/19265" source="SECUNIA">19265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers prev="1" num="5.06.05" />
        <vers num="5.07" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1323" published="2006-03-20" name="CVE-2006-1323" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZIP, or (4) TAR.GZ archive with a file whose file name contains ".." sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25335" source="XF">winhki-extract-directory-traversal(25335)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1010" source="VUPEN">ADV-2006-1010</ref>
      <ref url="http://www.securityfocus.com/bid/17153" source="BID">17153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428433/100/0/threaded" source="BUGTRAQ">20060322 WinHKI 1.6x Archive Extraction Directory traversal</ref>
      <ref url="http://secunia.com/advisories/19296" source="SECUNIA" adv="1">19296</ref>
      <ref url="http://hamid.ir/security/winhki.txt" source="MISC">http://hamid.ir/security/winhki.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtoolmaster_software" name="winhki">
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1324" published="2006-03-20" name="CVE-2006-1324" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1003" source="VUPEN">ADV-2006-1003</ref>
      <ref url="http://www.securityfocus.com/bid/17147" source="BID">17147</ref>
      <ref url="http://www.securityfocus.com/archive/1/428080" source="BUGTRAQ">20060318 Xss in Wbb 2.3.4</ref>
      <ref url="http://secunia.com/advisories/19293" source="SECUNIA" adv="1">19293</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25313" source="XF">wbb-classdbmysql-xss(25313)</ref>
      <ref url="http://securitytracker.com/id?1015789" source="SECTRACK">1015789</ref>
      <ref url="http://securityreason.com/securityalert/598" source="SREASON">598</ref>
      <ref url="http://securityreason.com/securityalert/529" source="SREASON">529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers prev="1" num="1.0.2pl2e_lite" />
        <vers prev="1" num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1325" published="2006-03-20" name="CVE-2006-1325" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Streber 0.055 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vulnerability has been fixed in version 0.055 (development release).</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1005" source="VUPEN">ADV-2006-1005</ref>
      <ref url="http://www.streber-pm.org/phpBB2/viewtopic.php?p=491#491" source="CONFIRM">http://www.streber-pm.org/phpBB2/viewtopic.php?p=491#491</ref>
      <ref url="http://secunia.com/advisories/19263" source="SECUNIA" adv="1">19263</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25317" source="XF">streber-xss(25317)</ref>
      <ref url="http://www.securityfocus.com/bid/17157" source="BID">17157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="streber" name="streber">
        <vers prev="1" num="0.055" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1326" published="2006-03-20" name="CVE-2006-1326" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sort_order, (15) max_results, or (16) sort_key parameter in a Members action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17144" source="BID">17144</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428015/100/0/threaded" source="BUGTRAQ">20060317 XSS IN Invision Power Board</ref>
      <ref url="http://www.osvdb.org/25015" source="OSVDB">25015</ref>
      <ref url="http://www.osvdb.org/25014" source="OSVDB">25014</ref>
      <ref url="http://www.osvdb.org/25013" source="OSVDB">25013</ref>
      <ref url="http://www.osvdb.org/25012" source="OSVDB">25012</ref>
      <ref url="http://www.osvdb.org/25011" source="OSVDB">25011</ref>
      <ref url="http://www.osvdb.org/25010" source="OSVDB">25010</ref>
      <ref url="http://www.osvdb.org/25009" source="OSVDB">25009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1327" published="2006-03-20" name="CVE-2006-1327" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in reg.php in SoftBB 0.1 allows remote attackers to execute arbitrary SQL commands via the mail parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1002" source="VUPEN">ADV-2006-1002</ref>
      <ref url="http://secunia.com/advisories/19283" source="SECUNIA" adv="1">19283</ref>
      <ref url="http://milw0rm.com/exploits/1594" source="MILW0RM">1594</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25320" source="XF">softbb-reg-sql-injection(25320)</ref>
      <ref url="http://www.securityfocus.com/bid/17160" source="BID">17160</ref>
      <ref url="http://www.osvdb.org/23999" source="OSVDB">23999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softbb" name="softbb">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1328" published="2006-03-20" name="CVE-2006-1328" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldname, or (3) url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1004" source="VUPEN">ADV-2006-1004</ref>
      <ref url="http://secunia.com/advisories/19314" source="SECUNIA" adv="1">19314</ref>
      <ref url="http://evuln.com/vulns/105/summary.html" source="MISC">http://evuln.com/vulns/105/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25316" source="XF">downloadcounter-count-sql-injection(25316)</ref>
      <ref url="http://www.securityfocus.com/bid/17156" source="BID">17156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429255/100/0/threaded" source="BUGTRAQ">20060329 [eVuln] Skull-Splitter's PHP Downloadcounter for Wallpapers SQL Injection</ref>
      <ref url="http://www.osvdb.org/23972" source="OSVDB">23972</ref>
      <ref url="http://securityreason.com/securityalert/649" source="SREASON">649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skull-splitter" name="download_counter_wallpaper">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1329" published="2006-03-20" name="CVE-2006-1329" modified="2011-06-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://article.gmane.org/gmane.network.jabber.admin/27372" source="CONFIRM" patch="1">http://article.gmane.org/gmane.network.jabber.admin/27372</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25334" source="XF">jabberd-sasl-dos(25334)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1009" source="VUPEN" adv="1">ADV-2006-1009</ref>
      <ref url="http://www.securityfocus.com/bid/17155" source="BID">17155</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://secunia.com/advisories/19281" source="SECUNIA" adv="1">19281</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jabberstudio" name="jabberd">
        <vers num="2.0_a1" />
        <vers num="2.0_a2" />
        <vers num="2.0_a3" />
        <vers num="2.0_a4" />
        <vers num="2.0_a5" />
        <vers num="2.0_a6" />
        <vers num="2.0_b1" />
        <vers num="2.0_b2" />
        <vers num="2.0_b3" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_s1" />
        <vers prev="1" num="2.0_s10" />
        <vers num="2.0_s2" />
        <vers num="2.0_s3" />
        <vers num="2.0_s4" />
        <vers num="2.0_s5" />
        <vers num="2.0_s6" />
        <vers num="2.0_s7" />
        <vers num="2.0_s8" />
        <vers num="2.0_s9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1330" published="2006-03-20" name="CVE-2006-1330" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25328" source="XF">phpwebsite-multiple-sql-injection(25328)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1039" source="VUPEN" adv="1">ADV-2006-1039</ref>
      <ref url="http://www.securityfocus.com/bid/17150" source="BID">17150</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430870/100/0/threaded" source="BUGTRAQ">20060413 Re: phpWebsite &lt;= SQL Injection (friend.php) &amp; (article.php)</ref>
      <ref url="http://www.securityfocus.com/archive/1/428156" source="BUGTRAQ">20060318 phpWebsite &lt;= SQL Injection (friend.php) &amp; (article.php)</ref>
      <ref url="http://secunia.com/advisories/19315" source="SECUNIA" adv="1">19315</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.7.3" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1331" published="2006-03-20" name="CVE-2006-1331" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zone14.free.fr/advisories/1" source="MISC" adv="1">http://zone14.free.fr/advisories/1</ref>
      <ref url="http://www.securityfocus.com/bid/17151" source="BID">17151</ref>
      <ref url="http://www.securityfocus.com/archive/1/428157" source="BUGTRAQ">20060320 Noah's Classifieds Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25331" source="XF">noahs-index-path-disclosure(25331)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25099" source="XF">noahs-index-xss(25099)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0191.html" source="FULLDISC">20060308 Noah's Classifieds Multiple Cross-Site Scripting Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1332" published="2006-03-20" name="CVE-2006-1332" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/428157" source="BUGTRAQ">20060320 Noah's Classifieds Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25331" source="XF">noahs-index-path-disclosure(25331)</ref>
      <ref url="http://securityreason.com/securityalert/605" source="SREASON">605</ref>
      <ref url="http://securityreason.com/securityalert/471" source="SREASON">471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="noahs_classifieds">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1333" published="2006-03-20" name="CVE-2006-1333" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multpile SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 6.02.</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19292" source="SECUNIA" patch="1" adv="1">19292</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1000" source="VUPEN">ADV-2006-1000</ref>
      <ref url="http://www.securityfocus.com/bid/17148" source="BID">17148</ref>
      <ref url="http://www.securityfocus.com/archive/1/428082" source="BUGTRAQ">20060318 Advisory: BetaParticle Blog &lt;= 6.0 Multiple Remote SQL InjectionVulnerabilities</ref>
      <ref url="http://www.nukedx.com/?viewdoc=20" source="MISC">http://www.nukedx.com/?viewdoc=20</ref>
      <ref url="http://blog.betaparticle.com/UserFiles/File/6fix.txt" source="CONFIRM">http://blog.betaparticle.com/UserFiles/File/6fix.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25327" source="XF">bpblog-multiple-sql-injection(25327)</ref>
      <ref url="http://www.osvdb.org/23966" source="OSVDB">23966</ref>
      <ref url="http://www.osvdb.org/23965" source="OSVDB">23965</ref>
      <ref url="http://securitytracker.com/id?1015788" source="SECTRACK">1015788</ref>
      <ref url="http://securityreason.com/securityalert/600" source="SREASON">600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="betaparticle" name="betaparticle_blog">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1334" published="2006-03-20" name="CVE-2006-1334" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25295" source="XF">maianweblog-printmail-sql-injection(25295)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0994" source="VUPEN">ADV-2006-0994</ref>
      <ref url="http://www.osvdb.org/23946" source="OSVDB">23946</ref>
      <ref url="http://secunia.com/advisories/19273" source="SECUNIA" adv="1">19273</ref>
      <ref url="http://evuln.com/vulns/101/summary.html" source="MISC">http://evuln.com/vulns/101/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/17247" source="BID">17247</ref>
      <ref url="http://www.securityfocus.com/bid/17159" source="BID">17159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428903/100/0/threaded" source="BUGTRAQ">20060327 [eVuln] Maian Weblog Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/23945" source="OSVDB">23945</ref>
      <ref url="http://securitytracker.com/id?1015818" source="SECTRACK">1015818</ref>
      <ref url="http://securityreason.com/securityalert/638" source="SREASON">638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian_script_world" name="maian_weblog">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1335" published="2006-03-20" name="CVE-2006-1335" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vulnerability has reportedly been fixed in version 2.14.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25340" source="XF">gnomescreensaver-security-bypass(25340)</ref>
      <ref url="http://www.osvdb.org/24015" source="OSVDB">24015</ref>
      <ref url="http://secunia.com/advisories/19280" source="SECUNIA" adv="1">19280</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=326663" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=326663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="screensaver">
        <vers prev="1" num="2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1336" published="2006-03-20" name="CVE-2006-1336" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) year, (2) month, (3) next, and (4) prev parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">This issue is reportedly addressed in ExtCalendar 2.0. Symantec has not confirmed this fix. Affected users are advised to contact the vendor for further information.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1012" source="VUPEN">ADV-2006-1012</ref>
      <ref url="http://www.securityfocus.com/bid/17146" source="BID">17146</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428131/100/0/threaded" source="BUGTRAQ">20060319 ExtCalendar v1.0 Multiple Xss Vuln</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25350" source="XF">extcalendar-calendar-xss(25350)</ref>
      <ref url="http://www.osvdb.org/23969" source="OSVDB">23969</ref>
      <ref url="http://securityreason.com/securityalert/601" source="SREASON">601</ref>
      <ref url="http://secunia.com/advisories/19321" source="SECUNIA">19321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extcalendar" name="extcalendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1337" published="2006-03-20" name="CVE-2006-1337" modified="2011-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the POP 3 (POP3) service in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 allows remote attackers to execute arbitrary code via unknown vectors before authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19288" source="SECUNIA" patch="1" adv="1">19288</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25314" source="XF">mailenable-pop-authentication(25314)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1006" source="VUPEN" adv="1">ADV-2006-1006</ref>
      <ref url="http://www.securityfocus.com/bid/17162" source="BID">17162</ref>
      <ref url="http://www.osvdb.org/24012" source="OSVDB">24012</ref>
      <ref url="http://www.mailenable.com/standardhistory.asp" source="CONFIRM">http://www.mailenable.com/standardhistory.asp</ref>
      <ref url="http://www.mailenable.com/professionalhistory.asp" source="CONFIRM">http://www.mailenable.com/professionalhistory.asp</ref>
      <ref url="http://www.mailenable.com/enterprisehistory.asp" source="CONFIRM">http://www.mailenable.com/enterprisehistory.asp</ref>
      <ref url="http://securitytracker.com/id?1015797" source="SECTRACK">1015797</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1359.html" source="FULLDISC">20060320 [MU-200603-01] MailEnable POP3 Pre-Authentication Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable">
        <vers num="1.00" edition="" />
        <vers num="1.00" edition=":enterprise" />
        <vers num="1.01" edition="" />
        <vers num="1.01" edition=":enterprise" />
        <vers num="1.02" edition="" />
        <vers num="1.02" edition=":enterprise" />
        <vers num="1.03" edition="" />
        <vers num="1.03" edition=":enterprise" />
        <vers num="1.04" edition="" />
        <vers num="1.04" edition=":enterprise" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":enterprise" />
        <vers num="1.17" edition="" />
        <vers num="1.17" edition=":professional" />
        <vers num="1.18" edition="" />
        <vers num="1.18" edition=":professional" />
        <vers num="1.19" edition="" />
        <vers num="1.19" edition=":professional" />
        <vers prev="1" num="1.2" edition="" />
        <vers prev="1" num="1.2" edition=":professional" />
        <vers prev="1" num="1.2" edition=":enterprise" />
        <vers num="1.2a" edition="" />
        <vers num="1.2a" edition=":professional" />
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":professional" />
        <vers num="1.51" edition="" />
        <vers num="1.51" edition=":professional" />
        <vers num="1.52" edition="" />
        <vers num="1.52" edition=":professional" />
        <vers num="1.53" edition="" />
        <vers num="1.53" edition=":professional" />
        <vers num="1.54" edition="" />
        <vers num="1.54" edition=":professional" />
        <vers num="1.6" edition="" />
        <vers num="1.6" edition=":professional" />
        <vers num="1.7" edition="" />
        <vers num="1.7" edition=":professional" />
        <vers num="1.70" edition="" />
        <vers num="1.70" edition=":professional" />
        <vers num="1.701" edition="" />
        <vers num="1.701" edition=":standard" />
        <vers num="1.702" edition="" />
        <vers num="1.702" edition=":standard" />
        <vers num="1.703" edition="" />
        <vers num="1.703" edition=":standard" />
        <vers num="1.704" edition="" />
        <vers num="1.704" edition=":standard" />
        <vers num="1.71" edition="" />
        <vers num="1.71" edition=":standard" />
        <vers num="1.71" edition=":professional" />
        <vers prev="1" num="1.72" edition="" />
        <vers prev="1" num="1.72" edition=":standard" />
        <vers prev="1" num="1.72" edition=":professional" />
        <vers num="1.8" edition="" />
        <vers num="1.8" edition=":standard" />
        <vers num="1.90" edition="" />
        <vers num="1.90" edition=":standard" />
        <vers num="1.91" edition="" />
        <vers num="1.91" edition=":standard" />
        <vers prev="1" num="1.92" edition="" />
        <vers prev="1" num="1.92" edition=":standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1338" published="2006-03-20" name="CVE-2006-1338" modified="2011-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors involving "incorrectly encoded quoted-printable emails".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19288" source="SECUNIA" patch="1" adv="1">19288</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25315" source="XF">mailenable-webmail-component-dos(25315)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1006" source="VUPEN" adv="1">ADV-2006-1006</ref>
      <ref url="http://www.securityfocus.com/bid/17161" source="BID">17161</ref>
      <ref url="http://www.osvdb.org/24014" source="OSVDB">24014</ref>
      <ref url="http://www.mailenable.com/professionalhistory.asp" source="CONFIRM">http://www.mailenable.com/professionalhistory.asp</ref>
      <ref url="http://www.mailenable.com/enterprisehistory.asp" source="CONFIRM">http://www.mailenable.com/enterprisehistory.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.71" />
        <vers num="1.72" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1339" published="2006-03-20" name="CVE-2006-1339" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which bypasses a sanity check that is only applied to a GET request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17152" source="BID">17152</ref>
      <ref url="http://secunia.com/advisories/19289" source="SECUNIA" adv="1">19289</ref>
      <ref url="http://hamid.ir/security/cutenews.txt" source="MISC">http://hamid.ir/security/cutenews.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25324" source="XF">cutenews-incfunction-directory-traversal(25324)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428434/100/0/threaded" source="BUGTRAQ">20060322 cutenews 1.4.1 Arbitrary File Access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers prev="1" num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1340" published="2006-03-20" name="CVE-2006-1340" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "register_globals" parameter is enabled.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17152" source="BID">17152</ref>
      <ref url="http://secunia.com/advisories/19289" source="SECUNIA" adv="1">19289</ref>
      <ref url="http://hamid.ir/security/cutenews.txt" source="MISC">http://hamid.ir/security/cutenews.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428434/100/0/threaded" source="BUGTRAQ">20060322 cutenews 1.4.1 Arbitrary File Access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="0.88" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.6" />
        <vers num="1.4.0" />
        <vers prev="1" num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1341" published="2006-03-20" name="CVE-2006-1341" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25298" source="XF">maianevents-events-sql-injection(25298)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0993" source="VUPEN">ADV-2006-0993</ref>
      <ref url="http://secunia.com/advisories/19274" source="SECUNIA" adv="1">19274</ref>
      <ref url="http://evuln.com/vulns/102/description.html" source="MISC">http://evuln.com/vulns/102/description.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429093/100/0/threaded" source="BUGTRAQ">20060328 [eVuln] Maian Events SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/23947" source="OSVDB">23947</ref>
      <ref url="http://securityreason.com/securityalert/646" source="SREASON">646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian_events" name="maian_events">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1342" published="2006-03-21" name="CVE-2006-1342" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=09d3b3dcfa80c9094f1748c1be064b9326c9ef2b" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=09d3b3dcfa80c9094f1748c1be064b9326c9ef2b</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN">ADV-2006-4502</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-netdev&amp;m=114148078223594&amp;w=2" source="MLIST">[linux-netdev] 20060304 BUG: Small information leak in SO_ORIGINAL_DST (2.4 and 2.6) and</ref>
      <ref url="http://www.vmware.com/download/esx/esx-254-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-254-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-213-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-213-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-202-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-202-200610-patch.html</ref>
      <ref url="http://www.securityfocus.com/bid/17203" source="BID">17203</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0580.html" source="REDHAT">RHSA-2006:0580</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0579.html" source="REDHAT">RHSA-2006:0579</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA">22875</ref>
      <ref url="http://secunia.com/advisories/21035" source="SECUNIA">21035</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19357" source="SECUNIA">19357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1343" published="2006-03-21" name="CVE-2006-1343" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">net/ipv4/netfilter/ip_conntrack_core.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c in 2.6, does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the getsockopt function with SO_ORIGINAL_DST, which allows local users to obtain portions of potentially sensitive memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-netdev&amp;m=114148078223594&amp;w=2" source="MLIST" patch="1">[linux-netdev] 20060304 BUG: Small information leak in SO_ORIGINAL_DST (2.4 and 2.6) and</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN">ADV-2006-4502</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2071" source="VUPEN">ADV-2006-2071</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10875" source="OVAL">oval:org.mitre.oval:def:10875</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25425" source="XF">linux-sockaddr-memory-leak(25425)</ref>
      <ref url="http://www.vmware.com/download/esx/esx-254-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-254-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-213-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-213-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-202-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-202-200610-patch.html</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0032/" source="TRUSTIX">2006-0032</ref>
      <ref url="http://www.securityfocus.com/bid/17203" source="BID">17203</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435490/100/0/threaded" source="BUGTRAQ">20060531 rPSA-2006-0087-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0580.html" source="REDHAT">RHSA-2006:0580</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0579.html" source="REDHAT">RHSA-2006:0579</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0437.html" source="REDHAT">RHSA-2006:0437</ref>
      <ref url="http://www.osvdb.org/29841" source="OSVDB">29841</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1184" source="DEBIAN">DSA-1184</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA">22875</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/22093" source="SECUNIA">22093</ref>
      <ref url="http://secunia.com/advisories/21983" source="SECUNIA">21983</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/21136" source="SECUNIA">21136</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA">21045</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA">19955</ref>
      <ref url="http://secunia.com/advisories/19357" source="SECUNIA">19357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1344" published="2006-03-21" name="CVE-2006-1344" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the VHTML_FILE parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1084" source="VUPEN">ADV-2006-1084</ref>
      <ref url="http://www.securityfocus.com/bid/17170" source="BID">17170</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428267/100/0/threaded" source="BUGTRAQ">20060320 CORE-2006-0124: Cross-Site Scripting in Verisign?s haydn.exe CGI script</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=522&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=522&amp;idxseccion=10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25349" source="XF">verisign-haydn-xss(25349)</ref>
      <ref url="http://securitytracker.com/id?1015813" source="SECTRACK">1015813</ref>
      <ref url="http://securityreason.com/securityalert/614" source="SREASON">614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verisign" name="mpki">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1345" published="2006-03-21" name="CVE-2006-1345" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an "option[]=null" parameter value, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25337" source="XF">mybb-polls-path-disclosure(25337)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428056/100/0/threaded" source="BUGTRAQ">20060317 MyBB 1.10 Full Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1346" published="2006-03-21" name="CVE-2006-1346" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1015" source="VUPEN">ADV-2006-1015</ref>
      <ref url="http://www.securityfocus.com/bid/17165" source="BID">17165</ref>
      <ref url="http://www.milw0rm.com/exploits/1595" source="MILW0RM">1595</ref>
      <ref url="http://www.osvdb.org/24016" source="OSVDB">24016</ref>
      <ref url="http://secunia.com/advisories/19322" source="SECUNIA">19322</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000698.html" source="VIM">20060414 Provable vendor ACK for gcards issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_neustaetter" name="gcards">
        <vers num="1.43" />
        <vers num="1.44" />
        <vers prev="1" num="1.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1347" published="2006-03-21" name="CVE-2006-1347" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Vulnerability can only be exploited if the "magic_quotes_gpc" parameter is set to Off.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1015" source="VUPEN">ADV-2006-1015</ref>
      <ref url="http://www.securityfocus.com/bid/17165" source="BID">17165</ref>
      <ref url="http://www.milw0rm.com/exploits/1595" source="MILW0RM">1595</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25344" source="XF">gcards-loginfunction-sql-injection(25344)</ref>
      <ref url="http://www.osvdb.org/24017" source="OSVDB">24017</ref>
      <ref url="http://secunia.com/advisories/19322" source="SECUNIA">19322</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000698.html" source="VIM">20060414 Provable vendor ACK for gcards issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_neustaetter" name="gcards">
        <vers num="1.43" />
        <vers num="1.44" />
        <vers prev="1" num="1.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1348" published="2006-03-21" name="CVE-2006-1348" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an error message.  NOTE: this issue might be resultant from CVE-2006-1346.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25343" source="XF">gcards-incsetlang-xss(25343)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1015" source="VUPEN">ADV-2006-1015</ref>
      <ref url="http://www.securityfocus.com/bid/17165" source="BID">17165</ref>
      <ref url="http://www.osvdb.org/24018" source="OSVDB">24018</ref>
      <ref url="http://www.milw0rm.com/exploits/1595" source="MILW0RM">1595</ref>
      <ref url="http://secunia.com/advisories/19322" source="SECUNIA" adv="1">19322</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000698.html" source="VIM">20060414 Provable vendor ACK for gcards issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_neustaetter" name="gcards">
        <vers num="1.43" />
        <vers num="1.44" />
        <vers prev="1" num="1.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1349" published="2006-03-21" name="CVE-2006-1349" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/27925" source="XF">musicbox-multiple-xss(27925)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25525" source="XF">musicbox-index-cart-xss(25525)</ref>
      <ref url="http://www.securityfocus.com/bid/17149" source="BID">17149</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded" source="BUGTRAQ">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428972/100/0/threaded" source="BUGTRAQ">20060324 XSS &amp; SQL Injection in Music Box v2.3</ref>
      <ref url="http://www.osvdb.org/23968" source="OSVDB">23968</ref>
      <ref url="http://www.osvdb.org/23967" source="OSVDB">23967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicbox" name="musicbox">
        <vers num="2.3_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1350" published="2006-03-21" name="CVE-2006-1350" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1037" source="VUPEN">ADV-2006-1037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428354/100/0/threaded" source="BUGTRAQ" adv="1">20060321 Free Articles Directory Remote Command Exucetion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25378" source="XF">freearticlesdirectory-index-file-include(25378)</ref>
      <ref url="http://www.securityfocus.com/bid/17183" source="BID">17183</ref>
      <ref url="http://www.osvdb.org/24024" source="OSVDB">24024</ref>
      <ref url="http://securityreason.com/securityalert/616" source="SREASON">616</ref>
      <ref url="http://secunia.com/advisories/19320" source="SECUNIA">19320</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000626.html" source="VIM">20060322 Free Articles Directory - file inclusion, code execution?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="articlesone" name="99articles_directory">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1351" published="2006-03-21" name="CVE-2006-1351" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a "default internal servlet" accessed through HTTP.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17166" source="BID" patch="1">17166</ref>
      <ref url="http://secunia.com/advisories/19310" source="SECUNIA" patch="1" adv="1">19310</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/180" source="BEA" patch="1" adv="1">BEA06-120.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1021" source="VUPEN">ADV-2006-1021</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25347" source="XF">weblogic-server-default-servlet(25347)</ref>
      <ref url="http://securitytracker.com/id?1015792" source="SECTRACK">1015792</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1352" published="2006-03-21" name="CVE-2006-1352" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via crafted non-canonicalized XML documents.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/183" source="BEA" patch="1" adv="1">BEA06-123.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1021" source="VUPEN">ADV-2006-1021</ref>
      <ref url="http://www.securityfocus.com/bid/17167" source="BID">17167</ref>
      <ref url="http://secunia.com/advisories/19310" source="SECUNIA" adv="1">19310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25348" source="XF">weblogic-xml-parser-dos(25348)</ref>
      <ref url="http://securitytracker.com/id?1015790" source="SECTRACK">1015790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:express" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="6.1" edition="sp7" />
        <vers num="6.1" edition="sp7:win32" />
        <vers num="6.1" edition="sp7:express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp6" />
        <vers num="7.0" edition="sp6:win32" />
        <vers num="7.0" edition="sp6:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1353" published="2006-03-21" name="CVE-2006-1353" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid parameter in download_click.asp and (2) content_ID parameter in news/News_Item.asp; authenticated administrators can also conduct attacks via (3) user_id parameter to users/add_edit_user.asp, (4) bannerid parameter to banner_adds/banner_add_edit.asp, (5) cat_id parameter to categories/add_edit_cat.asp, (6) Content_ID parameter to News/add_edit_news.asp, (7) download_id parameter to downloads/add_edit_download.asp, (8) Poll_ID parameter to poll/add_edit_poll.asp, (9) contactid parameter to contactus/contactus_add_edit.asp, (10) sortby parameter to poll/poll_list.asp, and (11) unspecified inputs to downloads/add_edit_download.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1014" source="VUPEN">ADV-2006-1014</ref>
      <ref url="http://www.nukedx.com/?viewdoc=21" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=21</ref>
      <ref url="http://www.milw0rm.com/exploits/1597" source="MILW0RM">1597</ref>
      <ref url="http://secunia.com/advisories/19286" source="SECUNIA" adv="1">19286</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25346" source="XF">aspportal-multiple-aspscripts-sql-injection(25346)</ref>
      <ref url="http://www.securityfocus.com/bid/17174" source="BID">17174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428615/100/0/threaded" source="BUGTRAQ">20060322 Re: [SPAM:] - ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities - Email has different SMTP TO: and MIME TO: fields in the email addresses</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428355/100/0/threaded" source="BUGTRAQ">20060321 ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24092" source="OSVDB">24092</ref>
      <ref url="http://www.osvdb.org/24091" source="OSVDB">24091</ref>
      <ref url="http://www.osvdb.org/24090" source="OSVDB">24090</ref>
      <ref url="http://www.osvdb.org/24089" source="OSVDB">24089</ref>
      <ref url="http://www.osvdb.org/24088" source="OSVDB">24088</ref>
      <ref url="http://www.osvdb.org/24087" source="OSVDB">24087</ref>
      <ref url="http://www.osvdb.org/24086" source="OSVDB">24086</ref>
      <ref url="http://www.osvdb.org/24085" source="OSVDB">24085</ref>
      <ref url="http://www.osvdb.org/24084" source="OSVDB">24084</ref>
      <ref url="http://www.osvdb.org/24020" source="OSVDB">24020</ref>
      <ref url="http://securityreason.com/securityalert/608" source="SREASON">608</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1431.html" source="FULLDISC">20060322 Re: [SPAM:] - ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities - Email has different SMTP TO: and MIME TO: fields in the email addresses</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1402.html" source="FULLDISC">20060321 ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspportal" name="aspportal">
        <vers num="3.0.0" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1354" published="2006-03-21" name="CVE-2006-1354" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19300" source="SECUNIA" patch="1" adv="1">19300</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1016" source="VUPEN">ADV-2006-1016</ref>
      <ref url="http://www.freeradius.org/security.html" source="CONFIRM">http://www.freeradius.org/security.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10156" source="OVAL">oval:org.mitre.oval:def:10156</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25352" source="XF">freeradius-eap-mschapv2-auth-bypass(25352)</ref>
      <ref url="http://www.trustix.org/errata/2006/0020" source="TRUSTIX">2006-0020</ref>
      <ref url="http://www.securityfocus.com/bid/17171" source="BID">17171</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:060" source="MANDRIVA">MDKSA-2006:060</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-03.xml" source="GENTOO">GLSA-200604-03</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1089" source="DEBIAN">DSA-1089</ref>
      <ref url="http://securitytracker.com/id?1015795" source="SECTRACK">1015795</ref>
      <ref url="http://secunia.com/advisories/20461" source="SECUNIA">20461</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19527" source="SECUNIA">19527</ref>
      <ref url="http://secunia.com/advisories/19518" source="SECUNIA">19518</ref>
      <ref url="http://secunia.com/advisories/19405" source="SECUNIA">19405</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0271.html" source="REDHAT">RHSA-2006:0271</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0009.html" source="SUSE">SUSE-SA:2006:019</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1355" published="2006-03-21" name="CVE-2006-1355" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">avast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1011" source="VUPEN">ADV-2006-1011</ref>
      <ref url="http://www.dslreports.com/forum/remark,15601404~days=9999~start=20" source="MISC">http://www.dslreports.com/forum/remark,15601404~days=9999~start=20</ref>
      <ref url="http://secunia.com/advisories/19284" source="SECUNIA" adv="1">19284</ref>
      <ref url="http://forum.avast.com/index.php?topic=19862.0" source="CONFIRM">http://forum.avast.com/index.php?topic=19862.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25336" source="XF">avast-default-insecure-permissions(25336)</ref>
      <ref url="http://www.securityfocus.com/bid/17158" source="BID">17158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers prev="1" num="4.6.763" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1356" published="2006-03-21" name="CVE-2006-1356" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a vCard file (e.g. contacts.vcf) containing a long line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25430" source="XF">libvc-vc-bo(25430)</ref>
      <ref url="http://www.securityfocus.com/bid/17237" source="BID">17237</ref>
      <ref url="http://www.osvdb.org/23985" source="OSVDB">23985</ref>
      <ref url="http://secunia.com/advisories/19295" source="SECUNIA">19295</ref>
      <ref url="http://osvdb.org/ref/23/23985-libvc.txt" source="MISC">http://osvdb.org/ref/23/23985-libvc.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_hsu" name="libvc">
        <vers num="3" />
      </prod>
      <prod vendor="andrew_hsu" name="rolo">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1357" published="2006-03-21" name="CVE-2006-1357" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1036" source="VUPEN">ADV-2006-1036</ref>
      <ref url="http://www.securityfocus.com/bid/17175" source="BID">17175</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428318/100/0/threaded" source="BUGTRAQ">20060321 XSS in Firepass 4100 SSL VPN v.5.4.2 (and probably others)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25393" source="XF">firepass-mysupport-xss(25393)</ref>
      <ref url="http://securitytracker.com/id?1015798" source="SECTRACK">1015798</ref>
      <ref url="http://securityreason.com/securityalert/611" source="SREASON">611</ref>
      <ref url="http://secunia.com/advisories/19337" source="SECUNIA">19337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass_4100">
        <vers num="5.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1358" published="2006-03-21" name="CVE-2006-1358" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19308" source="SECUNIA" patch="1" adv="1">19308</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/182" source="BEA" patch="1" adv="1">BEA06-122.00</ref>
      <ref url="ftp://ftpna.beasys.com/pub/releases/security/patch_CR259534_81SP5.zip" source="MISC" patch="1">ftp://ftpna.beasys.com/pub/releases/security/patch_CR259534_81SP5.zip</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1022" source="VUPEN">ADV-2006-1022</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25345" source="XF">weblogic-portal-portlet-disclosure(25345)</ref>
      <ref url="http://www.securityfocus.com/bid/17164" source="BID">17164</ref>
      <ref url="http://securitytracker.com/id?1015791" source="SECTRACK">1015791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1359" published="2006-03-22" name="CVE-2006-1359" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/876678" source="CERT-VN">VU#876678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25379" source="XF">ie-createtextrange-command-execution(25379)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1050" source="VUPEN">ADV-2006-1050</ref>
      <ref url="http://www.securityfocus.com/bid/17196" source="BID">17196</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429124/30/6120/threaded" source="BUGTRAQ">20060328 Determina Fix for CVE-2006-1359 (Zero Day MS Internet Explorer Remote "CreateTextRange()" Code Execution)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429088/100/0/threaded" source="BUGTRAQ">20060328 EEYE: Temporary workaround for IE createTextRange vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428600/100/0/threaded" source="BUGTRAQ">20060323 Secunia Research: Microsoft Internet Explorer "createTextRange()"Code Execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428583/100/0/threaded" source="BUGTRAQ">20060322 Microsoft Internet Explorer (mshtml.dll) - Remote Code Execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/428441" source="BUGTRAQ">20060322 IE crash</ref>
      <ref url="http://www.osvdb.org/24050" source="OSVDB">24050</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS">MS06-013</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/917077.mspx" source="CONFIRM">http://www.microsoft.com/technet/security/advisory/917077.mspx</ref>
      <ref url="http://www.computerterrorism.com/research/ct22-03-2006" source="MISC" adv="1">http://www.computerterrorism.com/research/ct22-03-2006</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-154.shtml" source="CIAC">Q-154</ref>
      <ref url="http://securitytracker.com/id?1015812" source="SECTRACK">1015812</ref>
      <ref url="http://secunia.com/secunia_research/2006-7/advisory/" source="MISC">http://secunia.com/secunia_research/2006-7/advisory/</ref>
      <ref url="http://secunia.com/advisories/18680" source="SECUNIA" adv="1">18680</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1662.html" source="FULLDISC">20060327 Determina Fix for the IE createTextRange() bug</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1434.html" source="FULLDISC">20060322 FW: [Full-disclosure] IE crash</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1430.html" source="FULLDISC">20060322 Microsoft Internet Explorer (mshtml.dll) - Remote Code Execution</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1427.html" source="FULLDISC">20060322 IE crash</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:985" source="OVAL" sig="1">oval:org.mitre.oval:def:985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1702" source="OVAL" sig="1">oval:org.mitre.oval:def:1702</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1678" source="OVAL" sig="1">oval:org.mitre.oval:def:1678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1657" source="OVAL" sig="1">oval:org.mitre.oval:def:1657</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1178" source="OVAL" sig="1">oval:org.mitre.oval:def:1178</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="7.0" edition="beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1360" published="2006-03-23" name="CVE-2006-1360" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/27926" source="XF">musicbox-multiple-sql-injection(27926)</ref>
      <ref url="http://www.securityfocus.com/bid/17149" source="BID">17149</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded" source="BUGTRAQ">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428972/100/0/threaded" source="BUGTRAQ">20060324 XSS &amp; SQL Injection in Music Box v2.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicbox" name="musicbox">
        <vers num="2.3_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1361" published="2006-03-23" name="CVE-2006-1361" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the username field to (1) list.rhtml or (2) show.rhtml.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
OSWiki, OSWiki, 0.3.1</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19290" source="SECUNIA" patch="1" adv="1">19290</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25410" source="XF">oswiki-username-xss(25410)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1035" source="VUPEN">ADV-2006-1035</ref>
      <ref url="http://www.securityfocus.com/bid/17189" source="BID">17189</ref>
      <ref url="http://svn.sourceforge.net/viewcvs.cgi/opensourcewiki/branches/0.3/oswiki/app/views/user/list.rhtml?view=log" source="CONFIRM">http://svn.sourceforge.net/viewcvs.cgi/opensourcewiki/branches/0.3/oswiki/app/views/user/list.rhtml?view=log</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oswiki" name="oswiki">
        <vers prev="1" num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1362" published="2006-03-23" name="CVE-2006-1362" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Mini-Nuke CMS System 1.8.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter in (a) members.asp, the (2) catid parameter in (b) articles.asp and (c) programs.asp, and the (3) id parameter in (d) hpages.asp and (e) forum.asp.  NOTE: The pages.asp/id vector is already covered by CVE-2006-0870.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428361/100/0/threaded" source="BUGTRAQ" adv="1">20060321 Mini-Nuke&lt;=1.8.2 SQL injection (6)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25372" source="XF">mininuke-multiple-sql-injection(25372)</ref>
      <ref url="http://securityreason.com/securityalert/617" source="SREASON">617</ref>
      <ref url="http://secunia.com/advisories/18439" source="SECUNIA">18439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-nuke" name="mini-nuke_cms">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1363" published="2006-03-23" name="CVE-2006-1363" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .php file into the /upload directory as specified in the dirPath parameter, then performing a direct request to that file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1038" source="VUPEN">ADV-2006-1038</ref>
      <ref url="http://www.milw0rm.com/exploits/1600" source="MILW0RM">1600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25377" source="XF">freewps-images-file-include(25377)</ref>
      <ref url="http://secunia.com/advisories/19343" source="SECUNIA">19343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justin_white" name="freewps">
        <vers num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1364" published="2006-03-23" name="CVE-2006-1364" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17188" source="BID">17188</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.html" source="MISC">http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.html</ref>
      <ref url="http://www.milw0rm.com/exploits/1601" source="MILW0RM">1601</ref>
      <ref url="http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zip" source="MISC">http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zip</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25392" source="XF">ms-aspnet-w3wp-dos(25392)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428622/100/0/threaded" source="BUGTRAQ">20060322 w3wp remote DoS</ref>
      <ref url="http://securitytracker.com/id?1015825" source="SECTRACK">1015825</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044292.html" source="FULLDISC">20060322 w3wp remote DoS</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044291.html" source="FULLDISC">20060322 w3wp remote DoS due to improper reference of STA COM components in ASP.NET</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp2" />
        <vers num="1.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1365" published="2006-03-23" name="CVE-2006-1365" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the target device, by initiating and interrupting an OBEX Push Profile that pretends to send a vCard, aka a "HeloMoto" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428431/100/0/threaded" source="BUGTRAQ">20060321 DMA[2006-0321a] - 'Motorola P2K Platform setpath() overflow and Blueline attack'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2006-0321a].txt</ref>
      <ref url="http://trifinite.org/trifinite_stuff_helomoto.html" source="MISC">http://trifinite.org/trifinite_stuff_helomoto.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="e398">
        <vers num="" />
      </prod>
      <prod vendor="motorola" name="pebl_u6">
        <vers num="08.83.76r" />
      </prod>
      <prod vendor="motorola" name="v600">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1366" published="2006-03-23" name="CVE-2006-1366" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in the Motorola PEBL U6 08.83.76R, and possibly other Motorola P2K-based phones, allows remote attackers to cause a denial of service (device shutdown), and possibly execute arbitrary code, via a long OBEX setpath to the OBEX File Transfer (aka FTP) service on Bluetooth channel 9.</descript>
    </desc>
    <sols>
      <sol source="nvd">Arbitrary code execution may also be possible, but has not been confirmed.  This vulnerability may affect other versions of Motorola P2K-based phones.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1045" source="VUPEN">ADV-2006-1045</ref>
      <ref url="http://www.securityfocus.com/bid/17185" source="BID">17185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428431/100/0/threaded" source="BUGTRAQ" adv="1">20060321 DMA[2006-0321a] - 'Motorola P2K Platform setpath() overflow and Blueline attack'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2006-0321a].txt</ref>
      <ref url="http://secunia.com/advisories/19319" source="SECUNIA" adv="1">19319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25401" source="XF">motorola-peblu6-v600-obex-bo(25401)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044287.html" source="FULLDISC">20060321 DMA[2006-0321a] - 'Motorola P2K Platform setpath() overflow and Blueline attack'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="pebl_u6">
        <vers num="u6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1367" published="2006-03-23" name="CVE-2006-1367" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and view phonebook entries and saved SMS messages by connecting on Bluetooth channel 3 and tricking the user into pressing Grant, aka a "Blueline" attack.  NOTE: while user-assisted, the attack is made more feasible because of a GUI misrepresentation issue that allows a default message to be replaced by an attacker-specified one.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25402" source="XF">motorola-peblu6-v600-name-spoofing(25402)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1045" source="VUPEN" adv="1">ADV-2006-1045</ref>
      <ref url="http://www.securityfocus.com/bid/17190" source="BID">17190</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428431/100/0/threaded" source="BUGTRAQ">20060321 DMA[2006-0321a] - 'Motorola P2K Platform setpath() overflow and Blueline attack'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2006-0321a].txt</ref>
      <ref url="http://secunia.com/advisories/19319" source="SECUNIA" adv="1">19319</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044287.html" source="FULLDISC">20060321 DMA[2006-0321a] - 'Motorola P2K Platform setpath() overflow and Blueline attack'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="pebl_u6">
        <vers num="u6_08.83.76r" />
      </prod>
      <prod vendor="motorola" name="v600">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1368" published="2006-03-23" name="CVE-2006-1368" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (kmalloc'd memory corruption) via a remote NDIS response to OID_GEN_SUPPORTED_LIST, which causes memory to be allocated for the reply data but not the reply structure.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 2.6.16.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1046" source="VUPEN">ADV-2006-1046</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.securityfocus.com/bid/17831" source="BID">17831</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8763716bfe4d8a16bef28c9947cf9d799b1796a5" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8763716bfe4d8a16bef28c9947cf9d799b1796a5</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA" adv="1">21045</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA" adv="1">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA" adv="1">19955</ref>
      <ref url="http://secunia.com/advisories/19330" source="SECUNIA" adv="1">19330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1369" published="2006-03-23" name="CVE-2006-1369" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 2.1.5 (2006-03-08 or later).</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1044" source="VUPEN">ADV-2006-1044</ref>
      <ref url="http://www.securityfocus.com/bid/17187" source="BID">17187</ref>
      <ref url="http://secunia.com/advisories/19299" source="SECUNIA" adv="1">19299</ref>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=209178" source="CONFIRM">http://forums.invisionpower.com/index.php?showtopic=209178</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25384" source="XF">invision-privatemessage-xss(25384)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.1" />
        <vers num="2.1.5" />
        <vers num="2.1_alpha2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1370" published="2006-03-23" name="CVE-2006-1370" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of RealNetworks, RealPlayer from 10.5 v6.0.12.1040 through 10.5 v6.0.12.1348.  </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/451556" source="CERT-VN">VU#451556</ref>
      <ref url="http://www.service.real.com/realplayer/security/03162006_player/en/" source="CONFIRM" patch="1">http://www.service.real.com/realplayer/security/03162006_player/en/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25411" source="XF">realnetworks-mbc-bo(25411)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1057" source="VUPEN">ADV-2006-1057</ref>
      <ref url="http://www.securityfocus.com/bid/17202" source="BID">17202</ref>
      <ref url="http://securitytracker.com/id?1015810" source="SECTRACK">1015810</ref>
      <ref url="http://secunia.com/advisories/19358" source="SECUNIA" adv="1">19358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" edition=":enterprise" />
        <vers num="10.0" />
        <vers num="10.5_6.0.12.1040" />
        <vers num="10.5_6.0.12.1053" />
        <vers num="10.5_6.0.12.1056" />
        <vers num="10.5_6.0.12.1059" />
        <vers num="10.5_6.0.12.1069" />
        <vers num="10.5_6.0.12.1235" />
        <vers num="10.5_6.0.12.1348" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1371" published="2006-03-23" name="CVE-2006-1371" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19353" source="SECUNIA" patch="1" adv="1">19353</ref>
      <ref url="http://xhp.targetit.ro/index.php?page=3&amp;box_id=34&amp;action=show_single_entry&amp;post_id=10" source="CONFIRM">http://xhp.targetit.ro/index.php?page=3&amp;box_id=34&amp;action=show_single_entry&amp;post_id=10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25399" source="XF">xhpcms-filemanager-file-upload(25399)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25399" source="XF">xhpcms-filemanager-file-upload(25399)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1052" source="VUPEN" adv="1">ADV-2006-1052</ref>
      <ref url="http://www.securityfocus.com/bid/17209" source="BID">17209</ref>
      <ref url="http://www.osvdb.org/24059" source="OSVDB">24059</ref>
      <ref url="http://www.osvdb.org/24058" source="OSVDB">24058</ref>
      <ref url="http://www.milw0rm.com/exploits/1605" source="MILW0RM">1605</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000649.html" source="VIM">20060324 XHP vendor ack/fix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xhp" name="cms">
        <vers prev="1" num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1372" published="2006-03-23" name="CVE-2006-1372" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1040" source="VUPEN">ADV-2006-1040</ref>
      <ref url="http://secunia.com/advisories/19329" source="SECUNIA">19329</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25373" source="XF">1webcalendar-multiple-sql-injection(25373)</ref>
      <ref url="http://www.securityfocus.com/bid/17193" source="BID">17193</ref>
      <ref url="http://www.osvdb.org/24023" source="OSVDB">24023</ref>
      <ref url="http://www.osvdb.org/24022" source="OSVDB">24022</ref>
      <ref url="http://www.osvdb.org/24021" source="OSVDB">24021</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="benson_it_solutions" name="1webcalendar">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1373" published="2006-03-23" name="CVE-2006-1373" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1054" source="VUPEN">ADV-2006-1054</ref>
      <ref url="http://www.securityfocus.com/bid/17184" source="BID">17184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428452/100/0/threaded" source="BUGTRAQ" adv="1">20060322 PHP Live! XSS status_image.php</ref>
      <ref url="http://secunia.com/advisories/19340" source="SECUNIA" adv="1">19340</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25386" source="XF">phplive-statusimage-xss(25386)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_live" name="php_live">
        <vers num="2.8.1" />
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1374" published="2006-03-23" name="CVE-2006-1374" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1071" source="VUPEN">ADV-2006-1071</ref>
      <ref url="http://secunia.com/advisories/19351" source="SECUNIA" adv="1">19351</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25403" source="XF">adman-viewstatement-sql-injection(25403)</ref>
      <ref url="http://www.securityfocus.com/bid/17208" source="BID">17208</ref>
      <ref url="http://www.osvdb.org/24064" source="OSVDB">24064</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/adman-v10x-sql-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/adman-v10x-sql-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brain_book_software" name="adman">
        <vers prev="1" num="1.0.20051221" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1375" published="2006-03-23" name="CVE-2006-1375" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1071" source="VUPEN">ADV-2006-1071</ref>
      <ref url="http://secunia.com/advisories/19351" source="SECUNIA" adv="1">19351</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25404" source="XF">adman-multiple-path-disclosure(25404)</ref>
      <ref url="http://www.osvdb.org/24066" source="OSVDB">24066</ref>
      <ref url="http://www.osvdb.org/24065" source="OSVDB">24065</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/adman-v10x-sql-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/adman-v10x-sql-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brain_book_software" name="adman">
        <vers prev="1" num="1.0.20051221" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1376" published="2006-03-23" name="CVE-2006-1376" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service (disk consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19331" source="SECUNIA" adv="1">19331</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358210" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358210</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25526" source="XF">debian-cdebconf-world-writable(25526)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1377" published="2006-03-23" name="CVE-2006-1377" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1087" source="VUPEN">ADV-2006-1087</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1086" source="VUPEN">ADV-2006-1086</ref>
      <ref url="http://www.securityfocus.com/bid/17201" source="BID">17201</ref>
      <ref url="http://www.securityfocus.com/bid/17199" source="BID">17199</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428553/100/0/threaded" source="BUGTRAQ" adv="1">20060323 [KAPDA::#37] - CoMoblog XSS</ref>
      <ref url="http://www.kapda.ir/advisory-301.html" source="MISC" adv="1">http://www.kapda.ir/advisory-301.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25420" source="XF">easymoblog-img-xss(25420)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25416" source="XF">comoblog-img-xss(25416)</ref>
      <ref url="http://www.osvdb.org/24094" source="OSVDB">24094</ref>
      <ref url="http://www.osvdb.org/24093" source="OSVDB">24093</ref>
      <ref url="http://securitytracker.com/id?1015824" source="SECTRACK">1015824</ref>
      <ref url="http://secunia.com/advisories/19379" source="SECUNIA">19379</ref>
      <ref url="http://secunia.com/advisories/19370" source="SECUNIA">19370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easymoblog" name="easymoblog">
        <vers num="0.5.1" />
      </prod>
      <prod vendor="php" name="comoblog">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1378" published="2006-03-23" name="CVE-2006-1378" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability exists only in Windows OS environments before XP.  For some reason it would not let me notate that in the "vulnerable software" section.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25429" source="XF">passwordsafe-key-brute-force(25429)</ref>
      <ref url="http://www.securityfocus.com/bid/17200" source="BID">17200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428552/100/0/threaded" source="BUGTRAQ" adv="1">20060323 PasswordSafe 3.0 weak random number generator allows key recovery attack</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/445509/100/0/threaded" source="BUGTRAQ">20060907 Re: PasswordSafe 3.0 weak random number generator allows key recovery attack</ref>
      <ref url="http://securityreason.com/securityalert/618" source="SREASON">618</ref>
    </refs>
    <vuln_soft>
      <prod vendor="counterpane" name="password_safe">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1379" published="2006-03-24" name="CVE-2006-1379" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Trend Micro PC-cillin Internet Security 2006 14.00.1485 and 14.10.0.1023, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying executable programs such as (1) tmntsrv.exe and (2) tmproxy.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19282" source="SECUNIA" patch="1" adv="1">19282</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1042" source="VUPEN">ADV-2006-1042</ref>
      <ref url="http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english" source="MISC" adv="1">http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="pc-cillin_2006">
        <vers num="14.00.1485" />
        <vers prev="1" num="14.10.0.1023" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1380" published="2006-03-24" name="CVE-2006-1380" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19022" source="SECUNIA" patch="1" adv="1">19022</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1041" source="VUPEN">ADV-2006-1041</ref>
      <ref url="http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english" source="MISC">http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25415" source="XF">imss-isntsmtp-directory-permissions(25415)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_messaging_security_suite">
        <vers prev="1" num="5.5_build_1183" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1381" published="2006-03-24" name="CVE-2006-1381" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1041" source="VUPEN">ADV-2006-1041</ref>
      <ref url="http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english" source="MISC">http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english</ref>
      <ref url="http://secunia.com/advisories/11576" source="SECUNIA" adv="1">11576</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25415" source="XF">imss-isntsmtp-directory-permissions(25415)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="officescan">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1382" published="2006-03-24" name="CVE-2006-1382" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1056" source="VUPEN">ADV-2006-1056</ref>
      <ref url="http://secunia.com/advisories/19352" source="SECUNIA" adv="1">19352</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044318.html" source="FULLDISC">20060323 XOR Crew :: vBulletin ImpEx &lt;= 1.74 - Remote Command Execution Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34095" source="XF">impex-systempath-file-include(34095)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25391" source="XF">impex-impexdata-file-include(25391)</ref>
      <ref url="http://www.securityfocus.com/bid/17206" source="BID">17206</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467666/100/0/threaded" source="BUGTRAQ">20070504 Remote File Include In Script impex</ref>
      <ref url="http://www.osvdb.org/24070" source="OSVDB">24070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="impex">
        <vers prev="1" num="1.74" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1383" published="2006-03-24" name="CVE-2006-1383" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1069" source="VUPEN">ADV-2006-1069</ref>
      <ref url="http://www.securityfocus.com/bid/17205" source="BID">17205</ref>
      <ref url="http://www.osvdb.org/24057" source="OSVDB">24057</ref>
      <ref url="http://secunia.com/advisories/19338" source="SECUNIA" adv="1">19338</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25413" source="XF">baby-ftp-information-disclosure(25413)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablo_software_solutions" name="baby_ftp_server">
        <vers num="1.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1384" published="2006-03-24" name="CVE-2006-1384" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1OA14904" source="AIXAPAR" patch="1">OA14904</ref>
      <ref url="http://secunia.com/advisories/19332" source="SECUNIA" patch="1" adv="1">19332</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1073" source="VUPEN">ADV-2006-1073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25412" source="XF">tivoli-bsm-skin-xss(25412)</ref>
      <ref url="http://www.securityfocus.com/bid/17210" source="BID">17210</ref>
      <ref url="http://www.osvdb.org/24069" source="OSVDB">24069</ref>
      <ref url="http://securitytracker.com/id?1015822" source="SECTRACK">1015822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_business_systems_manager">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1385" published="2006-03-24" name="CVE-2006-1385" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version R73p.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25422" source="XF">kismac-80211-parsing-bo(25422)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1070" source="VUPEN">ADV-2006-1070</ref>
      <ref url="http://www.securityfocus.com/bid/17198" source="BID">17198</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428537/100/0/threaded" source="BUGTRAQ">20060323 Advisory 03/2006: KisMAC Cisco Vendor Tag Encapsulated SSID Overflow</ref>
      <ref url="http://www.hardened-php.net/advisory_032006.115.html" source="MISC">http://www.hardened-php.net/advisory_032006.115.html</ref>
      <ref url="http://secunia.com/advisories/19354" source="SECUNIA" adv="1">19354</ref>
      <ref url="http://kismac.de/_trac/changeset/113" source="CONFIRM">http://kismac.de/_trac/changeset/113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25422" source="XF">kismac-80211-parsing-bo(25422)</ref>
      <ref url="http://www.osvdb.org/24072" source="OSVDB">24072</ref>
      <ref url="http://securityreason.com/securityalert/609" source="SREASON">609</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044323.html" source="FULLDISC">20060323 Advisory 03/2006: KisMAC Cisco Vendor Tag Encapsulated SSID Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kismac" name="kismac">
        <vers num="0.10a" />
        <vers num="0.11a" />
        <vers num="0.12a" />
        <vers num="0.1a" />
        <vers num="0.1b" />
        <vers num="0.1c" />
        <vers num="0.2a" />
        <vers num="0.5d" />
        <vers num="0.5d4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1386" published="2006-03-26" name="CVE-2006-1386" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1116" source="VUPEN">ADV-2006-1116</ref>
      <ref url="http://twiki.org/cgi-bin/view/Codev/SecurityAlertTWiki4RdiffPreviewAccess" source="CONFIRM">http://twiki.org/cgi-bin/view/Codev/SecurityAlertTWiki4RdiffPreviewAccess</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25444" source="XF">twiki-restricted-content-access(25444)</ref>
      <ref url="http://www.securityfocus.com/bid/17268" source="BID">17268</ref>
      <ref url="http://securitytracker.com/id?1015843" source="SECTRACK">1015843</ref>
      <ref url="http://secunia.com/advisories/19410" source="SECUNIA">19410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="twiki">
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1387" published="2006-03-26" name="CVE-2006-1387" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1116" source="VUPEN">ADV-2006-1116</ref>
      <ref url="http://twiki.org/cgi-bin/view/Codev/SecurityAdvisoryDosAttackWithInclude" source="CONFIRM">http://twiki.org/cgi-bin/view/Codev/SecurityAdvisoryDosAttackWithInclude</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25445" source="XF">twiki-include-edit-dos(25445)</ref>
      <ref url="http://www.securityfocus.com/bid/17267" source="BID">17267</ref>
      <ref url="http://secunia.com/advisories/19410" source="SECUNIA">19410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="twiki">
        <vers num="2001-09-01" />
        <vers num="2001-12-01" />
        <vers num="2003-02-01" />
        <vers num="2004-09-01" />
        <vers num="2004-09-02" />
        <vers num="2004-09-03" />
        <vers num="2004-09-04" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1388" published="2006-03-24" name="CVE-2006-1388" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/434641" source="CERT-VN">VU#434641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25394" source="XF">ie-hta-file-execution(25394)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1318" source="VUPEN">ADV-2006-1318</ref>
      <ref url="http://www.securityfocus.com/bid/17181" source="BID">17181</ref>
      <ref url="http://securitytracker.com/id?1015800" source="SECTRACK">1015800</ref>
      <ref url="http://news.zdnet.com/2100-1009_22-6052396.html?tag=zdfd.newsfeed" source="MISC">http://news.zdnet.com/2100-1009_22-6052396.html?tag=zdfd.newsfeed</ref>
      <ref url="http://jeffrey.vanderstad.net/grasshopper/" source="MISC">http://jeffrey.vanderstad.net/grasshopper/</ref>
      <ref url="http://www.osvdb.org/24095" source="OSVDB">24095</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx" source="MS">MS06-013</ref>
      <ref url="http://secunia.com/advisories/19378" source="SECUNIA">19378</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1415.html" source="FULLDISC">20060321 IE .hta vulnerability reported</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1774" source="OVAL" sig="1">oval:org.mitre.oval:def:1774</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1724" source="OVAL" sig="1">oval:org.mitre.oval:def:1724</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1676" source="OVAL" sig="1">oval:org.mitre.oval:def:1676</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1642" source="OVAL" sig="1">oval:org.mitre.oval:def:1642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1591" source="OVAL" sig="1">oval:org.mitre.oval:def:1591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1389" published="2006-03-24" name="CVE-2006-1389" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00622788" source="HP" patch="1">HPSBUX02105</ref>
      <ref url="http://www.securityfocus.com/bid/17215" source="BID" patch="1">17215</ref>
      <ref url="http://securitytracker.com/id?1015819" source="SECTRACK" patch="1">1015819</ref>
      <ref url="http://secunia.com/advisories/19373" source="SECUNIA" patch="1" adv="1">19373</ref>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00622788" source="HP">SSRT061134</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1089" source="VUPEN">ADV-2006-1089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25421" source="XF">hpux-swagentd-dos(25421)</ref>
      <ref url="http://www.osvdb.org/24097" source="OSVDB">24097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-076.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-076.htm</ref>
      <ref url="http://secunia.com/advisories/19395" source="SECUNIA">19395</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:616" source="OVAL" sig="1">oval:org.mitre.oval:def:616</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:312" source="OVAL" sig="1">oval:org.mitre.oval:def:312</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1031" source="OVAL" sig="1">oval:org.mitre.oval:def:1031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1390" published="2006-03-24" name="CVE-2006-1390" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability applies only to the following games/versions: 
1) NetHack 3.4.3-r1 and previous 
2) Falcon's Eye 1.9.4a and previous 
3) Slash'EM 0.0.760 and previous</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-23.xml" source="GENTOO" patch="1">GLSA-200603-23</ref>
      <ref url="http://www.securityfocus.com/bid/17217" source="BID">17217</ref>
      <ref url="http://secunia.com/advisories/19376" source="SECUNIA" adv="1">19376</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=127319" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=127319</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=127167" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=127167</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=125902" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=125902</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=122376" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=122376</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25528" source="XF">gentoo-multiple-games-privilege-escalation(25528)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428743/100/0/threaded" source="BUGTRAQ">20060324 Re: [ GLSA 200603-23 ] NetHack, Slash'EM, Falcon's Eye: Local privilege escalation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428739/100/0/threaded" source="BUGTRAQ">20060324 Re: [ GLSA 200603-23 ] NetHack, Slash'EM, Falcon's Eye: Localprivilege escalation</ref>
      <ref url="http://www.osvdb.org/24104" source="OSVDB">24104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1391" published="2006-03-24" name="CVE-2006-1391" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17222" source="BID" patch="1">17222</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428667/100/0/threaded" source="BUGTRAQ" patch="1">20060324 Secunia Research: Quick 'n Easy/Baby Web Server ASP CodeDisclosure Vulnerability</ref>
      <ref url="http://www.osvdb.org/24100" source="OSVDB" patch="1">24100</ref>
      <ref url="http://secunia.com/secunia_research/2006-19/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-19/advisory/</ref>
      <ref url="http://secunia.com/advisories/19306" source="SECUNIA" patch="1" adv="1">19306</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1088" source="VUPEN">ADV-2006-1088</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1085" source="VUPEN">ADV-2006-1085</ref>
      <ref url="http://secunia.com/advisories/19312" source="SECUNIA" adv="1">19312</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25418" source="XF">quickneasy-web-asp-disclosure(25418)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25417" source="XF">baby-web-asp-disclosure(25417)</ref>
      <ref url="http://www.osvdb.org/24099" source="OSVDB">24099</ref>
      <ref url="http://securityreason.com/securityalert/624" source="SREASON">624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablo_software_solutions" name="baby_asp_web_server">
        <vers num="2.7.2" />
      </prod>
      <prod vendor="pablo_software_solutions" name="quick_and_easy_web_server">
        <vers num="3.0.6" />
        <vers num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1392" published="2006-03-26" name="CVE-2006-1392" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337585" source="CERT-VN" patch="1" adv="1">VU#337585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25427" source="XF" patch="1">pubcookie-login-server-xss(25427)</ref>
      <ref url="http://secunia.com/advisories/19348" source="SECUNIA" patch="1" adv="1">19348</ref>
      <ref url="http://pubcookie.org/news/20060306-login-secadv.html" source="CONFIRM" patch="1" adv="1">http://pubcookie.org/news/20060306-login-secadv.html</ref>
      <ref url="http://www.securityfocus.com/bid/17221" source="BID">17221</ref>
      <ref url="http://www.osvdb.org/24521" source="OSVDB">24521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pubcookie">
        <vers num="3.0.0" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.1a" />
        <vers num="3.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1393" published="2006-03-26" name="CVE-2006-1393" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/314540" source="CERT-VN" patch="1" adv="1">VU#314540</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25426" source="XF" patch="1">pubcookie-appserver-module-xss(25426)</ref>
      <ref url="http://secunia.com/advisories/19348" source="SECUNIA" patch="1" adv="1">19348</ref>
      <ref url="http://pubcookie.org/news/20060306-apps-secadv.html" source="CONFIRM" patch="1" adv="1">http://pubcookie.org/news/20060306-apps-secadv.html</ref>
      <ref url="http://www.securityfocus.com/bid/17221" source="BID">17221</ref>
      <ref url="http://www.osvdb.org/24103" source="OSVDB">24103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pubcookie">
        <vers num="3.0.0" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.1a" />
        <vers num="3.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1394" published="2006-03-26" name="CVE-2006-1394" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/314540" source="CERT-VN" patch="1" adv="1">VU#314540</ref>
      <ref url="http://pubcookie.org/news/20060306-apps-secadv.html" source="CONFIRM" patch="1" adv="1">http://pubcookie.org/news/20060306-apps-secadv.html</ref>
      <ref url="http://www.securityfocus.com/bid/17221" source="BID">17221</ref>
      <ref url="http://www.osvdb.org/24520" source="OSVDB">24520</ref>
      <ref url="http://secunia.com/advisories/19348" source="SECUNIA">19348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pubcookie">
        <vers num="3.0.0" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.1a" />
        <vers num="3.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1395" published="2006-03-26" name="CVE-2006-1395" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1153" source="VUPEN">ADV-2006-1153</ref>
      <ref url="http://www.securityfocus.com/bid/17224" source="BID">17224</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25520" source="XF">cholod-mb-sql-injection(25520)</ref>
      <ref url="http://secunia.com/advisories/19439" source="SECUNIA">19439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cholod" name="mysql_based_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1396" published="2006-03-26" name="CVE-2006-1396" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1153" source="VUPEN">ADV-2006-1153</ref>
      <ref url="http://www.securityfocus.com/bid/17223" source="BID">17223</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25518" source="XF">cholod-mb-xss(25518)</ref>
      <ref url="http://secunia.com/advisories/19439" source="SECUNIA">19439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cholod" name="mysql_based_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1397" published="2006-03-28" name="CVE-2006-1397" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17251" source="BID" patch="1">17251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428898/100/0/threaded" source="BUGTRAQ" patch="1">20060327 [PHPADSNEW-SA-2006-001] phpAdsNew and phpPgAds 2.0.8 fix multiple vulnerabilities</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=404964" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=404964</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=404963" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=404963</ref>
      <ref url="http://securitytracker.com/id?1015829" source="SECTRACK" patch="1">1015829</ref>
      <ref url="http://securitytracker.com/id?1015828" source="SECTRACK" patch="1">1015828</ref>
      <ref url="http://secunia.com/advisories/19384" source="SECUNIA" patch="1" adv="1">19384</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1107" source="VUPEN">ADV-2006-1107</ref>
      <ref url="http://phpadsnew.com/two/nucleus/index.php?itemid=46" source="CONFIRM">http://phpadsnew.com/two/nucleus/index.php?itemid=46</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25458" source="XF">phpadsnew-login-banner-xss(25458)</ref>
      <ref url="http://www.osvdb.org/24206" source="OSVDB">24206</ref>
      <ref url="http://www.osvdb.org/24205" source="OSVDB">24205</ref>
      <ref url="http://securityreason.com/securityalert/633" source="SREASON">633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpadsnew" name="phpadsnew">
        <vers num="2.0" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.7" />
        <vers num="2_dev_2001-10-09" />
      </prod>
      <prod vendor="phppgads" name="phppgads">
        <vers num="2.0.4" />
        <vers num="2.0.4_pr2" />
        <vers num="2.0.5" />
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1398" published="2006-03-28" name="CVE-2006-1398" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book 1.0 allows remote attackers to inject arbitrary web script or HTML via the g_message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1100" source="VUPEN">ADV-2006-1100</ref>
      <ref url="http://www.securityfocus.com/bid/17253" source="BID">17253</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428900/100/0/threaded" source="BUGTRAQ">20060327 HYSA-2006-006 G-Book 1.0 XSS And Other Vulnerabilities</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-006-g-book.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-006-g-book.txt</ref>
      <ref url="http://secunia.com/advisories/19414" source="SECUNIA" adv="1">19414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25475" source="XF">gbook-guestbook-xss(25475)</ref>
      <ref url="http://www.osvdb.org/24141" source="OSVDB">24141</ref>
      <ref url="http://securitytracker.com/id?1015830" source="SECTRACK">1015830</ref>
      <ref url="http://securityreason.com/securityalert/634" source="SREASON">634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sixal" name="g-book">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1399" published="2006-03-28" name="CVE-2006-1399" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25432" source="XF">meeting-reserve-searchresult-xss(25432)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1110" source="VUPEN">ADV-2006-1110</ref>
      <ref url="http://www.securityfocus.com/bid/17256" source="BID">17256</ref>
      <ref url="http://secunia.com/advisories/19372" source="SECUNIA" adv="1">19372</ref>
      <ref url="http://www.osvdb.org/24162" source="OSVDB">24162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_lite" name="meeting_reserve">
        <vers num="1.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1400" published="2006-03-28" name="CVE-2006-1400" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Task parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1112" source="VUPEN">ADV-2006-1112</ref>
      <ref url="http://www.securityfocus.com/bid/17234" source="BID">17234</ref>
      <ref url="http://secunia.com/advisories/19385" source="SECUNIA" adv="1">19385</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25490" source="XF">metisware-instructor-personaltaskcreate-xss(25490)</ref>
      <ref url="http://www.osvdb.org/24139" source="OSVDB">24139</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/metisware-instructor-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/metisware-instructor-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metisware" name="instructor">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1401" published="2006-03-28" name="CVE-2006-1401" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1109" source="VUPEN">ADV-2006-1109</ref>
      <ref url="http://www.securityfocus.com/bid/17240" source="BID">17240</ref>
      <ref url="http://secunia.com/advisories/19393" source="SECUNIA" adv="1">19393</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25467" source="XF">calendarexpress-search-xss(25467)</ref>
      <ref url="http://www.osvdb.org/24161" source="OSVDB">24161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_lite" name="calendar_express">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1402" published="2006-03-28" name="CVE-2006-1402" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute arbitrary code via a long string sent when joining a match or a long chat message to the SV_BroadcastPrintf function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17248" source="BID" patch="1">17248</ref>
      <ref url="http://aluigi.altervista.org/adv/csdoombof-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/csdoombof-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1105" source="VUPEN">ADV-2006-1105</ref>
      <ref url="http://voxelsoft.com/csdoom/" source="CONFIRM">http://voxelsoft.com/csdoom/</ref>
      <ref url="http://secunia.com/advisories/19389" source="SECUNIA" adv="1">19389</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25449" source="XF">csdoom-sv-setupuserinfo-bo(25449)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25448" source="XF">csdoom-sv-broadcastprintf-bo(25448)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="csdoom" name="csdoom">
        <vers num="2005_0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1403" published="2006-03-28" name="CVE-2006-1403" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Format string vulnerability in the PrintString function in c_console.cpp in client/server Doom (csDoom) 0.7 and earlier allows remote attackers cause a denial of service and possibly execute arbitrary commands via format string specifiers in strings passed to the console.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17248" source="BID" patch="1">17248</ref>
      <ref url="http://voxelsoft.com/csdoom/" source="CONFIRM" patch="1">http://voxelsoft.com/csdoom/</ref>
      <ref url="http://secunia.com/advisories/19389" source="SECUNIA" patch="1" adv="1">19389</ref>
      <ref url="http://aluigi.altervista.org/adv/csdoombof-adv.txt" source="MISC" patch="1">http://aluigi.altervista.org/adv/csdoombof-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1105" source="VUPEN">ADV-2006-1105</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25450" source="XF">csdoom-printf-format-string(25450)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="csdoom" name="csdoom_2005">
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1404" published="2006-03-28" name="CVE-2006-1404" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file or (2) function parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1111" source="VUPEN">ADV-2006-1111</ref>
      <ref url="http://secunia.com/advisories/19387" source="SECUNIA" adv="1">19387</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25488" source="XF">blankol-bol-xss(25488)</ref>
      <ref url="http://www.securityfocus.com/bid/17265" source="BID">17265</ref>
      <ref url="http://www.osvdb.org/24124" source="OSVDB">24124</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/blankol-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/blankol-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="industrial_imagination" name="blankol">
        <vers prev="1" num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1405" published="2006-03-28" name="CVE-2006-1405" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.aspx in SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25452" source="XF">sscms-search-xss(25452)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1097" source="VUPEN">ADV-2006-1097</ref>
      <ref url="http://www.securityfocus.com/bid/17254" source="BID">17254</ref>
      <ref url="http://www.osvdb.org/24120" source="OSVDB">24120</ref>
      <ref url="http://secunia.com/advisories/19399" source="SECUNIA" adv="1">19399</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/sweetsuitenet-sscms-21x-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/sweetsuitenet-sscms-21x-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sheer_vision_technologies" name="sscms">
        <vers prev="1" num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1406" published="2006-03-28" name="CVE-2006-1406" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1101" source="VUPEN">ADV-2006-1101</ref>
      <ref url="http://www.securityfocus.com/bid/17245" source="BID">17245</ref>
      <ref url="http://www.osvdb.org/24123" source="OSVDB">24123</ref>
      <ref url="http://secunia.com/advisories/19397" source="SECUNIA" adv="1">19397</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25433" source="XF">uniforum-wbadmlog-xss(25433)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/uniforum-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/uniforum-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uniforum" name="uniforum">
        <vers prev="1" num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1407" published="2006-03-28" name="CVE-2006-1407" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.</descript>
    </desc>
    <sols>
      <sol source="nvd">These issues are reportedly fixed by the vendor. Version 3.2.10-stable will contain these fixes when it is released. Contact the vendor for further information on obtaining fixes.</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1093" source="VUPEN">ADV-2006-1093</ref>
      <ref url="http://www.securityfocus.com/bid/17263" source="BID">17263</ref>
      <ref url="http://secunia.com/advisories/19375" source="SECUNIA" adv="1">19375</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/30309" source="XF">helm-domainsusersdefaault-xss(30309)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25470" source="XF">helm-domainsdefault-xss(25470)</ref>
      <ref url="http://www.osvdb.org/24126" source="OSVDB">24126</ref>
      <ref url="http://www.osvdb.org/24125" source="OSVDB">24125</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html" source="MISC">http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000654.html" source="VIM">20060327 Helm Control Panel followup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webhost_automation" name="helm_web_hosting_control_panel">
        <vers prev="1" num="3.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1408" published="2006-03-28" name="CVE-2006-1408" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1104" source="VUPEN">ADV-2006-1104</ref>
      <ref url="http://www.securityfocus.com/bid/17261" source="BID">17261</ref>
      <ref url="http://secunia.com/advisories/19388" source="SECUNIA" adv="1">19388</ref>
      <ref url="http://aluigi.altervista.org/adv/vaboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/vaboom-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25454" source="XF">vavoom-fionread-dos(25454)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vavoom" name="vavoom">
        <vers num="1.1" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.2" />
        <vers num="1.12" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.3" />
        <vers num="1.15_beta_1" />
        <vers num="1.16" />
        <vers num="1.16.1" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.19.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4_beta" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5_beta" />
        <vers num="1.6" />
        <vers num="1.666" />
        <vers num="1.666_beta_1" />
        <vers num="1.666_beta_2" />
        <vers num="1.7" />
        <vers num="1.7_beta_1" />
        <vers num="1.7_beta_2" />
        <vers num="1.7_beta_3" />
        <vers num="1.7_beta_4" />
        <vers num="1.7_beta_5" />
        <vers num="1.8" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1409" published="2006-03-28" name="CVE-2006-1409" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1104" source="VUPEN">ADV-2006-1104</ref>
      <ref url="http://www.securityfocus.com/bid/17261" source="BID">17261</ref>
      <ref url="http://secunia.com/advisories/19388" source="SECUNIA" adv="1">19388</ref>
      <ref url="http://aluigi.altervista.org/adv/vaboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/vaboom-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25455" source="XF">vavoom-comprlength-bo(25455)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vavoom" name="vavoom">
        <vers num="1.1" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.2" />
        <vers num="1.12" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.3" />
        <vers num="1.15_beta_1" />
        <vers num="1.16" />
        <vers num="1.16.1" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.19.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4_beta" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5_beta" />
        <vers num="1.6" />
        <vers num="1.666" />
        <vers num="1.666_beta_1" />
        <vers num="1.666_beta_2" />
        <vers num="1.7" />
        <vers num="1.7_beta_1" />
        <vers num="1.7_beta_2" />
        <vers num="1.7_beta_3" />
        <vers num="1.7_beta_4" />
        <vers num="1.7_beta_5" />
        <vers num="1.8" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1410" published="2006-03-28" name="CVE-2006-1410" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1099" source="VUPEN">ADV-2006-1099</ref>
      <ref url="http://www.securityfocus.com/bid/17258" source="BID">17258</ref>
      <ref url="http://secunia.com/advisories/19415" source="SECUNIA" adv="1">19415</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25434" source="XF">absolutelivesupport-register-xss(25434)</ref>
      <ref url="http://www.osvdb.org/24131" source="OSVDB">24131</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xigla" name="absolute_live_support_xe">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1411" published="2006-03-28" name="CVE-2006-1411" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1103" source="VUPEN">ADV-2006-1103</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25466" source="XF">absolute-gallery-xss(25466)</ref>
      <ref url="http://www.securityfocus.com/bid/18712" source="BID">18712</ref>
      <ref url="http://www.osvdb.org/24214" source="OSVDB">24214</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/absolute-image-gallery-xe-20-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/absolute-image-gallery-xe-20-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xigla" name="absolute_image_gallery_xe">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1412" published="2006-03-28" name="CVE-2006-1412" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1115" source="VUPEN">ADV-2006-1115</ref>
      <ref url="http://secunia.com/advisories/19411" source="SECUNIA" adv="1">19411</ref>
      <ref url="http://milw0rm.com/exploits/1611" source="MILW0RM">1611</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25465" source="XF">tftgallery-passwd-disclosure(25465)</ref>
      <ref url="http://www.securityfocus.com/bid/17250" source="BID">17250</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/453485/100/0/threaded" source="BUGTRAQ">20061204 Re: Multiple bugs in TFT-Gallery</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/453471/100/0/threaded" source="BUGTRAQ">20061204 Multiple bugs in TFT-Gallery</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tft_gallery" name="tft_gallery">
        <vers num="0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1413" published="2006-03-28" name="CVE-2006-1413" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1094" source="VUPEN">ADV-2006-1094</ref>
      <ref url="http://www.securityfocus.com/bid/17236" source="BID">17236</ref>
      <ref url="http://www.osvdb.org/24136" source="OSVDB">24136</ref>
      <ref url="http://www.osvdb.org/24135" source="OSVDB">24135</ref>
      <ref url="http://www.osvdb.org/24134" source="OSVDB">24134</ref>
      <ref url="http://www.osvdb.org/24133" source="OSVDB">24133</ref>
      <ref url="http://www.osvdb.org/24132" source="OSVDB">24132</ref>
      <ref url="http://secunia.com/advisories/19386" source="SECUNIA" adv="1">19386</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25468" source="XF">ezhomepagepro-multiple-xss(25468)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/ezhomepagepro-multiple-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/ezhomepagepro-multiple-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htmljunction" name="ezhomepagepro">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1414" published="2006-03-28" name="CVE-2006-1414" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1092" source="VUPEN">ADV-2006-1092</ref>
      <ref url="http://www.securityfocus.com/bid/17249" source="BID">17249</ref>
      <ref url="http://www.osvdb.org/24119" source="OSVDB" adv="1">24119</ref>
      <ref url="http://secunia.com/advisories/19401" source="SECUNIA" adv="1">19401</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25440" source="XF">toastforums-toast-xss(25440)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/xss-in-toast-forums-16.html" source="MISC">http://pridels0.blogspot.com/2006/03/xss-in-toast-forums-16.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toast_forums" name="toast_forums">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1415" published="2006-03-28" name="CVE-2006-1415" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1098" source="VUPEN">ADV-2006-1098</ref>
      <ref url="http://www.securityfocus.com/bid/17246" source="BID">17246</ref>
      <ref url="http://www.osvdb.org/24122" source="OSVDB">24122</ref>
      <ref url="http://secunia.com/advisories/19398" source="SECUNIA" adv="1">19398</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25462" source="XF">dotnetbb-iforget-xss(25462)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/xss-vuln-in-dotnetbb-v24.html" source="MISC">http://pridels0.blogspot.com/2006/03/xss-vuln-in-dotnetbb-v24.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotnetbb" name="dotnetbb_forums">
        <vers prev="1" num="2.42ec_sp_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1416" published="2006-03-28" name="CVE-2006-1416" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1096" source="VUPEN">ADV-2006-1096</ref>
      <ref url="http://secunia.com/advisories/19396" source="SECUNIA" adv="1">19396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25463" source="XF">absolutefaqmanager-search-xss(25463)</ref>
      <ref url="http://www.securityfocus.com/bid/17242" source="BID">17242</ref>
      <ref url="http://www.osvdb.org/24127" source="OSVDB">24127</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/absolute-faq-manager-net-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/absolute-faq-manager-net-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xigla" name="absolute_faq_manager_.net">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1417" published="2006-03-28" name="CVE-2006-1417" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25431" source="XF">webquiz-multiple-xss(25431)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1091" source="VUPEN" adv="1">ADV-2006-1091</ref>
      <ref url="http://www.securityfocus.com/bid/17255" source="BID">17255</ref>
      <ref url="http://www.osvdb.org/24130" source="OSVDB">24130</ref>
      <ref url="http://www.osvdb.org/24129" source="OSVDB">24129</ref>
      <ref url="http://secunia.com/advisories/19416" source="SECUNIA" adv="1">19416</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/web-quiz-pro-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/web-quiz-pro-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caloris_planitia_technologies" name="web_quiz_pro">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1418" published="2006-03-28" name="CVE-2006-1418" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">A new version of School Management System was released on May 28, 2006.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25469" source="XF">eschoolmanagementsystem-default-xss(25469)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1095" source="VUPEN">ADV-2006-1095</ref>
      <ref url="http://www.securityfocus.com/bid/17257" source="BID">17257</ref>
      <ref url="http://www.osvdb.org/24128" source="OSVDB">24128</ref>
      <ref url="http://secunia.com/advisories/19381" source="SECUNIA" adv="1">19381</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/e-school-management-system-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/e-school-management-system-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caloris_planitia_technologies" name="e-school_management_system">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1419" published="2006-03-28" name="CVE-2006-1419" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1134" source="VUPEN">ADV-2006-1134</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428895/100/0/threaded" source="BUGTRAQ" adv="1">20060326 nuked-klan&lt;=1.7.5 SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25446" source="XF">nuked-klan-calendar-sql-injection(25446)</ref>
      <ref url="http://www.securityfocus.com/bid/17233" source="BID">17233</ref>
      <ref url="http://www.osvdb.org/24204" source="OSVDB">24204</ref>
      <ref url="http://securityreason.com/securityalert/632" source="SREASON">632</ref>
      <ref url="http://secunia.com/advisories/19382" source="SECUNIA">19382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers num="1.3_beta" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5_sp2" />
        <vers num="1.7" />
        <vers prev="1" num="1.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1420" published="2006-03-28" name="CVE-2006-1420" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17239" source="BID">17239</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428891/100/0/threaded" source="BUGTRAQ" adv="1">20060325 SQL Injection in SaphpLesson2.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25453" source="XF">saphplesson-print-sql-injection(25453)</ref>
      <ref url="http://www.osvdb.org/24254" source="OSVDB">24254</ref>
      <ref url="http://securityreason.com/securityalert/629" source="SREASON">629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arabless" name="saphplesson">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1421" published="2006-03-28" name="CVE-2006-1421" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.</descript>
      <descript source="nvd">In order to exploit this vulnerability, the 'magic_quotes_gpc' parameter must be disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17241" source="BID" patch="1">17241</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428893/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060326 AkoComment SQL injection vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25451" source="XF">akocomment-akocomment-sql-injection(25451)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1136" source="VUPEN">ADV-2006-1136</ref>
      <ref url="http://secunia.com/advisories/19392" source="SECUNIA" adv="1">19392</ref>
      <ref url="http://www.osvdb.org/24209" source="OSVDB">24209</ref>
      <ref url="http://securityreason.com/securityalert/631" source="SREASON">631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arthur_konze_webdesign" name="akocomment">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1422" published="2006-03-28" name="CVE-2006-1422" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17230" source="BID">17230</ref>
      <ref url="http://www.milw0rm.com/exploits/1610" source="MILW0RM">1610</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25580" source="XF">phpbookingcal-detailsview-sql-injection(25580)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jjwwebdesign" name="phpbookingcalendar">
        <vers prev="1" num="1.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1423" published="2006-03-28" name="CVE-2006-1423" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428833/100/0/threaded" source="BUGTRAQ" adv="1">20060325 UBBThreads&lt;=5.5.1+6.0.2+6.0 br5+6.0.1 SQL injection</ref>
      <ref url="http://securityreason.com/securityalert/628" source="SREASON">628</ref>
    </refs>
  </entry>
  <entry type="CVE" seq="2006-1424" reject="1" published="2006-03-28" name="CVE-2006-1424" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1482.  Reason: This candidate is a duplicate of CVE-2006-1482.  Notes: All CVE users should reference CVE-2006-1482 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1425" published="2006-03-28" name="CVE-2006-1425" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1130" source="VUPEN">ADV-2006-1130</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428901/100/0/threaded" source="BUGTRAQ" adv="1">20060327 HYSA-2006-007 phpmyfamily 1.4.1 CRLF injection &amp; XSS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114344921211241&amp;w=2" source="FULLDISC">20060327 HYSA-2006-007 phpmyfamily 1.4.1 CRLF injection &amp; XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25476" source="XF">phpmyfamily-track-xss(25476)</ref>
      <ref url="http://www.securityfocus.com/bid/17278" source="BID">17278</ref>
      <ref url="http://www.osvdb.org/24166" source="OSVDB">24166</ref>
      <ref url="http://securityreason.com/securityalert/636" source="SREASON">636</ref>
      <ref url="http://secunia.com/advisories/19409" source="SECUNIA">19409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyfamily" name="phpmyfamily">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1426" published="2006-03-28" name="CVE-2006-1426" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1135" source="VUPEN">ADV-2006-1135</ref>
      <ref url="http://www.securityfocus.com/bid/17260" source="BID">17260</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428964/100/0/threaded" source="BUGTRAQ">20060327 Blog Pixel Motion&lt;=1.xx Authentication Bypass Vulnerability &amp; SQL injection</ref>
      <ref url="http://secunia.com/advisories/19421" source="SECUNIA" adv="1">19421</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25481" source="XF">pixelmotionblog-index-sql-injection(25481)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25478" source="XF">pixelmotionblog-adminindex-security-bypass(25478)</ref>
      <ref url="http://www.osvdb.org/24169" source="OSVDB">24169</ref>
      <ref url="http://www.osvdb.org/24168" source="OSVDB">24168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixel_motion" name="pixel_motion_blog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1427" published="2006-03-28" name="CVE-2006-1427" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter in cgi-bin/index.cgi, or (10) vsSD parameter in /mods/calendar/index.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1102" source="VUPEN">ADV-2006-1102</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25435" source="XF">webapp-index-xss(25435)</ref>
      <ref url="http://www.web-app.net/cgi-bin/index.cgi?action=redirectd&amp;cat=pastversions&amp;id=1" source="CONFIRM">http://www.web-app.net/cgi-bin/index.cgi?action=redirectd&amp;cat=pastversions&amp;id=1</ref>
      <ref url="http://www.web-app.net/cgi-bin/index.cgi?action=downloadinfo&amp;cat=pastversions&amp;id=1" source="CONFIRM">http://www.web-app.net/cgi-bin/index.cgi?action=downloadinfo&amp;cat=pastversions&amp;id=1</ref>
      <ref url="http://www.securityfocus.com/bid/17359" source="BID">17359</ref>
      <ref url="http://www.osvdb.org/24279" source="OSVDB">24279</ref>
      <ref url="http://www.osvdb.org/24278" source="OSVDB">24278</ref>
      <ref url="http://secunia.com/advisories/19506" source="SECUNIA">19506</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/webapp-multiple-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/webapp-multiple-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1428" published="2006-03-28" name="CVE-2006-1428" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1129" source="VUPEN">ADV-2006-1129</ref>
      <ref url="http://secunia.com/advisories/19419" source="SECUNIA" adv="1">19419</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25492" source="XF">phpcoin-multiple-xss(25492)</ref>
      <ref url="http://www.securityfocus.com/bid/17279" source="BID">17279</ref>
      <ref url="http://www.osvdb.org/24189" source="OSVDB">24189</ref>
      <ref url="http://www.osvdb.org/24188" source="OSVDB">24188</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/phpcoin-v122-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/phpcoin-v122-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coinsoft_technologies" name="phpcoin">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1429" published="2006-03-28" name="CVE-2006-1429" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1132" source="VUPEN">ADV-2006-1132</ref>
      <ref url="http://www.securityfocus.com/bid/17273" source="BID">17273</ref>
      <ref url="http://secunia.com/advisories/19427" source="SECUNIA" adv="1">19427</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25494" source="XF">classifiedzone-accountlogon-xss(25494)</ref>
      <ref url="http://www.osvdb.org/24187" source="OSVDB">24187</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/classifiedzone-v12-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/classifiedzone-v12-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusionzone" name="classifiedzone">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1430" published="2006-03-28" name="CVE-2006-1430" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1131" source="VUPEN">ADV-2006-1131</ref>
      <ref url="http://www.securityfocus.com/bid/17282" source="BID">17282</ref>
      <ref url="http://www.osvdb.org/24176" source="OSVDB">24176</ref>
      <ref url="http://www.osvdb.org/24175" source="OSVDB">24175</ref>
      <ref url="http://www.osvdb.org/24174" source="OSVDB">24174</ref>
      <ref url="http://www.osvdb.org/24173" source="OSVDB">24173</ref>
      <ref url="http://secunia.com/advisories/19432" source="SECUNIA" adv="1">19432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25491" source="XF">controlzshms-multiple-scripts-xss(25491)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/controlzx-hms-hosting-management.html" source="MISC">http://pridels0.blogspot.com/2006/03/controlzx-hms-hosting-management.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="controlzx" name="hms">
        <vers prev="1" num="3.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1431" published="2006-03-28" name="CVE-2006-1431" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1127" source="VUPEN">ADV-2006-1127</ref>
      <ref url="http://www.securityfocus.com/bid/17272" source="BID">17272</ref>
      <ref url="http://secunia.com/advisories/19430" source="SECUNIA" adv="1">19430</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25484" source="XF">couponzone-local-xss(25484)</ref>
      <ref url="http://www.osvdb.org/24180" source="OSVDB">24180</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusionzone" name="couponzone">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1432" published="2006-03-28" name="CVE-2006-1432" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fusionZONE couponZONE 4.2 allows remote attackers to obtain the full path of the web server, and other sensitive information, via invalid values, as demonstrated using manipulations associated with SQL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25486" source="XF">couponzone-local-path-disclosure(25486)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusionzone" name="couponzone">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1433" published="2006-04-03" name="CVE-2006-1433" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24302" source="OSVDB">24302</ref>
      <ref url="http://osvdb.org/ref/24/24302-annuaire_directory.txt" source="MISC">http://osvdb.org/ref/24/24302-annuaire_directory.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25668" source="XF">annuaire-includelangen-path-disclosure(25668)</ref>
      <ref url="http://secunia.com/advisories/19548" source="SECUNIA">19548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="annuaire" name="directory">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1434" published="2006-04-03" name="CVE-2006-1434" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24303" source="OSVDB">24303</ref>
      <ref url="http://osvdb.org/ref/24/24302-annuaire_directory.txt" source="MISC">http://osvdb.org/ref/24/24302-annuaire_directory.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25669" source="XF">annuaire-inscription-xss(25669)</ref>
      <ref url="http://www.securityfocus.com/bid/17393" source="BID">17393</ref>
      <ref url="http://secunia.com/advisories/19548" source="SECUNIA">19548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="annuaire" name="directory">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1435" published="2006-04-03" name="CVE-2006-1435" modified="2008-09-05" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24255" source="OSVDB">24255</ref>
      <ref url="http://osvdb.org/ref/24/24255-aria.txt" source="MISC">http://osvdb.org/ref/24/24255-aria.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25688" source="XF">aria-genmessage-xss(25688)</ref>
      <ref url="http://www.securityfocus.com/bid/17411" source="BID">17411</ref>
      <ref url="http://secunia.com/advisories/19551" source="SECUNIA">19551</ref>
    </refs>
    <vuln_soft>
      <prod vendor="accounting_receiving_and_inventory_administration" name="aria">
        <vers num="0.99-6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1436" published="2006-04-15" name="CVE-2006-1436" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24236" source="OSVDB">24236</ref>
      <ref url="http://www.osvdb.org/24235" source="OSVDB">24235</ref>
      <ref url="http://osvdb.org/ref/24/24236-upoint.txt" source="MISC">http://osvdb.org/ref/24/24236-upoint.txt</ref>
      <ref url="http://www.securityfocus.com/bid/17646" source="BID">17646</ref>
      <ref url="http://secunia.com/advisories/19727" source="SECUNIA">19727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upoint" name="at1_event_publisher">
        <vers num="2003-12-18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1437" published="2006-04-15" name="CVE-2006-1437" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24237" source="OSVDB">24237</ref>
      <ref url="http://osvdb.org/ref/24/24236-upoint.txt" source="MISC">http://osvdb.org/ref/24/24236-upoint.txt</ref>
      <ref url="http://www.securityfocus.com/bid/17647" source="BID">17647</ref>
      <ref url="http://secunia.com/advisories/19727" source="SECUNIA">19727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upoint" name="at1_event_publisher">
        <vers num="2003-12-18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1438" published="2006-04-03" name="CVE-2006-1438" modified="2008-09-05" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword_list parameter to (a) index.php; (2) title, (3) article, (4) author, and (5) keywords parameters to (b) submit_article.php; and (6) Question, (7) Name, and (8) Email parameters to (c) submit_question.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24312" source="OSVDB">24312</ref>
      <ref url="http://www.osvdb.org/24311" source="OSVDB">24311</ref>
      <ref url="http://www.osvdb.org/24310" source="OSVDB">24310</ref>
      <ref url="http://osvdb.org/ref/24/24310-aphpkb.txt" source="MISC">http://osvdb.org/ref/24/24310-aphpkb.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25666" source="XF">aphpkb-multiple-scripts-xss(25666)</ref>
      <ref url="http://www.securityfocus.com/bid/17377" source="BID">17377</ref>
      <ref url="http://secunia.com/advisories/19554" source="SECUNIA">19554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andy_grayndler" name="andys_php_knowledgebase">
        <vers num="0.57" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1439" published="2006-05-12" name="CVE-2006-1439" modified="2011-08-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26404" source="XF">macos-appkit-nssecuretext-weak-security(26404)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25583" source="OSVDB">25583</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" adv="1">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1440" published="2006-05-12" name="CVE-2006-1440" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26405" source="XF">macos-bom-archive-file-overwrite(26405)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25584" source="OSVDB">25584</ref>
      <ref url="http://securitytracker.com/id?1016082" source="SECTRACK">1016082</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1441" published="2006-05-12" name="CVE-2006-1441" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26406" source="XF">macos-cfnetwork-chunked-overlow(26406)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25585" source="OSVDB">25585</ref>
      <ref url="http://securitytracker.com/id?1016082" source="SECTRACK">1016082</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1442" published="2006-05-12" name="CVE-2006-1442" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26407" source="XF">macos-corefoundation-bundle-code-execution(26407)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25586" source="OSVDB">25586</ref>
      <ref url="http://securitytracker.com/id?1016080" source="SECTRACK">1016080</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1443" published="2006-05-12" name="CVE-2006-1443" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26408" source="XF">macos-corefoundation-integer-underflow(26408)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25587" source="OSVDB">25587</ref>
      <ref url="http://securitytracker.com/id?1016080" source="SECTRACK">1016080</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1444" published="2006-05-12" name="CVE-2006-1444" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Event Services.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "Enable access for assistive devices" is on.
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26409" source="XF">macos-coregraphics-quartz-security-bypass(26409)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25588" source="OSVDB">25588</ref>
      <ref url="http://securitytracker.com/id?1016079" source="SECTRACK">1016079</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1445" published="2006-05-12" name="CVE-2006-1445" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server path name handling."</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26411" source="XF">macos-ftpserver-code-execution(26411)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25589" source="OSVDB">25589</ref>
      <ref url="http://securitytracker.com/id?1016084" source="SECTRACK">1016084</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1446" published="2006-05-12" name="CVE-2006-1446" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference after the Keychain has been locked.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26413" source="XF">macos-keychain-security-bypass(26413)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25590" source="OSVDB">25590</ref>
      <ref url="http://securitytracker.com/id?1016072" source="SECTRACK">1016072</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1447" published="2006-05-12" name="CVE-2006-1447" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26416" source="XF">macos-launchservices-security-bypass(26416)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25591" source="OSVDB">25591</ref>
      <ref url="http://securitytracker.com/id?1016081" source="SECTRACK">1016081</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1448" published="2006-05-12" name="CVE-2006-1448" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25592" source="OSVDB">25592</ref>
      <ref url="http://securitytracker.com/id?1016082" source="SECTRACK">1016082</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26410" source="XF">macos-finder-url-type-spoofing(26410)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1449" published="2006-05-12" name="CVE-2006-1449" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26417" source="XF">macos-mail-macmime-bo(26417)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25593" source="OSVDB">25593</ref>
      <ref url="http://securitytracker.com/id?1016078" source="SECTRACK">1016078</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1450" published="2006-05-12" name="CVE-2006-1450" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initialize arbitrary classes.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26419" source="XF">macos-mail-color-code-execution(26419)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25594" source="OSVDB">25594</ref>
      <ref url="http://securitytracker.com/id?1016078" source="SECTRACK">1016078</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1451" published="2006-05-12" name="CVE-2006-1451" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26420" source="XF">macos-mysql-manager-blank-password(26420)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25595" source="OSVDB">25595</ref>
      <ref url="http://securitytracker.com/id?1016077" source="SECTRACK">1016077</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1452" published="2006-05-12" name="CVE-2006-1452" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26422" source="XF">macos-preview-directory-bo(26422)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25596" source="OSVDB">25596</ref>
      <ref url="http://securitytracker.com/id?1016076" source="SECTRACK">1016076</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1453" published="2006-05-12" name="CVE-2006-1453" modified="2011-08-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID" patch="1">17951</ref>
      <ref url="http://securitytracker.com/id?1016075" source="SECTRACK" patch="1">1016075</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26400" source="XF">quicktime-pict-font-bo(26400)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" adv="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.2.0" />
        <vers num="6.3.0" />
        <vers num="6.4.0" />
        <vers num="6.5" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers prev="1" num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1454" published="2006-05-12" name="CVE-2006-1454" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID" patch="1">17951</ref>
      <ref url="http://securitytracker.com/id?1016075" source="SECTRACK" patch="1">1016075</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26401" source="XF">quicktime-pict-image-bo(26401)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" adv="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1455" published="2006-05-12" name="CVE-2006-1455" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26423" source="XF">quicktime-missing-track-dos(26423)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25599" source="OSVDB">25599</ref>
      <ref url="http://securitytracker.com/id?1016070" source="SECTRACK">1016070</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1456" published="2006-05-12" name="CVE-2006-1456" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26424" source="XF">quicktime-rtsp-bo(26424)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25600" source="OSVDB">25600</ref>
      <ref url="http://securitytracker.com/id?1016070" source="SECTRACK">1016070</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1457" published="2006-05-12" name="CVE-2006-1457" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/519473" source="CERT-VN">VU#519473</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26427" source="XF">safari-archive-code-execution(26427)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/25598" source="OSVDB">25598</ref>
      <ref url="http://securitytracker.com/id?1016069" source="SECTRACK">1016069</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1458" published="2006-05-12" name="CVE-2006-1458" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime Player before 7.1 allows remote attackers to execute arbitrary code via a crafted JPEG image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/289705" source="CERT-VN" patch="1">VU#289705</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26391" source="XF">quicktime-jpeg-overflow(26391)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1459" published="2006-05-12" name="CVE-2006-1459" modified="2011-09-09" discovered="2006-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" patch="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26392" source="XF">quicktime-mov-overflow(26392)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers prev="1" num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1460" published="2006-05-12" name="CVE-2006-1460" modified="2011-09-20" discovered="2006-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" patch="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26393" source="XF">quicktime-mov-bo(26393)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433810/100/0/threaded" source="BUGTRAQ">20060512 Apple QuickTime udta ATOM Heap Overflow</ref>
      <ref url="http://secway.org/advisory/AD20060512.txt" source="MISC" adv="1">http://secway.org/advisory/AD20060512.txt</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045987.html" source="FULLDISC">20060512 Apple QuickTime udta ATOM Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers prev="1" num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1461" published="2006-05-12" name="CVE-2006-1461" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" patch="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26394" source="XF">quicktime-flash-bo(26394)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers prev="1" num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1462" published="2006-05-12" name="CVE-2006-1462" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" patch="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26395" source="XF">quicktime-h264-overflow(26395)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers prev="1" num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1463" published="2006-05-12" name="CVE-2006-1463" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-015.html" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-06-015.html</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433828/100/0/threaded" source="BUGTRAQ" patch="1">20060511 ZDI-06-015: Apple QuickTime H.264 Parsing Heap Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26396" source="XF">quicktime-h264-bo(26396)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN" adv="1">ADV-2006-1778</ref>
      <ref url="http://securityreason.com/securityalert/888" source="SREASON">888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1464" published="2006-05-12" name="CVE-2006-1464" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/587937" source="CERT-VN">VU#587937</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" patch="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN">ADV-2006-1778</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26397" source="XF">quicktime-mpeg4-bo(26397)</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1465" published="2006-05-12" name="CVE-2006-1465" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html" source="CERT">TA06-132B</ref>
      <ref url="http://www.securityfocus.com/bid/17953" source="BID" patch="1">17953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded" source="BUGTRAQ" patch="1">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20069" source="SECUNIA" patch="1" adv="1">20069</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1778" source="VUPEN">ADV-2006-1778</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26399" source="XF">quicktime-avi-bo(26399)</ref>
      <ref url="http://securityreason.com/securityalert/887" source="SREASON">887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1466" published="2006-05-23" name="CVE-2006-1466" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1950" source="VUPEN">ADV-2006-1950</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26634" source="XF">xcode-webobjects-unauth-access(26634)</ref>
      <ref url="http://www.securityfocus.com/bid/18091" source="BID">18091</ref>
      <ref url="http://www.osvdb.org/25889" source="OSVDB">25889</ref>
      <ref url="http://securitytracker.com/id?1016143" source="SECTRACK">1016143</ref>
      <ref url="http://secunia.com/advisories/20267" source="SECUNIA">20267</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00004.html" source="APPLE">APPLE-SA-2006-05-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="xcode">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1467" published="2006-06-29" name="CVE-2006-1467" modified="2011-03-07" discovered="2006-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/907836" source="CERT-VN" patch="1">VU#907836</ref>
      <ref url="http://secunia.com/advisories/20891" source="SECUNIA" patch="1" adv="1">20891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303952" source="APPLE" patch="1">APPLE-SA-2006-06-29</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27481" source="XF">itunes-aac-file-overflow(27481)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-020.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-020.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2601" source="VUPEN" adv="1">ADV-2006-2601</ref>
      <ref url="http://www.securityfocus.com/bid/18730" source="BID">18730</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438812/100/0/threaded" source="BUGTRAQ">20060630 ZDI-06-020: Apple iTunes AAC File Parsing Integer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1016413" source="SECTRACK">1016413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers prev="1" num="6.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1468" published="2006-06-27" name="CVE-2006-1468" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.7</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html" source="APPLE" patch="1">APPLE-SA-2006-06-27</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27477" source="XF">macosx-afp-information-disclosure(27477)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2566" source="VUPEN" adv="1">ADV-2006-2566</ref>
      <ref url="http://www.securityfocus.com/bid/18733" source="BID">18733</ref>
      <ref url="http://www.securityfocus.com/bid/18686" source="BID">18686</ref>
      <ref url="http://www.osvdb.org/26930" source="OSVDB">26930</ref>
      <ref url="http://securitytracker.com/id?1016395" source="SECTRACK">1016395</ref>
      <ref url="http://secunia.com/advisories/20877" source="SECUNIA" adv="1">20877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1469" published="2006-06-27" name="CVE-2006-1469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/988356" source="CERT-VN">VU#988356</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27478" source="XF">macosx-imageio-tiff-bo(27478)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2566" source="VUPEN" adv="1">ADV-2006-2566</ref>
      <ref url="http://www.securityfocus.com/bid/18731" source="BID">18731</ref>
      <ref url="http://www.securityfocus.com/bid/18686" source="BID">18686</ref>
      <ref url="http://www.osvdb.org/26931" source="OSVDB">26931</ref>
      <ref url="http://securitytracker.com/id?1016394" source="SECTRACK">1016394</ref>
      <ref url="http://secunia.com/advisories/20877" source="SECUNIA" adv="1">20877</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html" source="APPLE">APPLE-SA-2006-06-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1470" published="2006-06-27" name="CVE-2006-1470" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/652196" source="CERT-VN">VU#652196</ref>
      <ref url="http://www.securityfocus.com/bid/18728" source="BID" patch="1">18728</ref>
      <ref url="http://www.securityfocus.com/bid/18686" source="BID" patch="1">18686</ref>
      <ref url="http://securitytracker.com/id?1016396" source="SECTRACK" patch="1">1016396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27480" source="XF">macosx-openldap-directory-dos(27480)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2566" source="VUPEN" adv="1">ADV-2006-2566</ref>
      <ref url="http://www.osvdb.org/26932" source="OSVDB">26932</ref>
      <ref url="http://secunia.com/advisories/20877" source="SECUNIA" adv="1">20877</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html" source="APPLE">APPLE-SA-2006-06-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1471" published="2006-06-27" name="CVE-2006-1471" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/27479" source="XF">macosx-launchd-format-string(27479)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2566" source="VUPEN" adv="1">ADV-2006-2566</ref>
      <ref url="http://www.securityfocus.com/bid/18724" source="BID">18724</ref>
      <ref url="http://www.securityfocus.com/bid/18686" source="BID">18686</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438699/100/0/threaded" source="BUGTRAQ">20060629 DMA[2006-0628a] - 'Apple OSX launchd unformatted syslog() vulnerability'</ref>
      <ref url="http://www.osvdb.org/26933" source="OSVDB">26933</ref>
      <ref url="http://securitytracker.com/id?1016397" source="SECTRACK">1016397</ref>
      <ref url="http://secunia.com/advisories/20877" source="SECUNIA" adv="1">20877</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html" source="APPLE">APPLE-SA-2006-06-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1472" published="2006-08-02" name="CVE-2006-1472" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determing names of unauthorized files and folders via unknown vectors related to the search results.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28134" source="XF">macosx-afp-file-disclosure(28134)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://securitytracker.com/id?1016620" source="SECTRACK">1016620</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1473" published="2006-08-02" name="CVE-2006-1473" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/575372" source="CERT-VN">VU#575372</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28135" source="XF">macosx-afp-overflow(28135)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.osvdb.org/27731" source="OSVDB">27731</ref>
      <ref url="http://securitytracker.com/id?1016620" source="SECTRACK">1016620</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1474" published="2006-03-28" name="CVE-2006-1474" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the "failed" functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428971/100/0/threaded" source="BUGTRAQ">20060324 [DDSi-SA] XSS in Raindance Communications Web Conferencing Pro</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raindance" name="web_conferencing_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1475" published="2006-03-28" name="CVE-2006-1475" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428970/100/0/threaded" source="BUGTRAQ">20060324 Microsoft Windows XP SP2 Firewall issue</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25597" source="XF">winxp-firewall-ads-bypass(25597)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429111/100/0/threaded" source="BUGTRAQ">20060327 Re: Microsoft Windows XP SP2 Firewall issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1476" published="2006-03-28" name="CVE-2006-1476" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429111/100/0/threaded" source="BUGTRAQ">20060327 Re: Microsoft Windows XP SP2 Firewall issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428970/100/0/threaded" source="BUGTRAQ">20060324 Microsoft Windows XP SP2 Firewall issue</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25598" source="XF">winxp-firewall-exe-bypass(25598)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1477" published="2006-03-28" name="CVE-2006-1477" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may affect all versions prior to 1.8  as well.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.turnkeywebtools.com/forum/showthread.php?p=10415" source="MISC" patch="1">http://www.turnkeywebtools.com/forum/showthread.php?p=10415</ref>
      <ref url="http://www.worlddefacers.de/Public/WD-TMPLH.txt" source="MISC">http://www.worlddefacers.de/Public/WD-TMPLH.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1137" source="VUPEN">ADV-2006-1137</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428976/100/0/threaded" source="BUGTRAQ" adv="1">20060327 PHPLiveHelper 1.8 remote command execution (include) Xploit (perl)</ref>
      <ref url="http://secunia.com/advisories/19428" source="SECUNIA" adv="1">19428</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25489" source="XF">phplivehelper-abspath-file-include(25489)</ref>
      <ref url="http://www.securityfocus.com/bid/18509" source="BID">18509</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437741/100/0/threaded" source="BUGTRAQ">20060619 Re: PHP Live Helper &lt;=([abs_path]) Remote File Include Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437648/100/0/threaded" source="BUGTRAQ">20060619 PHP Live Helper &lt;=([abs_path]) Remote File Include Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24199" source="OSVDB">24199</ref>
      <ref url="http://www.osvdb.org/24198" source="OSVDB">24198</ref>
      <ref url="http://www.osvdb.org/24197" source="OSVDB">24197</ref>
      <ref url="http://www.osvdb.org/24196" source="OSVDB">24196</ref>
      <ref url="http://www.osvdb.org/24195" source="OSVDB">24195</ref>
      <ref url="http://www.osvdb.org/24194" source="OSVDB">24194</ref>
      <ref url="http://www.osvdb.org/24193" source="OSVDB">24193</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turnkey_web_tools" name="php_live_helper">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1478" published="2006-03-28" name="CVE-2006-1478" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability may affect all other versions of Turnkey Web Tools, PHP Live Helper.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.turnkeywebtools.com/forum/showthread.php?p=10415" source="MISC" patch="1">http://www.turnkeywebtools.com/forum/showthread.php?p=10415</ref>
      <ref url="http://www.worlddefacers.de/Public/WD-TMPLH.txt" source="MISC">http://www.worlddefacers.de/Public/WD-TMPLH.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428976/100/0/threaded" source="BUGTRAQ" adv="1">20060327 PHPLiveHelper 1.8 remote command execution (include) Xploit (perl)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25489" source="XF">phplivehelper-abspath-file-include(25489)</ref>
      <ref url="http://securityreason.com/securityalert/641" source="SREASON">641</ref>
      <ref url="http://secunia.com/advisories/19428" source="SECUNIA">19428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turnkey_web_tools" name="php_live_helper">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1479" published="2006-03-28" name="CVE-2006-1479" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1203" source="VUPEN">ADV-2006-1203</ref>
      <ref url="http://www.osvdb.org/24158" source="OSVDB">24158</ref>
      <ref url="http://www.osvdb.org/24157" source="OSVDB">24157</ref>
      <ref url="http://www.osvdb.org/24156" source="OSVDB">24156</ref>
      <ref url="http://www.osvdb.org/24155" source="OSVDB">24155</ref>
      <ref url="http://www.osvdb.org/24154" source="OSVDB">24154</ref>
      <ref url="http://www.osvdb.org/24153" source="OSVDB">24153</ref>
      <ref url="http://www.osvdb.org/24152" source="OSVDB">24152</ref>
      <ref url="http://www.osvdb.org/24151" source="OSVDB">24151</ref>
      <ref url="http://www.osvdb.org/24150" source="OSVDB">24150</ref>
      <ref url="http://www.osvdb.org/24149" source="OSVDB">24149</ref>
      <ref url="http://osvdb.org/ref/24/24149-gtd-php.txt" source="MISC">http://osvdb.org/ref/24/24149-gtd-php.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25553" source="XF">gtdphp-multiple-scripts-xss(25553)</ref>
      <ref url="http://www.securityfocus.com/bid/17366" source="BID">17366</ref>
      <ref url="http://secunia.com/advisories/19512" source="SECUNIA">19512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serge_rey" name="gtd-php">
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1480" published="2006-03-28" name="CVE-2006-1480" modified="2011-03-07" discovered="2006-03-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1108" source="VUPEN">ADV-2006-1108</ref>
      <ref url="http://www.securityfocus.com/bid/17228" source="BID">17228</ref>
      <ref url="http://secunia.com/advisories/19400" source="SECUNIA" adv="1">19400</ref>
      <ref url="http://milw0rm.com/exploits/1608" source="MILW0RM">1608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25443" source="XF">webalbum-skin2-parameter-file-include(25443)</ref>
      <ref url="http://www.osvdb.org/24160" source="OSVDB">24160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duda" name="webalbum">
        <vers prev="1" num="2.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1481" published="2006-03-28" name="CVE-2006-1481" modified="2011-03-07" discovered="2006-03-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1106" source="VUPEN">ADV-2006-1106</ref>
      <ref url="http://www.securityfocus.com/bid/17229" source="BID">17229</ref>
      <ref url="http://secunia.com/advisories/19412" source="SECUNIA">19412</ref>
      <ref url="http://milw0rm.com/exploits/1609" source="MILW0RM">1609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25436" source="XF">phpticket-search-sql-injection(25436)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_ticket" name="php_ticket">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers prev="1" num="0.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1482" published="2006-03-28" name="CVE-2006-1482" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428899/100/0/threaded" source="BUGTRAQ">20060327 CanfTool v1.1 Cross Site Scripting Attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25437" source="XF">canftool-index-xss(25437)</ref>
      <ref url="http://www.securityfocus.com/bid/17231" source="BID">17231</ref>
      <ref url="http://www.osvdb.org/24264" source="OSVDB">24264</ref>
      <ref url="http://securityreason.com/securityalert/635" source="SREASON">635</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000664.html" source="VIM">20060328 Conftool, not Canftool; appears to be distributable</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conftool" name="conftool">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1483" published="2006-03-28" name="CVE-2006-1483" modified="2011-03-07" discovered="2006-03-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17270" source="BID" patch="1">17270</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429108/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060328 Secunia Research: Blazix Web Server JSP Source Code DisclosureVulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2006-22/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-22/advisory/</ref>
      <ref url="http://secunia.com/advisories/19341" source="SECUNIA" patch="1" adv="1">19341</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1133" source="VUPEN">ADV-2006-1133</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25485" source="XF">blazix-jsp-source-disclosure(25485)</ref>
      <ref url="http://www.osvdb.org/24178" source="OSVDB">24178</ref>
      <ref url="http://securitytracker.com/id?1015837" source="SECTRACK">1015837</ref>
      <ref url="http://securityreason.com/securityalert/643" source="SREASON">643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="desiderata_software" name="blazix_web_server">
        <vers prev="1" num="1.2.5" edition="" />
        <vers prev="1" num="1.2.5" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1484" published="2006-03-28" name="CVE-2006-1484" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Genius VideoCAM NB Driver does not drop privileges when saving files, which allows local users to gain privileges by opening arbitrary files via the "save as" dialog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25501" source="XF">genius-videocam-saveas-gain-privileges(25501)</ref>
      <ref url="http://www.securityfocus.com/bid/17284" source="BID">17284</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429107/100/0/threaded" source="BUGTRAQ" adv="1">20060328 Genius VideoCAM NB Local Privilege Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25501" source="XF">genius-videocam-saveas-gain-privileges(25501)</ref>
      <ref url="http://securitytracker.com/id?1015839" source="SECTRACK">1015839</ref>
      <ref url="http://secunia.com/advisories/19437" source="SECUNIA">19437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kye" name="genius_videocam_nb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1485" published="2006-03-28" name="CVE-2006-1485" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1138" source="VUPEN">ADV-2006-1138</ref>
      <ref url="http://www.securityfocus.com/bid/17271" source="BID">17271</ref>
      <ref url="http://secunia.com/advisories/19423" source="SECUNIA" adv="1">19423</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25496" source="XF">greymatter-gmupload-file-upload(25496)</ref>
      <ref url="http://www.osvdb.org/24210" source="OSVDB">24210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greymatter" name="greymatter">
        <vers num="1.1b" />
        <vers num="1.2" />
        <vers num="1.21" />
        <vers num="1.21a" />
        <vers num="1.21b" />
        <vers num="1.21c" />
        <vers num="1.21d" />
        <vers num="1.3" />
        <vers prev="1" num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1486" published="2006-03-28" name="CVE-2006-1486" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1128" source="VUPEN">ADV-2006-1128</ref>
      <ref url="http://www.securityfocus.com/bid/17277" source="BID">17277</ref>
      <ref url="http://secunia.com/advisories/19429" source="SECUNIA" adv="1">19429</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25487" source="XF">realestatezone-index-xss(25487)</ref>
      <ref url="http://www.osvdb.org/24186" source="OSVDB">24186</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusionzone" name="realestatezone">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1487" published="2006-03-28" name="CVE-2006-1487" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25495" source="XF">supporttrio-search-xss(25495)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1126" source="VUPEN">ADV-2006-1126</ref>
      <ref url="http://www.securityfocus.com/bid/17276" source="BID">17276</ref>
      <ref url="http://www.osvdb.org/24192" source="OSVDB">24192</ref>
      <ref url="http://secunia.com/advisories/19431" source="SECUNIA" adv="1">19431</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecampaign" name="supporttrio">
        <vers num="2.50.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1488" published="2006-03-28" name="CVE-2006-1488" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1126" source="VUPEN">ADV-2006-1126</ref>
      <ref url="http://secunia.com/advisories/19431" source="SECUNIA" adv="1">19431</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25517" source="XF">supporttrio-index-pdf-path-disclosure(25517)</ref>
      <ref url="http://www.osvdb.org/24191" source="OSVDB">24191</ref>
      <ref url="http://www.osvdb.org/24190" source="OSVDB">24190</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecampaign" name="supporttrio">
        <vers num="2.50.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1489" published="2006-03-29" name="CVE-2006-1489" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17274" source="BID">17274</ref>
      <ref url="http://www.osvdb.org/24179" source="OSVDB">24179</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25576" source="XF">couponzone-local-sql-injection(25576)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusionzone" name="couponzone">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1490" published="2006-03-29" name="CVE-2006-1490" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue.  NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html" source="CERT">TA06-333A</ref>
      <ref url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?r1=1.112&amp;r2=1.113" source="MISC" patch="1">http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?r1=1.112&amp;r2=1.113</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4750" source="VUPEN">ADV-2006-4750</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2685" source="VUPEN">ADV-2006-2685</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1149" source="VUPEN">ADV-2006-1149</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429164/100/0/threaded" source="BUGTRAQ">20060328 Critical PHP bug - act ASAP if you are running web with sensitive data</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429162/100/0/threaded" source="BUGTRAQ">20060328 Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11084" source="OVAL">oval:org.mitre.oval:def:11084</ref>
      <ref url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?view=log" source="MISC">http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?view=log</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=127939" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=127939</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25508" source="XF">php-htmlentitydecode-information-disclosure(25508)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-320-1" source="UBUNTU">USN-320-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0020" source="TRUSTIX">2006-0020</ref>
      <ref url="http://www.securityfocus.com/bid/17296" source="BID">17296</ref>
      <ref url="http://www.novell.com/linux/security/advisories/05-05-2006.html" source="SUSE">SUSE-SA:2006:024</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:063" source="MANDRIVA">MDKSA-2006:063</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200605-08.xml" source="GENTOO">GLSA-200605-08</ref>
      <ref url="http://secunia.com/advisories/23155" source="SECUNIA">23155</ref>
      <ref url="http://secunia.com/advisories/21125" source="SECUNIA">21125</ref>
      <ref url="http://secunia.com/advisories/20951" source="SECUNIA">20951</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20052" source="SECUNIA">20052</ref>
      <ref url="http://secunia.com/advisories/19979" source="SECUNIA">19979</ref>
      <ref url="http://secunia.com/advisories/19832" source="SECUNIA">19832</ref>
      <ref url="http://secunia.com/advisories/19570" source="SECUNIA">19570</ref>
      <ref url="http://secunia.com/advisories/19499" source="SECUNIA">19499</ref>
      <ref url="http://secunia.com/advisories/19383" source="SECUNIA">19383</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0276.html" source="REDHAT">RHSA-2006:0276</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html" source="APPLE">APPLE-SA-2006-11-28</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=304829" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=304829</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1491" published="2006-03-29" name="CVE-2006-1491" modified="2011-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25516" source="XF" patch="1">horde-help-viewer-command-execution(25516)</ref>
      <ref url="http://www.securityfocus.com/bid/17292" source="BID" patch="1">17292</ref>
      <ref url="http://securitytracker.com/id?1015841" source="SECTRACK" patch="1">1015841</ref>
      <ref url="http://lists.horde.org/archives/announce/2006/000271.html" source="CONFIRM" patch="1">http://lists.horde.org/archives/announce/2006/000271.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1154" source="VUPEN" adv="1">ADV-2006-1154</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_07_sr.html" source="SUSE">SUSE-SR:2006:007</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml" source="GENTOO">GLSA-200604-02</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1034" source="DEBIAN">DSA-1034</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1033" source="DEBIAN">DSA-1033</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000671.html" source="VIM">20060330 Recent unspecified Horde vuln is eval injection</ref>
      <ref url="http://secunia.com/advisories/19692" source="SECUNIA" adv="1">19692</ref>
      <ref url="http://secunia.com/advisories/19619" source="SECUNIA" adv="1">19619</ref>
      <ref url="http://secunia.com/advisories/19528" source="SECUNIA" adv="1">19528</ref>
      <ref url="http://secunia.com/advisories/19504" source="SECUNIA" adv="1">19504</ref>
      <ref url="http://secunia.com/advisories/19485" source="SECUNIA" adv="1">19485</ref>
      <ref url="http://lists.horde.org/archives/announce/2006/000272.html" source="CONFIRM">http://lists.horde.org/archives/announce/2006/000272.html</ref>
      <ref url="http://cvs.horde.org/diff.php?f=horde%2Fservices%2Fhelp%2Findex.php&amp;r1=2.85&amp;r2=2.86" source="CONFIRM">http://cvs.horde.org/diff.php?f=horde%2Fservices%2Fhelp%2Findex.php&amp;r1=2.85&amp;r2=2.86</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="application_framework">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.4_rc1" />
        <vers num="3.0.4_rc2" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1492" published="2006-03-29" name="CVE-2006-1492" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zataz.com/news/10871/Probleme-de-securite-decouvert-dans-le-logiciel-ExploreXP.html" source="MISC">http://www.zataz.com/news/10871/Probleme-de-securite-decouvert-dans-le-logiciel-ExploreXP.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1165" source="VUPEN">ADV-2006-1165</ref>
      <ref url="http://www.silitix.com/explorerxp.php" source="MISC">http://www.silitix.com/explorerxp.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25523" source="XF">explorerxp-dir-directory-traversal(25523)</ref>
      <ref url="http://www.securityfocus.com/bid/17303" source="BID">17303</ref>
      <ref url="http://www.osvdb.org/24259" source="OSVDB">24259</ref>
      <ref url="http://securitytracker.com/id?1015840" source="SECTRACK">1015840</ref>
      <ref url="http://secunia.com/advisories/19460" source="SECUNIA">19460</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1806.html" source="FULLDISC">20060329 ExplorerXP : Directory Traversal and Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nikolay_avrionov" name="explorer_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1493" published="2006-03-29" name="CVE-2006-1493" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter.  NOTE: it is possible that this issue is resultant from CVE-2006-1492.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zataz.com/news/10871/Probleme-de-securite-decouvert-dans-le-logiciel-ExploreXP.html" source="MISC">http://www.zataz.com/news/10871/Probleme-de-securite-decouvert-dans-le-logiciel-ExploreXP.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1165" source="VUPEN">ADV-2006-1165</ref>
      <ref url="http://www.silitix.com/explorerxp.php" source="MISC">http://www.silitix.com/explorerxp.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25524" source="XF">explorerxp-dir-xss(25524)</ref>
      <ref url="http://www.securityfocus.com/bid/17303" source="BID">17303</ref>
      <ref url="http://www.osvdb.org/24260" source="OSVDB">24260</ref>
      <ref url="http://securitytracker.com/id?1015840" source="SECTRACK">1015840</ref>
      <ref url="http://secunia.com/advisories/19460" source="SECUNIA">19460</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1806.html" source="FULLDISC">20060329 ExplorerXP : Directory Traversal and Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nikolay_avrionov" name="explorer_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1494" published="2006-04-10" name="CVE-2006-1494" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityreason.com/achievement_securityalert/36" source="SREASONRES" patch="1">20060408 tempnam() open_basedir bypass PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://secunia.com/advisories/19599" source="SECUNIA" patch="1" adv="1">19599</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1290" source="VUPEN">ADV-2006-1290</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10196" source="OVAL">oval:org.mitre.oval:def:10196</ref>
      <ref url="https://issues.rpath.com/browse/RPL-683" source="CONFIRM">https://issues.rpath.com/browse/RPL-683</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25705" source="XF">php-tempnam-directory-traversal(25705)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-320-1" source="UBUNTU">USN-320-1</ref>
      <ref url="http://www.securityfocus.com/bid/17439" source="BID">17439</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447866/100/0/threaded" source="BUGTRAQ">20061005 rPSA-2006-0182-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0568.html" source="REDHAT">RHSA-2006:0568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0567.html" source="REDHAT">RHSA-2006:0567</ref>
      <ref url="http://www.novell.com/linux/security/advisories/05-05-2006.html" source="SUSE">SUSE-SA:2006:024</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:074" source="MANDRIVA">MDKSA-2006:074</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm</ref>
      <ref url="http://securitytracker.com/id?1015881" source="SECTRACK">1015881</ref>
      <ref url="http://securityreason.com/securityalert/677" source="SREASON">677</ref>
      <ref url="http://secunia.com/advisories/22225" source="SECUNIA">22225</ref>
      <ref url="http://secunia.com/advisories/21723" source="SECUNIA">21723</ref>
      <ref url="http://secunia.com/advisories/21252" source="SECUNIA">21252</ref>
      <ref url="http://secunia.com/advisories/21202" source="SECUNIA">21202</ref>
      <ref url="http://secunia.com/advisories/21135" source="SECUNIA">21135</ref>
      <ref url="http://secunia.com/advisories/21125" source="SECUNIA">21125</ref>
      <ref url="http://secunia.com/advisories/21031" source="SECUNIA">21031</ref>
      <ref url="http://secunia.com/advisories/19979" source="SECUNIA">19979</ref>
      <ref url="http://secunia.com/advisories/19775" source="SECUNIA">19775</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0549.html" source="REDHAT">RHSA-2006:0549</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U" source="SGI">20060701-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1495" published="2006-03-29" name="CVE-2006-1495" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25503" source="XF">netoffice-sendpassword-sql-injection(25503)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1142" source="VUPEN">ADV-2006-1142</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1141" source="VUPEN">ADV-2006-1141</ref>
      <ref url="http://www.securityfocus.com/bid/17283" source="BID">17283</ref>
      <ref url="http://www.milw0rm.com/exploits/1617" source="MILW0RM">1617</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200812-20.xml" source="GENTOO">GLSA-200812-20</ref>
      <ref url="http://secunia.com/advisories/33258" source="SECUNIA">33258</ref>
      <ref url="http://secunia.com/advisories/19449" source="SECUNIA" adv="1">19449</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/PHPCollab_NetOffice_SQLINJ.php" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/PHPCollab_NetOffice_SQLINJ.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25505" source="XF">phpcollab-sendpassword-sql-injection(25505)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25503" source="XF">netoffice-sendpassword-bypass-security(25503)</ref>
      <ref url="http://www.securityfocus.com/bid/17286" source="BID">17286</ref>
      <ref url="http://www.osvdb.org/24230" source="OSVDB">24230</ref>
      <ref url="http://www.osvdb.org/24226" source="OSVDB">24226</ref>
      <ref url="http://secunia.com/advisories/19452" source="SECUNIA">19452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netoffice" name="netoffice">
        <vers num="2.5.3_pl1" />
      </prod>
      <prod vendor="phpcollab" name="phpcollab">
        <vers num="2.4" />
        <vers num="2.5.rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1496" published="2006-03-29" name="CVE-2006-1496" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17226" source="BID">17226</ref>
      <ref url="http://www.securityfocus.com/archive/1/428737" source="BUGTRAQ">20060324 VihorDesing Script Remote Command Exucetion And Cross Scripting Attack</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000651.html" source="VIM">20060326 clarification of "VihorDesign" (not VihorDesing) issues</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000650.html" source="VIM">20060326 clarification of "VihorDesign" (not VihorDesing) issues</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25483" source="XF">vihordesign-index-xss(25483)</ref>
      <ref url="http://secunia.com/advisories/19403" source="SECUNIA">19403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vihor" name="vihordesign">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1497" published="2006-03-29" name="CVE-2006-1497" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19403" source="SECUNIA" patch="1" adv="1">19403</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1114" source="VUPEN">ADV-2006-1114</ref>
      <ref url="http://www.securityfocus.com/bid/17226" source="BID">17226</ref>
      <ref url="http://www.securityfocus.com/archive/1/428737" source="BUGTRAQ">20060324 VihorDesing Script Remote Command Exucetion And Cross Scripting Attack</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000652.html" source="VIM">20060327 clarification of "VihorDesign" (not VihorDesing) issues</ref>
      <ref url="http://www.securityfocus.com/bid/17227" source="BID">17227</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-March/000650.html" source="VIM">20060326 clarification of "VihorDesign" (not VihorDesing) issues</ref>
      <ref url="http://securityreason.com/securityalert/625" source="SREASON">625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vihor" name="vihordesign">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1498" published="2006-03-29" name="CVE-2006-1498" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17269" source="BID" patch="1">17269</ref>
      <ref url="http://mail.wikipedia.org/pipermail/mediawiki-announce/2006-March/000040.html" source="MLIST" patch="1">[MediaWiki-announce] 20060327 MediaWiki 1.5.8, 1.4.15 released [SECURITY]</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1194" source="VUPEN">ADV-2006-1194</ref>
      <ref url="http://www.mediawiki.org/wiki/MediaWiki" source="CONFIRM">http://www.mediawiki.org/wiki/MediaWiki</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25588" source="XF">mediawiki-unspecified-xss(25588)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_07_sr.html" source="SUSE">SUSE-SR:2006:007</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-01.xml" source="GENTOO">GLSA-200604-01</ref>
      <ref url="http://secunia.com/advisories/19517" source="SECUNIA">19517</ref>
      <ref url="http://secunia.com/advisories/19508" source="SECUNIA">19508</ref>
      <ref url="http://secunia.com/advisories/19504" source="SECUNIA">19504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5_alpha1" />
        <vers num="1.5_alpha2" />
        <vers num="1.5_beta1" />
        <vers num="1.5_beta2" />
        <vers num="1.5_beta3" />
        <vers num="1.5_beta4" />
        <vers num="1.5_rc2" />
        <vers num="1.5_rc3" />
        <vers num="1.5_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1499" published="2006-03-29" name="CVE-2006-1499" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1147" source="VUPEN">ADV-2006-1147</ref>
      <ref url="http://secunia.com/advisories/19422" source="SECUNIA" adv="1">19422</ref>
      <ref url="http://evuln.com/vulns/108/summary.html" source="MISC">http://evuln.com/vulns/108/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25500" source="XF">vcounter-url-sql-injection(25500)</ref>
      <ref url="http://www.securityfocus.com/bid/17302" source="BID">17302</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430353/100/0/threaded" source="BUGTRAQ">20060407 [eVuln] vCounter - sourceworkshop SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/24234" source="OSVDB">24234</ref>
    </refs>
    <vuln_soft>
      <prod vendor="source_workshop" name="vcounter">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1500" published="2006-03-29" name="CVE-2006-1500" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25510" source="XF">tildecms-index-sql-injection(25510)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1145" source="VUPEN" adv="1">ADV-2006-1145</ref>
      <ref url="http://www.securityfocus.com/bid/17299" source="BID">17299</ref>
      <ref url="http://www.osvdb.org/24233" source="OSVDB">24233</ref>
      <ref url="http://secunia.com/advisories/19447" source="SECUNIA" adv="1">19447</ref>
      <ref url="http://osvdb.org/ref/24/24233-tilde.txt" source="MISC">http://osvdb.org/ref/24/24233-tilde.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tilde" name="tilde_cms">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1501" published="2006-03-29" name="CVE-2006-1501" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25511" source="XF">oneorzero-helpdesk-index-sql-injection(25511)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1146" source="VUPEN" adv="1">ADV-2006-1146</ref>
      <ref url="http://www.securityfocus.com/bid/17298" source="BID">17298</ref>
      <ref url="http://www.osvdb.org/24228" source="OSVDB">24228</ref>
      <ref url="http://secunia.com/advisories/19446" source="SECUNIA" adv="1">19446</ref>
      <ref url="http://osvdb.org/ref/24/24228-oneorzero.txt" source="MISC">http://osvdb.org/ref/24/24228-oneorzero.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneorzero" name="oneorzero">
        <vers num="1.6.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1502" published="2006-03-29" name="CVE-2006-1502" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.xfocus.org/advisories/200603/11.html" source="MISC" adv="1">http://www.xfocus.org/advisories/200603/11.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1156" source="VUPEN">ADV-2006-1156</ref>
      <ref url="http://www.securityfocus.com/bid/17295" source="BID">17295</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429251/100/0/threaded" source="BUGTRAQ" adv="1">20060329 [xfocus-SD-060329]MPlayer: Multiple integer overflows</ref>
      <ref url="http://secunia.com/advisories/19418" source="SECUNIA" adv="1">19418</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044615.html" source="FULLDISC">20060329 [xfocus-SD-060329]MPlayer: Multiple integer overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25514" source="XF">mplayer-aviheader-integer-overflow(25514)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25513" source="XF">mplayer-asfheader-integer-overflow(25513)</ref>
      <ref url="http://www.osvdb.org/24247" source="OSVDB">24247</ref>
      <ref url="http://www.osvdb.org/24246" source="OSVDB">24246</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:068" source="MANDRIVA">MDKSA-2006:068</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-01.xml" source="GENTOO">GLSA-200605-01</ref>
      <ref url="http://securitytracker.com/id?1015842" source="SECTRACK">1015842</ref>
      <ref url="http://securityreason.com/securityalert/647" source="SREASON">647</ref>
      <ref url="http://securityreason.com/securityalert/532" source="SREASON">532</ref>
      <ref url="http://secunia.com/advisories/19919" source="SECUNIA">19919</ref>
      <ref url="http://secunia.com/advisories/19565" source="SECUNIA">19565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers prev="1" num="1.0_pre7try2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1503" published="2006-03-29" name="CVE-2006-1503" modified="2011-08-22" discovered="2006-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter.  NOTE: this is a different vulnerability than CVE-2006-1636.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "register_globals" parameter is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25497" source="XF">virtual-war-functionsinstall-file-include(25497)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1144" source="VUPEN" adv="1">ADV-2006-1144</ref>
      <ref url="http://www.securityfocus.com/bid/17290" source="BID">17290</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429090/100/0/threaded" source="BUGTRAQ" adv="1">20060328 VWar &lt;= 1.5.0 R11 Remote Code Execution Exploit</ref>
      <ref url="http://www.osvdb.org/24239" source="OSVDB">24239</ref>
      <ref url="http://secunia.com/advisories/19438" source="SECUNIA" adv="1">19438</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000679.html" source="VIM">20060403 Vendor ACK for VWar issue - VWar used by PhpNuke Clan</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vwar" name="virtual_war">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5.0_r1" />
        <vers num="1.5.0_r10" />
        <vers num="1.5.0_r11" />
        <vers num="1.5.0_r2" />
        <vers num="1.5.0_r3" />
        <vers num="1.5.0_r4" />
        <vers num="1.5.0_r5" />
        <vers num="1.5.0_r6" />
        <vers num="1.5.0_r7" />
        <vers num="1.5.0_r8" />
        <vers num="1.5.0_r9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1504" published="2006-03-29" name="CVE-2006-1504" modified="2011-03-07" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "register_globals" parameter is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1150" source="VUPEN">ADV-2006-1150</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429109/100/0/threaded" source="BUGTRAQ" adv="1">20060328 ArabPortal 2.0 Stable CrossSiteScripting</ref>
      <ref url="http://secunia.com/advisories/19445" source="SECUNIA" adv="1">19445</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25515" source="XF">arabportal-online-download-xss(25515)</ref>
      <ref url="http://www.securityfocus.com/bid/17285" source="BID">17285</ref>
      <ref url="http://www.osvdb.org/24221" source="OSVDB">24221</ref>
      <ref url="http://www.osvdb.org/24220" source="OSVDB">24220</ref>
      <ref url="http://securityreason.com/securityalert/673" source="SREASON">673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arab_portal" name="arab_portal">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1505" published="2006-03-29" name="CVE-2006-1505" modified="2011-03-07" discovered="2006-02-26" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".</descript>
    </desc>
    <sols>
      <sol source="nvd">Succesful exploitation requires that the product is running in standalone mode.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24101" source="OSVDB" patch="1" adv="1">24101</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1192" source="VUPEN">ADV-2006-1192</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/secureideas/base-php4/docs/CHANGELOG?rev=1.233&amp;view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/secureideas/base-php4/docs/CHANGELOG?rev=1.233&amp;view=markup</ref>
      <ref url="http://www.securityfocus.com/bid/17354" source="BID">17354</ref>
      <ref url="http://secunia.com/advisories/19510" source="SECUNIA">19510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="basic_analysis_and_security_engine" name="base">
        <vers num="1.1.2_zora" />
        <vers num="1.1.3_lynn" />
        <vers num="1.1.4_cheryl" />
        <vers num="1.1_elizabeth" />
        <vers num="1.2.1_kris" />
        <vers num="1.2.2_cindy" />
        <vers num="1.2_betty" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1506" published="2006-03-29" name="CVE-2006-1506" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Sun Microsystems, Sun Grid Engine 5.3 before 20060327 &amp; N1 Grid Engine 6.0 before 20060327.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102268-1" source="SUNALERT" patch="1">102268</ref>
      <ref url="http://securitytracker.com/id?1015835" source="SECTRACK" patch="1">1015835</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1155" source="VUPEN">ADV-2006-1155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="grid_engine">
        <vers num="5.3" />
      </prod>
      <prod vendor="sun" name="n1_grid_engine">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1507" published="2006-03-29" name="CVE-2006-1507" modified="2008-09-05" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17291" source="BID">17291</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429249/100/0/threaded" source="BUGTRAQ" adv="1">20060328 XSS in PHPKIT Version 1.6.03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25594" source="XF">phpkit-error-xss(25594)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1508" published="2006-03-29" name="CVE-2006-1508" modified="2011-03-07" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1125" source="VUPEN">ADV-2006-1125</ref>
      <ref url="http://www.securityfocus.com/bid/17287" source="BID">17287</ref>
      <ref url="http://secunia.com/advisories/19434" source="SECUNIA" adv="1">19434</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25474" source="XF">connectdailywebcalendar-multiple-xss(25474)</ref>
      <ref url="http://www.osvdb.org/24185" source="OSVDB">24185</ref>
      <ref url="http://www.osvdb.org/24184" source="OSVDB">24184</ref>
      <ref url="http://www.osvdb.org/24183" source="OSVDB">24183</ref>
      <ref url="http://www.osvdb.org/24182" source="OSVDB">24182</ref>
      <ref url="http://www.osvdb.org/24181" source="OSVDB">24181</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/connect-daily-multiple-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/connect-daily-multiple-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mh_software" name="connect_daily">
        <vers num="3.2.8" />
        <vers prev="1" num="3.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1509" published="2006-03-29" name="CVE-2006-1509" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of HP-UX B.11.00, B.11.11, and B.11.23 before 20060326.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550" source="HP" patch="1">SSRT5953</ref>
      <ref url="http://www.securityfocus.com/bid/17280" source="BID" patch="1">17280</ref>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550" source="HP">HPSBUX02103</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1208" source="VUPEN">ADV-2006-1208</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25596" source="XF">hpux-passwd-dos(25596)</ref>
      <ref url="http://secunia.com/advisories/19490" source="SECUNIA">19490</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1690" source="OVAL" sig="1">oval:org.mitre.oval:def:1690</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1660" source="OVAL" sig="1">oval:org.mitre.oval:def:1660</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1412" source="OVAL" sig="1">oval:org.mitre.oval:def:1412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1510" published="2006-03-29" name="CVE-2006-1510" modified="2011-03-07" discovered="2005-11-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.</descript>
    </desc>
    <sols>
      <sol source="nvd">Succesful exploitation can only occur when ntdll.dll system library is used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK packages.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17243" source="BID" patch="1">17243</ref>
      <ref url="http://secunia.com/advisories/19406" source="SECUNIA" patch="1" adv="1">19406</ref>
      <ref url="http://owasp.net/forums/234/showpost.aspx" source="MISC" patch="1">http://owasp.net/forums/234/showpost.aspx</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044482.html" source="FULLDISC" patch="1" adv="1">20060327 Buffer OverFlow in ILASM and ILDASM</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25439" source="XF">ms-dotnet-ildasm-bo(25439)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1113" source="VUPEN">ADV-2006-1113</ref>
      <ref url="http://owasp.net/forums/257/showpost.aspx" source="MISC">http://owasp.net/forums/257/showpost.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp1:sdk" />
        <vers num="1.0" edition="sp2" />
        <vers num="1.0" edition="sp2:sdk" />
        <vers num="1.1" edition="sp1" />
        <vers num="1.1" edition="sp1:sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1511" published="2006-03-29" name="CVE-2006-1511" modified="2011-03-07" discovered="2005-11-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25438" source="XF" patch="1">ms-dotnet-ilasm-bo(25438)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1113" source="VUPEN">ADV-2006-1113</ref>
      <ref url="http://www.securityfocus.com/bid/17243" source="BID">17243</ref>
      <ref url="http://secunia.com/advisories/19406" source="SECUNIA" adv="1">19406</ref>
      <ref url="http://owasp.net/forums/257/showpost.aspx" source="MISC">http://owasp.net/forums/257/showpost.aspx</ref>
      <ref url="http://owasp.net/forums/234/showpost.aspx" source="MISC">http://owasp.net/forums/234/showpost.aspx</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044482.html" source="FULLDISC">20060327 Buffer OverFlow in ILASM and ILDASM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":sdk" />
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp1:sdk" />
        <vers num="1.0" edition="sp2" />
        <vers num="1.0" edition="sp2:sdk" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":sdk" />
        <vers num="1.1" edition="sp1" />
        <vers num="1.1" edition="sp1:sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-1512" reject="1" published="2006-04-24" name="CVE-2006-1512" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1712.  Reason: This candidate is a reservation duplicate of CVE-2006-1712.  Notes: All CVE users should reference CVE-2006-1712 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1513" published="2006-04-25" name="CVE-2006-1513" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in abc2ps before 1.3.3 allow user-assisted attackers to execute arbitrary code via crafted ABC music files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1041" source="DEBIAN" patch="1" adv="1">DSA-1041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26043" source="XF">abc2ps-abc-bo(26043)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1511" source="VUPEN" adv="1">ADV-2006-1511</ref>
      <ref url="http://www.securityfocus.com/bid/17689" source="BID">17689</ref>
      <ref url="http://secunia.com/advisories/19807" source="SECUNIA" adv="1">19807</ref>
      <ref url="http://secunia.com/advisories/19787" source="SECUNIA" adv="1">19787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abc2ps" name="abc2ps">
        <vers num="1.2.2e3" />
        <vers num="1.2.2e4" />
        <vers num="1.2.5" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1514" published="2006-04-27" name="CVE-2006-1514" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the abcmidi-yaps translator in abcmidi 20050101, and other versions, allow remote attackers to execute arbitrary code via crafted ABC music files that trigger the overflows during translation into PostScript.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24974" source="OSVDB" patch="1">24974</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1043" source="DEBIAN" patch="1">DSA-1043</ref>
      <ref url="http://secunia.com/advisories/19829" source="SECUNIA" patch="1" adv="1">19829</ref>
      <ref url="http://secunia.com/advisories/19826" source="SECUNIA" patch="1" adv="1">19826</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1531" source="VUPEN">ADV-2006-1531</ref>
      <ref url="http://www.securityfocus.com/bid/17704" source="BID">17704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abcmidi" name="abcmidi">
        <vers num="2004-12-04" />
        <vers num="2005-01-01" />
        <vers prev="1" num="2006-04-22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1515" published="2006-05-31" name="CVE-2006-1515" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1084" source="DEBIAN" patch="1" adv="1">DSA-1084</ref>
      <ref url="http://secunia.com/advisories/20393" source="SECUNIA" patch="1" adv="1">20393</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2087" source="VUPEN">ADV-2006-2087</ref>
      <ref url="http://www.securityfocus.com/bid/18194" source="BID">18194</ref>
      <ref url="http://secunia.com/advisories/20379" source="SECUNIA" adv="1">20379</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200606-20.xml" source="GENTOO">GLSA-200606-20</ref>
      <ref url="http://secunia.com/advisories/20708" source="SECUNIA">20708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typespeed" name="typespeed">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1516" published="2006-05-05" name="CVE-2006-1516" modified="2011-03-07" discovered="2006-05-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.wisec.it/vulns.php?page=7" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=7</ref>
      <ref url="http://securitytracker.com/id?1016017" source="SECTRACK" patch="1">1016017</ref>
      <ref url="http://secunia.com/advisories/19929" source="SECUNIA" patch="1" adv="1">19929</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html" source="CONFIRM" patch="1">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1326/references" source="VUPEN">ADV-2008-1326</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1633" source="VUPEN">ADV-2006-1633</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432733/100/0/threaded" source="BUGTRAQ">20060502 MySQL Anonymous Login Handshake - Information Leakage.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9918" source="OVAL">oval:org.mitre.oval:def:9918</ref>
      <ref url="http://bugs.debian.org/365938" source="CONFIRM">http://bugs.debian.org/365938</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26236" source="XF">mysql-login-packet-info-disclosure(26236)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-283-1" source="UBUNTU">USN-283-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0028" source="TRUSTIX">2006-0028</ref>
      <ref url="http://www.securityfocus.com/bid/17780" source="BID">17780</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434164/100/0/threaded" source="BUGTRAQ">20060516 UPDATE: [ GLSA 200605-13 ] MySQL: Information leakage</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0544.html" source="REDHAT">RHSA-2006:0544</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-06-02.html" source="SUSE">SUSE-SR:2006:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:084" source="MANDRIVA">MDKSA-2006:084</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml" source="GENTOO">GLSA-200605-13</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1079" source="DEBIAN">DSA-1079</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1073" source="DEBIAN">DSA-1073</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1071" source="DEBIAN">DSA-1071</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1" source="SUNALERT">236703</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.599377" source="SLACKWARE">SSA:2006-155-01</ref>
      <ref url="http://securityreason.com/securityalert/840" source="SREASON">840</ref>
      <ref url="http://secunia.com/advisories/29847" source="SECUNIA">29847</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/20762" source="SECUNIA">20762</ref>
      <ref url="http://secunia.com/advisories/20625" source="SECUNIA">20625</ref>
      <ref url="http://secunia.com/advisories/20457" source="SECUNIA">20457</ref>
      <ref url="http://secunia.com/advisories/20424" source="SECUNIA">20424</ref>
      <ref url="http://secunia.com/advisories/20333" source="SECUNIA">20333</ref>
      <ref url="http://secunia.com/advisories/20253" source="SECUNIA">20253</ref>
      <ref url="http://secunia.com/advisories/20241" source="SECUNIA">20241</ref>
      <ref url="http://secunia.com/advisories/20223" source="SECUNIA">20223</ref>
      <ref url="http://secunia.com/advisories/20076" source="SECUNIA">20076</ref>
      <ref url="http://secunia.com/advisories/20073" source="SECUNIA">20073</ref>
      <ref url="http://secunia.com/advisories/20002" source="SECUNIA">20002</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html" source="SUSE">SUSE-SA:2006:036</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.16" />
        <vers num="4.0.17" />
        <vers num="4.0.18" />
        <vers num="4.0.19" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.23" />
        <vers num="4.0.24" />
        <vers num="4.0.25" />
        <vers num="4.0.26" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.10" />
        <vers num="4.1.10a" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" />
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.2" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1517" published="2006-05-05" name="CVE-2006-1517" modified="2011-03-07" discovered="2006-05-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.wisec.it/vulns.php?page=8" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=8</ref>
      <ref url="http://securitytracker.com/id?1016016" source="SECTRACK" patch="1">1016016</ref>
      <ref url="http://secunia.com/advisories/19929" source="SECUNIA" patch="1" adv="1">19929</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html" source="CONFIRM" patch="1">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1326/references" source="VUPEN">ADV-2008-1326</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1633" source="VUPEN">ADV-2006-1633</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432734/100/0/threaded" source="BUGTRAQ">20060502 MySQL COM_TABLE_DUMP Information Leakage and Arbitrary commandexecution.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11036" source="OVAL">oval:org.mitre.oval:def:11036</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26228" source="XF">mysql-sqlparcecc-information-disclosure(26228)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-283-1" source="UBUNTU">USN-283-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0028" source="TRUSTIX">2006-0028</ref>
      <ref url="http://www.securityfocus.com/bid/17780" source="BID">17780</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434164/100/0/threaded" source="BUGTRAQ">20060516 UPDATE: [ GLSA 200605-13 ] MySQL: Information leakage</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0544.html" source="REDHAT">RHSA-2006:0544</ref>
      <ref url="http://www.osvdb.org/25228" source="OSVDB">25228</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-06-02.html" source="SUSE">SUSE-SR:2006:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:084" source="MANDRIVA">MDKSA-2006:084</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml" source="GENTOO">GLSA-200605-13</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1079" source="DEBIAN">DSA-1079</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1073" source="DEBIAN">DSA-1073</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1071" source="DEBIAN">DSA-1071</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1" source="SUNALERT">236703</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.599377" source="SLACKWARE">SSA:2006-155-01</ref>
      <ref url="http://securityreason.com/securityalert/839" source="SREASON">839</ref>
      <ref url="http://secunia.com/advisories/29847" source="SECUNIA">29847</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/20762" source="SECUNIA">20762</ref>
      <ref url="http://secunia.com/advisories/20625" source="SECUNIA">20625</ref>
      <ref url="http://secunia.com/advisories/20457" source="SECUNIA">20457</ref>
      <ref url="http://secunia.com/advisories/20424" source="SECUNIA">20424</ref>
      <ref url="http://secunia.com/advisories/20333" source="SECUNIA">20333</ref>
      <ref url="http://secunia.com/advisories/20253" source="SECUNIA">20253</ref>
      <ref url="http://secunia.com/advisories/20241" source="SECUNIA">20241</ref>
      <ref url="http://secunia.com/advisories/20223" source="SECUNIA">20223</ref>
      <ref url="http://secunia.com/advisories/20076" source="SECUNIA">20076</ref>
      <ref url="http://secunia.com/advisories/20073" source="SECUNIA">20073</ref>
      <ref url="http://secunia.com/advisories/20002" source="SECUNIA">20002</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html" source="SUSE">SUSE-SA:2006:036</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.16" />
        <vers num="4.0.17" />
        <vers num="4.0.18" />
        <vers num="4.0.19" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.21" />
        <vers num="4.0.23" />
        <vers num="4.0.24" />
        <vers num="4.0.25" />
        <vers num="4.0.26" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
        <vers num="4.1.10" />
        <vers num="4.1.10a" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.2" edition="alpha" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" />
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.2" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1518" published="2006-05-05" name="CVE-2006-1518" modified="2011-03-07" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602457" source="CERT-VN" patch="1" adv="1">VU#602457</ref>
      <ref url="http://www.wisec.it/vulns.php?page=8" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=8</ref>
      <ref url="http://securitytracker.com/id?1016016" source="SECTRACK" patch="1">1016016</ref>
      <ref url="http://secunia.com/advisories/19929" source="SECUNIA" patch="1" adv="1">19929</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html" source="CONFIRM" patch="1">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1633" source="VUPEN">ADV-2006-1633</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432734/100/0/threaded" source="BUGTRAQ">20060502 MySQL COM_TABLE_DUMP Information Leakage and Arbitrary commandexecution.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26232" source="XF">mysql-comtabledump-bo(26232)</ref>
      <ref url="http://www.securityfocus.com/bid/17780" source="BID">17780</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-06-02.html" source="SUSE">SUSE-SR:2006:012</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1079" source="DEBIAN">DSA-1079</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1073" source="DEBIAN">DSA-1073</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1071" source="DEBIAN">DSA-1071</ref>
      <ref url="http://securityreason.com/securityalert/839" source="SREASON">839</ref>
      <ref url="http://secunia.com/advisories/20762" source="SECUNIA">20762</ref>
      <ref url="http://secunia.com/advisories/20457" source="SECUNIA">20457</ref>
      <ref url="http://secunia.com/advisories/20333" source="SECUNIA">20333</ref>
      <ref url="http://secunia.com/advisories/20253" source="SECUNIA">20253</ref>
      <ref url="http://secunia.com/advisories/20241" source="SECUNIA">20241</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html" source="SUSE">SUSE-SA:2006:036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.2" />
        <vers num="5.0.20" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-1519" reject="1" published="2006-05-15" name="CVE-2006-1519" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-2224.  Reason: This candidate is a duplicate of CVE-2006-2224.  Notes: All CVE users should reference CVE-2006-2224 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1520" published="2006-05-22" name="CVE-2006-1520" modified="2011-03-07" discovered="2006-05-09" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Format string vulnerability in ANSI C Sender Policy Framework library (libspf) before 1.0.0-p5, when debugging is enabled, allows remote attackers to execute arbitrary code via format string specifiers, possibly in an e-mail address.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.libspf.org/index.html" source="CONFIRM" patch="1">http://www.libspf.org/index.html</ref>
      <ref url="http://www.gossamer-threads.com/lists/spf/devel/27053?page=last" source="MISC" patch="1">http://www.gossamer-threads.com/lists/spf/devel/27053?page=last</ref>
      <ref url="http://permalink.gmane.org/gmane.mail.spam.spf.devel/849" source="MISC" patch="1">http://permalink.gmane.org/gmane.mail.spam.spf.devel/849</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1846" source="VUPEN">ADV-2006-1846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26535" source="XF">libspf-debugging-format-string(26535)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libspf" name="libspf">
        <vers num="1.0.0_p4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1522" published="2006-04-10" name="CVE-2006-1522" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188466" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188466</ref>
      <ref url="http://www.securityfocus.com/bid/17451" source="BID" patch="1">17451</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c3a9d6541f84ac3ff566982d08389b87c1c36b4e" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c3a9d6541f84ac3ff566982d08389b87c1c36b4e</ref>
      <ref url="http://secunia.com/advisories/19573" source="SECUNIA" patch="1" adv="1">19573</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25722" source="XF">linux-keyringsearchone-dos(25722)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1475" source="VUPEN" adv="1">ADV-2006-1475</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1307" source="VUPEN" adv="1">ADV-2006-1307</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.osvdb.org/24507" source="OSVDB">24507</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086" source="MANDRIVA">MDKSA-2006:086</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA" adv="1">21745</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA" adv="1">20716</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA" adv="1">20237</ref>
      <ref url="http://secunia.com/advisories/20157" source="SECUNIA" adv="1">20157</ref>
      <ref url="http://secunia.com/advisories/19735" source="SECUNIA" adv="1">19735</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9325" source="OVAL">oval:org.mitre.oval:def:9325</ref>
      <ref url="http://lwn.net/Alerts/180820/" source="FEDORA">FEDORA-2006-423</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.3" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.16.1" />
        <vers num="2.6.17" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1523" published="2006-04-12" name="CVE-2006-1523" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The __group_complete_signal function in the RCU signal handling (signal.c) in Linux kernel 2.6.16, and possibly other versions, has unknown impact and attack vectors related to improper use of BUG_ON.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=114476543426600&amp;w=2" source="MLIST" patch="1">[linux-kernel] 20060411 [PATCH] __group_complete_signal: remove bogus BUG_ON</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188604" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188604</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.securityfocus.com/bid/17640" source="BID">17640</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1524" published="2006-04-19" name="CVE-2006-1524" modified="2011-10-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability.  NOTE: this description was originally written in a way that combined two separate issues.  The mprotect issue now has a separate name, CVE-2006-2071.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17587" source="BID" patch="1">17587</ref>
      <ref url="http://secunia.com/advisories/19657" source="SECUNIA" patch="1" adv="1">19657</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25870" source="XF">linux-madvise-security-bypass(25870)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN" adv="1">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1475" source="VUPEN" adv="1">ADV-2006-1475</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1391" source="VUPEN" adv="1">ADV-2006-1391</ref>
      <ref url="http://www.osvdb.org/24714" source="OSVDB">24714</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA" adv="1">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA" adv="1">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA" adv="1">20398</ref>
      <ref url="http://secunia.com/advisories/19735" source="SECUNIA" adv="1">19735</ref>
      <ref url="http://secunia.com/advisories/19664" source="SECUNIA" adv="1">19664</ref>
      <ref url="http://lwn.net/Alerts/180820/" source="FEDORA">FEDORA-2006-423</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1525" published="2006-04-19" name="CVE-2006-1525" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">ip_route_input in Linux kernel 2.6 before 2.6.16.8 allows local users to cause a denial of service (panic) via a request for a route for a multicast IP address, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17593" source="BID" patch="1">17593</ref>
      <ref url="http://secunia.com/advisories/19709" source="SECUNIA" patch="1" adv="1">19709</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189346" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189346</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25872" source="XF">linux-ip-route-input-dos(25872)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN" adv="1">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1475" source="VUPEN" adv="1">ADV-2006-1475</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1399" source="VUPEN" adv="1">ADV-2006-1399</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1" source="UBUNTU">USN-281-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.osvdb.org/24715" source="OSVDB">24715</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086" source="MANDRIVA">MDKSA-2006:086</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA" adv="1">21745</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA" adv="1">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA" adv="1">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA" adv="1">20398</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA" adv="1">20237</ref>
      <ref url="http://secunia.com/advisories/20157" source="SECUNIA" adv="1">20157</ref>
      <ref url="http://secunia.com/advisories/19955" source="SECUNIA" adv="1">19955</ref>
      <ref url="http://secunia.com/advisories/19735" source="SECUNIA" adv="1">19735</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10146" source="OVAL">oval:org.mitre.oval:def:10146</ref>
      <ref url="http://lwn.net/Alerts/180820/" source="FEDORA">FEDORA-2006-423</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.8" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1526" published="2006-05-02" name="CVE-2006-1526" modified="2011-03-07" discovered="2006-05-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&amp;" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/633257" source="CERT-VN">VU#633257</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0451.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0451</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_03.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:023</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-02.xml" source="GENTOO" patch="1" adv="1">GLSA-200605-02</ref>
      <ref url="http://secunia.com/advisories/19956" source="SECUNIA" patch="1" adv="1">19956</ref>
      <ref url="http://secunia.com/advisories/19951" source="SECUNIA" patch="1" adv="1">19951</ref>
      <ref url="http://secunia.com/advisories/19943" source="SECUNIA" patch="1" adv="1">19943</ref>
      <ref url="http://secunia.com/advisories/19921" source="SECUNIA" patch="1" adv="1">19921</ref>
      <ref url="http://secunia.com/advisories/19916" source="SECUNIA" patch="1" adv="1">19916</ref>
      <ref url="http://secunia.com/advisories/19915" source="SECUNIA" patch="1" adv="1">19915</ref>
      <ref url="http://secunia.com/advisories/19900" source="SECUNIA" patch="1" adv="1">19900</ref>
      <ref url="http://lists.freedesktop.org/archives/xorg/2006-May/015136.html" source="MLIST" patch="1">[xorg] 20060502 [CVE-2006-1525] X.Org security advisory: Buffer overflow in the Xrender extension</ref>
      <ref url="https://bugs.freedesktop.org/show_bug.cgi?id=6642" source="CONFIRM">https://bugs.freedesktop.org/show_bug.cgi?id=6642</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1617" source="VUPEN">ADV-2006-1617</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-280-1" source="UBUNTU">USN-280-1</ref>
      <ref url="http://www.openbsd.org/errata38.html#xorg" source="OPENBSD">[3.8] 007: SECURITY FIX: May 2, 2006</ref>
      <ref url="http://securitytracker.com/id?1016018" source="SECTRACK">1016018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9929" source="OVAL">oval:org.mitre.oval:def:9929</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26200" source="XF">xorg-xrender-bo(26200)</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/bid/17795" source="BID">17795</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436327/100/0/threaded" source="FEDORA">FLSA:190777</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:081" source="MANDRIVA">MDKSA-2006:081</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102339-1" source="SUNALERT">102339</ref>
      <ref url="http://secunia.com/advisories/19983" source="SECUNIA">19983</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0" />
        <vers num="6.8" />
        <vers num="6.8.1" />
        <vers num="6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1527" published="2006-05-03" name="CVE-2006-1527" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SCTP-netfilter code in Linux kernel before 2.6.16.13 allows remote attackers to trigger a denial of service (infinite loop) via unknown vectors that cause an invalid SCTP chunk size to be processed by the for_each_sctp_chunk function.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to Linux Kernel version 2.6.16.13 :
http://www.kernel.org/</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1632" source="VUPEN">ADV-2006-1632</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.13" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10373" source="OVAL">oval:org.mitre.oval:def:10373</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26194" source="XF">linux-sctp-netfilter-dos(26194)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/bid/17806" source="BID">17806</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.osvdb.org/25229" source="OSVDB">25229</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086" source="MANDRIVA">MDKSA-2006:086</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
      <ref url="http://secunia.com/advisories/20157" source="SECUNIA">20157</ref>
      <ref url="http://secunia.com/advisories/19926" source="SECUNIA">19926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1528" published="2006-05-18" name="CVE-2006-1528" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168791" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28510" source="XF">kernel-sg-dos(28510)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3330" source="VUPEN">ADV-2006-3330</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/bid/18101" source="BID">18101</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html" source="SUSE">SUSE-SA:2006:047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1184" source="DEBIAN">DSA-1184</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1183" source="DEBIAN">DSA-1183</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/22093" source="SECUNIA" adv="1">22093</ref>
      <ref url="http://secunia.com/advisories/22082" source="SECUNIA" adv="1">22082</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA" adv="1">21745</ref>
      <ref url="http://secunia.com/advisories/21555" source="SECUNIA" adv="1">21555</ref>
      <ref url="http://secunia.com/advisories/21498" source="SECUNIA" adv="1">21498</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA" adv="1">21179</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA" adv="1">21045</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA" adv="1">20716</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA" adv="1">20237</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11037" source="OVAL">oval:org.mitre.oval:def:11037</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-scsi&amp;m=112540053711489&amp;w=2" source="MISC">http://marc.theaimsgroup.com/?l=linux-scsi&amp;m=112540053711489&amp;w=2</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@43220081yu9ClBQNuqSSnW_9amW7iQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@43220081yu9ClBQNuqSSnW_9amW7iQ</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.1" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="" />
        <vers num="2.6.11" edition=":x86_64" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="final" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1529" published="2006-04-14" name="CVE-2006-1529" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/350262" source="CERT-VN">VU#350262</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-20.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=315254" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=315254</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://securitytracker.com/id?1015921" source="SECTRACK">1015921</ref>
      <ref url="http://securitytracker.com/id?1015920" source="SECTRACK">1015920</ref>
      <ref url="http://securitytracker.com/id?1015919" source="SECTRACK">1015919</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1947" source="OVAL" sig="1">oval:org.mitre.oval:def:1947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="preview_release" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1530" published="2006-04-14" name="CVE-2006-1530" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addresses in the following product releases: 
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/350262" source="CERT-VN">VU#350262</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-20.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=326615" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=326615</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://securitytracker.com/id?1015921" source="SECTRACK">1015921</ref>
      <ref url="http://securitytracker.com/id?1015920" source="SECTRACK">1015920</ref>
      <ref url="http://securitytracker.com/id?1015919" source="SECTRACK">1015919</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1903" source="OVAL" sig="1">oval:org.mitre.oval:def:1903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1531" published="2006-04-14" name="CVE-2006-1531" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/350262" source="CERT-VN">VU#350262</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-20.html</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://securitytracker.com/id?1015921" source="SECTRACK">1015921</ref>
      <ref url="http://securitytracker.com/id?1015920" source="SECTRACK">1015920</ref>
      <ref url="http://securitytracker.com/id?1015919" source="SECTRACK">1015919</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2023" source="OVAL" sig="1">oval:org.mitre.oval:def:2023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1532" published="2006-03-30" name="CVE-2006-1532" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25507" source="XF">phpclassifieds-search-xss(25507)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1143" source="VUPEN">ADV-2006-1143</ref>
      <ref url="http://www.securityfocus.com/bid/17305" source="BID">17305</ref>
      <ref url="http://www.osvdb.org/24232" source="OSVDB">24232</ref>
      <ref url="http://secunia.com/advisories/19440" source="SECUNIA" adv="1">19440</ref>
      <ref url="http://osvdb.org/ref/24/24232-php_classifieds.txt" source="MISC">http://osvdb.org/ref/24/24232-php_classifieds.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deltascripts" name="php_classifieds">
        <vers num="6.18" />
        <vers num="6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1533" published="2006-03-30" name="CVE-2006-1533" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1148" source="VUPEN">ADV-2006-1148</ref>
      <ref url="http://secunia.com/advisories/19425" source="SECUNIA" adv="1">19425</ref>
      <ref url="http://evuln.com/vulns/107/summary.html" source="MISC">http://evuln.com/vulns/107/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25498" source="XF">newsletter-script-sql-injection(25498)</ref>
      <ref url="http://www.securityfocus.com/bid/17304" source="BID">17304</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430375/100/0/threaded" source="BUGTRAQ">20060407 [eVuln] newsletter - sourceworkshop SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/24229" source="OSVDB">24229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceworkshop" name="newsletter">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1534" published="2006-03-30" name="CVE-2006-1534" modified="2011-03-07" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Succesful exploitation of this vulnerability requires the "magic_quotes_gpc" parameter to be disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1151" source="VUPEN">ADV-2006-1151</ref>
      <ref url="http://secunia.com/advisories/19413" source="SECUNIA" adv="1">19413</ref>
      <ref url="http://evuln.com/vulns/109/summary.html" source="MISC">http://evuln.com/vulns/109/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25502" source="XF">nullnews-multiple-sql-injection(25502)</ref>
      <ref url="http://www.securityfocus.com/bid/17300" source="BID">17300</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430298/100/0/threaded" source="BUGTRAQ">20060408 [eVuln] Null news SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/24242" source="OSVDB">24242</ref>
      <ref url="http://www.osvdb.org/24241" source="OSVDB">24241</ref>
      <ref url="http://www.osvdb.org/24240" source="OSVDB">24240</ref>
      <ref url="http://securityreason.com/securityalert/682" source="SREASON">682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="null_news" name="null_news">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1535" published="2006-03-30" name="CVE-2006-1535" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17307" source="BID">17307</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429259/100/0/threaded" source="BUGTRAQ">20060328 PhxContacts &lt;= 0.93.1 beta Multiple SQL injection &amp; xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phoetux.net" name="phxcontacts">
        <vers num="0.93" />
        <vers num="0.93.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1536" published="2006-03-30" name="CVE-2006-1536" modified="2008-09-05" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17306" source="BID">17306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429259/100/0/threaded" source="BUGTRAQ" adv="1">20060328 PhxContacts &lt;= 0.93.1 beta Multiple SQL injection &amp; xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phoetux.net" name="phxcontacts">
        <vers num="0.93" />
        <vers num="0.93.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1537" published="2006-03-30" name="CVE-2006-1537" modified="2008-09-05" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429267/100/0/threaded" source="BUGTRAQ" adv="1">20060329 Full path disclosure in Webcalendar 1.1.0-CVS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25539" source="XF">webcalendar-multiple-path-disclosure(25539)</ref>
      <ref url="http://www.osvdb.org/24536" source="OSVDB">24536</ref>
      <ref url="http://www.osvdb.org/24535" source="OSVDB">24535</ref>
      <ref url="http://www.osvdb.org/24534" source="OSVDB">24534</ref>
      <ref url="http://www.osvdb.org/24533" source="OSVDB">24533</ref>
      <ref url="http://www.osvdb.org/24532" source="OSVDB">24532</ref>
      <ref url="http://www.osvdb.org/24531" source="OSVDB">24531</ref>
      <ref url="http://www.osvdb.org/24530" source="OSVDB">24530</ref>
      <ref url="http://www.osvdb.org/24529" source="OSVDB">24529</ref>
      <ref url="http://www.osvdb.org/24528" source="OSVDB">24528</ref>
      <ref url="http://www.osvdb.org/24527" source="OSVDB">24527</ref>
      <ref url="http://www.osvdb.org/24526" source="OSVDB">24526</ref>
      <ref url="http://www.osvdb.org/24525" source="OSVDB">24525</ref>
      <ref url="http://www.osvdb.org/24524" source="OSVDB">24524</ref>
      <ref url="http://www.osvdb.org/24523" source="OSVDB">24523</ref>
      <ref url="http://www.osvdb.org/24522" source="OSVDB">24522</ref>
      <ref url="http://securityreason.com/securityalert/651" source="SREASON">651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1538" published="2006-03-30" name="CVE-2006-1538" modified="2008-09-05" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.</descript>
    </desc>
    <sols>
      <sol source="nvd">Physical access to the device or hardware token is required to perform
the attack.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429253/100/0/threaded" source="BUGTRAQ" adv="1">20060329 [HV-INFO] Enova hardware encryption: false sense of security</ref>
      <ref url="http://www.hexview.com/docs/20060328-1.txt" source="MISC">http://www.hexview.com/docs/20060328-1.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25527" source="XF">enova-xwall-insecure-encryption-key(25527)</ref>
      <ref url="http://securityreason.com/securityalert/648" source="SREASON">648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enova" name="x-wall_asic">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1539" published="2006-03-30" name="CVE-2006-1539" modified="2008-09-05" discovered="2006-02-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17308" source="BID" patch="1">17308</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-26</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=122399" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=122399</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25611" source="XF">bsdgames-tetrisbsd-checkscores-bo(25611)</ref>
      <ref url="http://www.osvdb.org/24261" source="OSVDB">24261</ref>
      <ref url="http://secunia.com/advisories/19442" source="SECUNIA">19442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsd-games" name="tetris-bsd">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1540" published="2006-03-30" name="CVE-2006-1540" modified="2011-09-20" discovered="2006-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt.  NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/609868" source="CERT-VN">VU#609868</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27609" source="XF">office-property-string-bo(27609)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27607" source="XF">office-string-parse-bo(27607)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2756" source="VUPEN" adv="1">ADV-2006-2756</ref>
      <ref url="http://www.securityfocus.com/bid/18889" source="BID">18889</ref>
      <ref url="http://www.securityfocus.com/bid/17252" source="BID">17252</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439697/100/0/threaded" source="BUGTRAQ">20060710 SYMSA-2006-007: Microsoft Office Malformed String Parsing Vulnerability</ref>
      <ref url="http://www.osvdb.org/27150" source="OSVDB">27150</ref>
      <ref url="http://www.milw0rm.com/exploits/1615" source="MILW0RM">1615</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-038.mspx" source="MS">MS06-038</ref>
      <ref url="http://securitytracker.com/id?1015855" source="SECTRACK">1015855</ref>
      <ref url="http://secunia.com/advisories/21012" source="SECUNIA">21012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:639" source="OVAL" sig="1">oval:org.mitre.oval:def:639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::korean" />
        <vers num="2000" edition="::japanese" />
        <vers num="2000" edition="::chinese" />
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":student_teacher" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp1" />
        <vers num="xp" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1541" published="2006-03-30" name="CVE-2006-1541" modified="2011-03-07" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1164" source="VUPEN">ADV-2006-1164</ref>
      <ref url="http://www.nukedx.com/?viewdoc=22" source="MISC">http://www.nukedx.com/?viewdoc=22</ref>
      <ref url="http://milw0rm.com/exploits/1623" source="MILW0RM">1623</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25544" source="XF">ezaspsite-default-sql-injection(25544)</ref>
      <ref url="http://www.securityfocus.com/bid/17309" source="BID">17309</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429487/100/0/threaded" source="BUGTRAQ">20060329 EzASPSite &lt;= 2.0 RC3 Remote SQL Injection Exploit Vulnerability.</ref>
      <ref url="http://www.osvdb.org/24256" source="OSVDB">24256</ref>
      <ref url="http://secunia.com/advisories/19441" source="SECUNIA">19441</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114367573519326&amp;w=2" source="FULLDISC">20060329 EzASPSite &lt;= 2.0 RC3 Remote SQL Injection Exploit Vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezaspsite" name="ezaspsite">
        <vers prev="1" num="2.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1542" published="2006-03-30" name="CVE-2006-1542" modified="2009-01-23" discovered="2006-03-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function.  NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the Python is running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0629.html" source="REDHAT">RHSA-2008:0629</ref>
      <ref url="http://www.gotfault.net/research/exploit/gexp-python.py" source="MISC">http://www.gotfault.net/research/exploit/gexp-python.py</ref>
      <ref url="http://secunia.com/advisories/31492" source="SECUNIA">31492</ref>
      <ref url="http://milw0rm.com/exploits/1591" source="MILW0RM">1591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.4" />
        <vers prev="1" num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1543" published="2006-03-30" name="CVE-2006-1543" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1173" source="VUPEN">ADV-2006-1173</ref>
      <ref url="http://www.evuln.com/vulns/112" source="MISC">http://www.evuln.com/vulns/112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25529" source="XF">vnews-adminnews-sql-injection(25529)</ref>
      <ref url="http://www.securityfocus.com/bid/17316" source="BID">17316</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430674/100/0/threaded" source="BUGTRAQ">20060411 [eVuln] VNews Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24274" source="OSVDB">24274</ref>
      <ref url="http://www.osvdb.org/24273" source="OSVDB">24273</ref>
      <ref url="http://secunia.com/advisories/19435" source="SECUNIA">19435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts" name="vnews">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1544" published="2006-03-30" name="CVE-2006-1544" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1173" source="VUPEN">ADV-2006-1173</ref>
      <ref url="http://www.evuln.com/vulns/112" source="MISC">http://www.evuln.com/vulns/112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25530" source="XF">vnews-news-xss(25530)</ref>
      <ref url="http://www.securityfocus.com/bid/17317" source="BID">17317</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430674/100/0/threaded" source="BUGTRAQ">20060411 [eVuln] VNews Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24275" source="OSVDB">24275</ref>
      <ref url="http://secunia.com/advisories/19435" source="SECUNIA">19435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts" name="vnews">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1545" published="2006-03-30" name="CVE-2006-1545" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1173" source="VUPEN">ADV-2006-1173</ref>
      <ref url="http://www.evuln.com/vulns/112" source="MISC">http://www.evuln.com/vulns/112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25531" source="XF">vnews-config-file-include(25531)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430674/100/0/threaded" source="BUGTRAQ">20060411 [eVuln] VNews Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24276" source="OSVDB">24276</ref>
      <ref url="http://secunia.com/advisories/19435" source="SECUNIA">19435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts" name="vnews">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1546" published="2006-03-30" name="CVE-2006-1546" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1205" source="VUPEN">ADV-2006-1205</ref>
      <ref url="http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html" source="CONFIRM">http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html</ref>
      <ref url="http://mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%3c20060121221800.15814.qmail@web32607.mail.mud.yahoo.com%3e" source="MLIST">[struts-user] 20060121 Validation Security Hole?</ref>
      <ref url="http://mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%3cdr169r$623$2@sea.gmane.org%3e" source="MLIST">[struts-devel] 20060122 Re: Validation Security Hole?</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=38374" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=38374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25612" source="XF">struts-iscancelled-security-bypass(25612)</ref>
      <ref url="http://www.securityfocus.com/bid/17342" source="BID">17342</ref>
      <ref url="http://securitytracker.com/id?1015856" source="SECTRACK">1015856</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19493" source="SECUNIA">19493</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers prev="1" num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1547" published="2006-03-30" name="CVE-2006-1547" modified="2011-03-07" discovered="2006-02-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html" source="CONFIRM" patch="1" adv="1">http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1205" source="VUPEN">ADV-2006-1205</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=38534" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=38534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25613" source="XF">struts-actionform-dos(25613)</ref>
      <ref url="http://www.securityfocus.com/bid/17342" source="BID">17342</ref>
      <ref url="http://securitytracker.com/id?1015856" source="SECTRACK">1015856</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19493" source="SECUNIA">19493</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers num="1.2.7" />
        <vers prev="1" num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1548" published="2006-03-30" name="CVE-2006-1548" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.apache.org/struts/browse/STR-2781" source="CONFIRM">https://issues.apache.org/struts/browse/STR-2781</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1205" source="VUPEN">ADV-2006-1205</ref>
      <ref url="http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html" source="CONFIRM">http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=38749" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=38749</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25614" source="XF">struts-lookupmap-xss(25614)</ref>
      <ref url="http://www.securityfocus.com/bid/17342" source="BID">17342</ref>
      <ref url="http://securitytracker.com/id?1015856" source="SECTRACK">1015856</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19493" source="SECUNIA">19493</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers prev="1" num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1549" published="2006-04-10" name="CVE-2006-1549" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function.  NOTE: it has been reported by a reliable third party that some later versions are also affected.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to PHP 5.1.3-RC3</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25704" source="XF">php-function-dos(25704)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1290" source="VUPEN" adv="1">ADV-2006-1290</ref>
      <ref url="http://www.securityfocus.com/bid/22766" source="BID">22766</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431018/100/0/threaded" source="BUGTRAQ">20060414 Re: Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430742/100/0/threaded" source="BUGTRAQ">20060412 Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430598/100/0/threaded" source="BUGTRAQ">20060410 Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430453/100/0/threaded" source="BUGTRAQ">20060409 function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-02-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-02-2007.html</ref>
      <ref url="http://www.osvdb.org/24485" source="OSVDB">24485</ref>
      <ref url="http://securitytracker.com/id?1015880" source="SECTRACK">1015880</ref>
      <ref url="http://securityreason.com/securityalert/676" source="SREASON">676</ref>
      <ref url="http://securityreason.com/securityalert/2312" source="SREASON">2312</ref>
      <ref url="http://securityreason.com/achievement_securityalert/35" source="SREASONRES">20060408 function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.2" />
        <vers prev="1" num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1550" published="2006-03-30" name="CVE-2006-1550" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17310" source="BID" patch="1">17310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25566" source="XF">diaxfig-xfig-import-bo(25566)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-266-1" source="UBUNTU">USN-266-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429357/100/0/threaded" source="BUGTRAQ">20060329 Buffer overflows in Dia XFig import</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0280.html" source="REDHAT">RHSA-2006:0280</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00021.html" source="FEDORA">FEDORA-2006-261</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:062" source="MANDRIVA">MDKSA-2006:062</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-14.xml" source="GENTOO">GLSA-200604-14</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1025" source="DEBIAN">DSA-1025</ref>
      <ref url="http://securitytracker.com/id?1015853" source="SECTRACK">1015853</ref>
      <ref url="http://secunia.com/advisories/19959" source="SECUNIA" adv="1">19959</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA" adv="1">19897</ref>
      <ref url="http://secunia.com/advisories/19765" source="SECUNIA" adv="1">19765</ref>
      <ref url="http://secunia.com/advisories/19546" source="SECUNIA" adv="1">19546</ref>
      <ref url="http://secunia.com/advisories/19543" source="SECUNIA" adv="1">19543</ref>
      <ref url="http://secunia.com/advisories/19507" source="SECUNIA" adv="1">19507</ref>
      <ref url="http://secunia.com/advisories/19505" source="SECUNIA" adv="1">19505</ref>
      <ref url="http://secunia.com/advisories/19469" source="SECUNIA" adv="1">19469</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10361" source="OVAL">oval:org.mitre.oval:def:10361</ref>
      <ref url="http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html" source="MLIST">[dia-list] 20060329 Vulnerability in xfig import code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dia" name="dia">
        <vers num="0.87" />
        <vers num="0.88.1" />
        <vers num="0.91" />
        <vers num="0.92.2" />
        <vers num="0.93" />
        <vers num="0.94" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1551" published="2006-04-13" name="CVE-2006-1551" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $method and (2) $args parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1353" source="VUPEN">ADV-2006-1353</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2006-001.php" source="MISC" adv="1">http://www.redteam-pentesting.de/advisories/rt-sa-2006-001.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25859" source="XF">pajax-pajaxcalldispatcher-code-execution(25859)</ref>
      <ref url="http://www.securityfocus.com/bid/17519" source="BID">17519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431029/100/0/threaded" source="BUGTRAQ">20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref>
      <ref url="http://www.osvdb.org/24618" source="OSVDB">24618</ref>
      <ref url="http://secunia.com/advisories/19653" source="SECUNIA">19653</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0270.html" source="FULLDISC">20060413 PAJAX Remote file inclusion  and File Inclusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="georges_auberger" name="pajax">
        <vers num="0.5.0" />
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1552" published="2006-03-31" name="CVE-2006-1552" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26412" source="XF">macos-imageio-jpeg-bo(26412)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.securityfocus.com/bid/17321" source="BID">17321</ref>
      <ref url="http://www.osvdb.org/25597" source="OSVDB">25597</ref>
      <ref url="http://drunkenblog.com/drunkenblog-archives/000760.html" source="MISC">http://drunkenblog.com/drunkenblog-archives/000760.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.3" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_pre" />
        <vers num="beta2" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1553" published="2006-03-31" name="CVE-2006-1553" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
      <descript source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17281" source="BID">17281</ref>
      <ref url="http://securitytracker.com/id?1015836" source="SECTRACK">1015836</ref>
      <ref url="http://secunia.com/advisories/19420" source="SECUNIA" adv="1">19420</ref>
      <ref url="http://evuln.com/vulns/106/description.html" source="MISC">http://evuln.com/vulns/106/description.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25456" source="XF">vsns-lemon-finalfunctions-sql-injection(25456)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430345/100/0/threaded" source="BUGTRAQ">20060406 [eVuln] VSNS Lemon Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24211" source="OSVDB">24211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tachyon" name="vsns_lemon">
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1554" published="2006-03-31" name="CVE-2006-1554" modified="2008-09-05" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19420" source="SECUNIA" adv="1">19420</ref>
      <ref url="http://evuln.com/vulns/106/description.html" source="MISC">http://evuln.com/vulns/106/description.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25457" source="XF">vsns-lemon-name-xss(25457)</ref>
      <ref url="http://www.securityfocus.com/bid/17395" source="BID">17395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430345/100/0/threaded" source="BUGTRAQ">20060406 [eVuln] VSNS Lemon Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24212" source="OSVDB">24212</ref>
      <ref url="http://securitytracker.com/id?1015836" source="SECTRACK">1015836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tachyon" name="vsns_lemon">
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1555" published="2006-03-31" name="CVE-2006-1555" modified="2008-09-05" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">VSNS Lemon 3.2.0 allows remote attackers to bypass authentication and access password-protected articles by setting the vsns[topic_id] cookie to the targeted topic.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17396" source="BID">17396</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430345/100/0/threaded" source="BUGTRAQ">20060406 [eVuln] VSNS Lemon Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24213" source="OSVDB">24213</ref>
      <ref url="http://securitytracker.com/id?1015836" source="SECTRACK">1015836</ref>
      <ref url="http://secunia.com/advisories/19420" source="SECUNIA" adv="1">19420</ref>
      <ref url="http://evuln.com/vulns/106/description.html" source="MISC">http://evuln.com/vulns/106/description.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25459" source="XF">vsns-lemon-cookie-auth-bypass(25459)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tachyon" name="vsns_lemon">
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1556" published="2006-03-31" name="CVE-2006-1556" modified="2008-09-05" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) CatName, (2) CaricatierID, or (3) CatID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17289" source="BID">17289</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429095/100/0/threaded" source="BUGTRAQ" adv="1">20060328 XSS in AL-Caricatier</ref>
      <ref url="http://secunia.com/advisories/17292" source="SECUNIA" adv="1">17292</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25493" source="XF">alcaricatier-viewcaricatier-xss(25493)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="al-caricatier" name="al-caricatier">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1557" published="2006-03-31" name="CVE-2006-1557" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1188" source="VUPEN">ADV-2006-1188</ref>
      <ref url="http://www.securityfocus.com/bid/17322" source="BID">17322</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429359/100/0/threaded" source="BUGTRAQ" adv="1">20060330 X-Changer &lt;=v0.2 Demo SQL injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25549" source="XF">xchanger-index-sql-injection(25549)</ref>
      <ref url="http://www.osvdb.org/24288" source="OSVDB">24288</ref>
      <ref url="http://securityreason.com/securityalert/654" source="SREASON">654</ref>
      <ref url="http://secunia.com/advisories/19459" source="SECUNIA">19459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skintech" name="x-changer">
        <vers num="0.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1558" published="2006-03-31" name="CVE-2006-1558" modified="2011-03-07" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1158" source="VUPEN">ADV-2006-1158</ref>
      <ref url="http://www.securityfocus.com/bid/17297" source="BID">17297</ref>
      <ref url="http://www.osvdb.org/24243" source="OSVDB">24243</ref>
      <ref url="http://secunia.com/advisories/19443" source="SECUNIA" adv="1">19443</ref>
      <ref url="http://osvdb.org/ref/24/24243-script_index.txt" source="MISC">http://osvdb.org/ref/24/24243-script_index.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php_script_index">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1559" published="2006-03-31" name="CVE-2006-1559" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1158" source="VUPEN">ADV-2006-1158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php_script_index">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1560" published="2006-03-31" name="CVE-2006-1560" modified="2011-03-07" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts.  NOTE: portions of the description details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25512" source="XF">phpnewsmanager-multiple-sql-injection(25512)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1152" source="VUPEN">ADV-2006-1152</ref>
      <ref url="http://www.securityfocus.com/bid/17301" source="BID">17301</ref>
      <ref url="http://evuln.com/vulns/110" source="MISC">http://evuln.com/vulns/110</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430478/100/0/threaded" source="BUGTRAQ">20060410 [eVuln] phpNewsManager Multiple SQL Injections</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430311/100/0/threaded" source="BUGTRAQ">20060408 [eVuln] phpNewsManager Multiple SQL Injections</ref>
      <ref url="http://www.osvdb.org/24268" source="OSVDB">24268</ref>
      <ref url="http://www.osvdb.org/24267" source="OSVDB">24267</ref>
      <ref url="http://www.osvdb.org/24266" source="OSVDB">24266</ref>
      <ref url="http://www.osvdb.org/24265" source="OSVDB">24265</ref>
      <ref url="http://securityreason.com/securityalert/680" source="SREASON">680</ref>
      <ref url="http://secunia.com/advisories/19391" source="SECUNIA">19391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skintech" name="phpnewsmanager">
        <vers num="1.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1561" published="2006-03-31" name="CVE-2006-1561" modified="2011-03-07" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is set to off.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1174" source="VUPEN">ADV-2006-1174</ref>
      <ref url="http://evuln.com/vulns/111" source="MISC">http://evuln.com/vulns/111</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25519" source="XF">vbook-index-sql-injection(25519)</ref>
      <ref url="http://www.securityfocus.com/bid/17320" source="BID">17320</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430624/100/0/threaded" source="BUGTRAQ">20060411 [eVuln] [V]Book Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24270" source="OSVDB">24270</ref>
      <ref url="http://securityreason.com/securityalert/696" source="SREASON">696</ref>
      <ref url="http://secunia.com/advisories/19448" source="SECUNIA">19448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts" name="vbook">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1562" published="2006-03-31" name="CVE-2006-1562" modified="2011-03-07" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) autor, (2) www, (3) temat, and (4) tresc parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1174" source="VUPEN">ADV-2006-1174</ref>
      <ref url="http://evuln.com/vulns/111" source="MISC">http://evuln.com/vulns/111</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25521" source="XF">vbook-index-xss(25521)</ref>
      <ref url="http://www.securityfocus.com/bid/17319" source="BID">17319</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430624/100/0/threaded" source="BUGTRAQ">20060411 [eVuln] [V]Book Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24271" source="OSVDB">24271</ref>
      <ref url="http://secunia.com/advisories/19448" source="SECUNIA">19448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts" name="vbook">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1563" published="2006-03-31" name="CVE-2006-1563" modified="2011-03-07" discovered="2006-03-29" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into the config file, which is included other [V]Book scripts.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is set to off.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1174" source="VUPEN">ADV-2006-1174</ref>
      <ref url="http://evuln.com/vulns/111" source="MISC">http://evuln.com/vulns/111</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25522" source="XF">vbook-config-file-include(25522)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430624/100/0/threaded" source="BUGTRAQ">20060411 [eVuln] [V]Book Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24272" source="OSVDB">24272</ref>
      <ref url="http://secunia.com/advisories/19448" source="SECUNIA">19448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts" name="vbook">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1564" published="2006-03-31" name="CVE-2006-1564" modified="2008-09-05" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17288" source="BID" patch="1">17288</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359234" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359234</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25680" source="XF">libapache2-svn-file-upload(25680)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1565" published="2006-03-31" name="CVE-2006-1565" modified="2008-09-05" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17288" source="BID" patch="1">17288</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359239" source="MISC" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359239</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25681" source="XF">libgpib-perl-buildd-file-upload(25681)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1566" published="2006-03-31" name="CVE-2006-1566" modified="2008-09-05" discovered="2006-03-27" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17288" source="BID" patch="1">17288</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359241" source="MISC" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359241</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25682" source="XF">libtunepimp-perl-buildd-file-upload(25682)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1567" published="2006-03-31" name="CVE-2006-1567" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1185" source="VUPEN">ADV-2006-1185</ref>
      <ref url="http://secunia.com/advisories/19467" source="SECUNIA" adv="1">19467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25564" source="XF">sitesearch-indexer-searchfield-xss(25564)</ref>
      <ref url="http://www.securityfocus.com/bid/17332" source="BID">17332</ref>
      <ref url="http://www.osvdb.org/24289" source="OSVDB">24289</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/sitesearch-indexer-35-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/sitesearch-indexer-35-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitesearch" name="indexer">
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1568" published="2006-03-31" name="CVE-2006-1568" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) email, (2) location, or (3) website parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1186" source="VUPEN">ADV-2006-1186</ref>
      <ref url="http://secunia.com/advisories/19475" source="SECUNIA" adv="1">19475</ref>
      <ref url="http://evuln.com/vulns/115/summary.html" source="MISC">http://evuln.com/vulns/115/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25577" source="XF">redcms-register-xss(25577)</ref>
      <ref url="http://www.securityfocus.com/bid/17336" source="BID">17336</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431001/100/0/threaded" source="BUGTRAQ">20060413 [eVuln] RedCMS Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24296" source="OSVDB">24296</ref>
      <ref url="http://securityreason.com/securityalert/708" source="SREASON">708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redcms" name="redcms">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1569" published="2006-03-31" name="CVE-2006-1569" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1186" source="VUPEN">ADV-2006-1186</ref>
      <ref url="http://secunia.com/advisories/19475" source="SECUNIA" adv="1">19475</ref>
      <ref url="http://evuln.com/vulns/115/summary.html" source="MISC">http://evuln.com/vulns/115/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25578" source="XF">redcms-multiple-sql-injection(25578)</ref>
      <ref url="http://www.securityfocus.com/bid/17336" source="BID">17336</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431001/100/0/threaded" source="BUGTRAQ">20060413 [eVuln] RedCMS Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24299" source="OSVDB">24299</ref>
      <ref url="http://www.osvdb.org/24298" source="OSVDB">24298</ref>
      <ref url="http://www.osvdb.org/24297" source="OSVDB">24297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redcms" name="redcms">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1570" published="2006-03-31" name="CVE-2006-1570" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=406021" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=406021</ref>
      <ref url="http://secunia.com/advisories/19474" source="SECUNIA" patch="1" adv="1">19474</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1183" source="VUPEN">ADV-2006-1183</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25568" source="XF">esqlanelapse-xss(25568)</ref>
      <ref url="http://www.securityfocus.com/bid/17331" source="BID">17331</ref>
      <ref url="http://www.osvdb.org/24300" source="OSVDB">24300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esqlanelapse" name="esqlanelapse">
        <vers num="2.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1571" published="2006-03-31" name="CVE-2006-1571" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires "magic_quotes_gpc" to be disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1182" source="VUPEN">ADV-2006-1182</ref>
      <ref url="http://secunia.com/advisories/19476" source="SECUNIA" adv="1">19476</ref>
      <ref url="http://evuln.com/vulns/114/summary.html" source="MISC">http://evuln.com/vulns/114/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25565" source="XF">qlitenews-loginprocess-sql-injection(25565)</ref>
      <ref url="http://www.securityfocus.com/bid/17333" source="BID">17333</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430873/100/0/threaded" source="BUGTRAQ">20060413 [eVuln] qliteNews SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/24301" source="OSVDB">24301</ref>
      <ref url="http://securityreason.com/securityalert/701" source="SREASON">701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="r2xdesign" name="qlitenews">
        <vers num="2005-07-01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1572" published="2006-03-31" name="CVE-2006-1572" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1181" source="VUPEN">ADV-2006-1181</ref>
      <ref url="http://www.securityfocus.com/bid/17324" source="BID">17324</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429474/100/0/threaded" source="BUGTRAQ">20060330 Oxygen&lt;=1.x.x SQL injection</ref>
      <ref url="http://secunia.com/advisories/19481" source="SECUNIA" adv="1">19481</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25570" source="XF">oxygen-post-sql-injection(25570)</ref>
      <ref url="http://www.osvdb.org/24287" source="OSVDB">24287</ref>
      <ref url="http://securityreason.com/securityalert/658" source="SREASON">658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="o2php.com" name="oxygen">
        <vers num="1.0.11" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1573" published="2006-03-31" name="CVE-2006-1573" modified="2008-09-05" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17323" source="BID">17323</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429395/100/0/threaded" source="BUGTRAQ">20060330 MediaSlash Gallery 'rub' variable Remote File inlcusion Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25583" source="XF">mediaslash-index-file-include(25583)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434419/100/0/threaded" source="BUGTRAQ">20060516 Re: MediaSlash Gallery 'rub' variable Remote File inlcusion Vulnerability</ref>
      <ref url="http://www.osvdb.org/24313" source="OSVDB">24313</ref>
      <ref url="http://securityreason.com/securityalert/657" source="SREASON">657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediaslash.com" name="mediaslash_gallery">
        <vers num="0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1574" published="2006-03-31" name="CVE-2006-1574" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patch :
http://www.hitachi-support.com/security_e/vuls_e/HS06-005_e/index-e.html</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-005_e/index-e.html" source="CONFIRM" patch="1">http://www.hitachi-support.com/security_e/vuls_e/HS06-005_e/index-e.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1180" source="VUPEN">ADV-2006-1180</ref>
      <ref url="http://secunia.com/advisories/19483" source="SECUNIA" adv="1">19483</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25574" source="XF">groupmax-www-xss(25574)</ref>
      <ref url="http://www.securityfocus.com/bid/17337" source="BID">17337</ref>
      <ref url="http://www.osvdb.org/24295" source="OSVDB">24295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="groupmax_world_wide_web">
        <vers num="2" />
        <vers num="3" />
      </prod>
      <prod vendor="hitachi" name="groupmax_world_wide_web_desktop">
        <vers num="5" />
        <vers num="6" />
      </prod>
      <prod vendor="hitachi" name="groupmax_world_wide_web_desktop_scheduler">
        <vers num="5" />
      </prod>
      <prod vendor="hitachi" name="groupmax_world_wide_web_scheduler">
        <vers num="2" />
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1575" published="2006-04-02" name="CVE-2006-1575" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17335" source="BID">17335</ref>
      <ref url="http://secunia.com/advisories/19479" source="SECUNIA" adv="1">19479</ref>
      <ref url="http://evuln.com/vulns/113/description.html" source="MISC">http://evuln.com/vulns/113/description.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25546" source="XF">qlnews-news-xss(25546)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430741/100/0/threaded" source="BUGTRAQ">20060412 [eVuln] QLnews XSS and PHP Code Insertion Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24290" source="OSVDB">24290</ref>
      <ref url="http://securityreason.com/securityalert/699" source="SREASON">699</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts.pl" name="qlnews">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1576" published="2006-04-02" name="CVE-2006-1576" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17335" source="BID">17335</ref>
      <ref url="http://secunia.com/advisories/19479" source="SECUNIA" adv="1">19479</ref>
      <ref url="http://evuln.com/vulns/113/description.html" source="MISC">http://evuln.com/vulns/113/description.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25548" source="XF">qlnews-config-file-include(25548)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430741/100/0/threaded" source="BUGTRAQ">20060412 [eVuln] QLnews XSS and PHP Code Insertion Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24291" source="OSVDB">24291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vscripts.pl" name="qlnews">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1577" published="2006-04-02" name="CVE-2006-1577" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2) start_year, and (3) start_month parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1184" source="VUPEN">ADV-2006-1184</ref>
      <ref url="http://www.securityfocus.com/bid/17326" source="BID">17326</ref>
      <ref url="http://secunia.com/advisories/19471" source="SECUNIA" adv="1">19471</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25579" source="XF">mantis-viewallset-script-xss(25579)</ref>
      <ref url="http://www.osvdb.org/24292" source="OSVDB">24292</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1133" source="DEBIAN">DSA-1133</ref>
      <ref url="http://secunia.com/advisories/21400" source="SECUNIA">21400</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/mantis-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/mantis-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="1.0" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers num="1.0.0_rc4" />
        <vers num="1.0.0a1" />
        <vers num="1.0.0a2" />
        <vers num="1.0.0a3" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1578" published="2006-04-02" name="CVE-2006-1578" modified="2008-11-03" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25571" source="XF">keystonedls-subjecttypeid-sql-injection(25571)</ref>
      <ref url="http://pridels0.blogspot.com/2006/03/keystone-dls-sql-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/03/keystone-dls-sql-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="index_data_aps" name="keystone_digital_library_suite">
        <vers prev="1" num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1579" published="2006-04-02" name="CVE-2006-1579" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in topics.php in Dynamic Bulletin Board System (DbbS) 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the limite parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25584" source="XF">dbbs-topics-sql-injection(25584)</ref>
      <ref url="http://www.securityfocus.com/bid/17338" source="BID">17338</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429512/100/0/threaded" source="BUGTRAQ">20060331 DbbS&lt;=2.0-alpha SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbbs" name="dbbs">
        <vers prev="1" num="2.0-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1580" published="2006-04-02" name="CVE-2006-1580" modified="2011-03-07" discovered="2006-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1195" source="VUPEN">ADV-2006-1195</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25601" source="XF">bugzero-query-edit-xss(25601)</ref>
      <ref url="http://www.securityfocus.com/bid/17351" source="BID">17351</ref>
      <ref url="http://www.osvdb.org/24329" source="OSVDB">24329</ref>
      <ref url="http://www.osvdb.org/24328" source="OSVDB">24328</ref>
      <ref url="http://secunia.com/advisories/19492" source="SECUNIA">19492</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="websina" name="bugzero">
        <vers prev="1" num="4.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1581" published="2006-04-02" name="CVE-2006-1581" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.silitix.com/bnb.php" source="MISC">http://www.silitix.com/bnb.php</ref>
      <ref url="http://www.securityfocus.com/bid/17345" source="BID">17345</ref>
      <ref url="http://securitytracker.com/id?1015854" source="SECTRACK">1015854</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25617" source="XF">blanknberg-index-directory-traversal(25617)</ref>
      <ref url="http://www.osvdb.org/24373" source="OSVDB">24373</ref>
      <ref url="http://secunia.com/advisories/19520" source="SECUNIA">19520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blanknberg" name="blanknberg">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1582" published="2006-04-02" name="CVE-2006-1582" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter.  NOTE: this might be resultant from the directory traversal issue.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.silitix.com/bnb.php" source="MISC">http://www.silitix.com/bnb.php</ref>
      <ref url="http://www.securityfocus.com/bid/17346" source="BID">17346</ref>
      <ref url="http://securitytracker.com/id?1015854" source="SECTRACK">1015854</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25618" source="XF">blanknberg-index-xss(25618)</ref>
      <ref url="http://www.osvdb.org/24374" source="OSVDB">24374</ref>
      <ref url="http://secunia.com/advisories/19520" source="SECUNIA">19520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blanknberg" name="blanknberg">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1583" published="2006-04-02" name="CVE-2006-1583" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter.  NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17334" source="BID">17334</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429535/100/0/threaded" source="BUGTRAQ">20060331 Warcraft III Replay Parser Script Remote Command Exucetion Vulnerability And Cross-Site Scripting Attacking</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25685" source="XF">warcraft3-replay-parser-index-xss(25685)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juliusz_julas_gonera" name="warcraft_iii_replay_parser_php">
        <vers num="1.8c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1584" published="2006-04-02" name="CVE-2006-1584" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads.  NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17334" source="BID">17334</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429535/100/0/threaded" source="BUGTRAQ">20060331 Warcraft III Replay Parser Script Remote Command Exucetion Vulnerability And Cross-Site Scripting Attacking</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25686" source="XF">warcraft3-replay-parser-index-file-include(25686)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juliusz_julas_gonera" name="warcraft_iii_replay_parser_php">
        <vers num="1.8c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1585" published="2006-04-02" name="CVE-2006-1585" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MonAlbum 0.8.7 allow remote attackers to execute arbitrary SQL commands via (1) the pc parameter in (a) index.php and (2) pnom, (3) pcourriel, and (4) pcommentaire parameters in (b) image_agrandir.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25572" source="XF">monalbum-image-imageagrandir-sql-injection(25572)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1206" source="VUPEN">ADV-2006-1206</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429475/100/0/threaded" source="BUGTRAQ">20060331 MonAlbum 0.8.7 SQL Injection</ref>
      <ref url="http://www.securityfocus.com/bid/17327" source="BID">17327</ref>
      <ref url="http://www.bash-x.net/undef/adv/monalbum.html" source="MISC">http://www.bash-x.net/undef/adv/monalbum.html</ref>
      <ref url="http://securityreason.com/securityalert/660" source="SREASON">660</ref>
      <ref url="http://secunia.com/advisories/19503" source="SECUNIA">19503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3dsrc" name="monalbum">
        <vers num="0.8.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1586" published="2006-04-02" name="CVE-2006-1586" modified="2011-03-07" discovered="2006-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1190" source="VUPEN">ADV-2006-1190</ref>
      <ref url="http://www.securityfocus.com/bid/17347" source="BID">17347</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429607/100/0/threaded" source="BUGTRAQ">20060401 SiteMan &lt;= All version SQL injection in admin_login.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25595" source="XF">siteman-adminlogin-sql-injection(25595)</ref>
      <ref url="http://www.osvdb.org/24362" source="OSVDB">24362</ref>
      <ref url="http://secunia.com/advisories/19500" source="SECUNIA">19500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="internet_solutions_professionals" name="site_man">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1587" published="2006-04-03" name="CVE-2006-1587" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015847" source="SECTRACK">1015847</ref>
      <ref url="http://secunia.com/advisories/19465" source="SECUNIA" adv="1">19465</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25581" source="XF">bsd-mailrc-insecure-permissions(25581)</ref>
      <ref url="http://www.osvdb.org/24258" source="OSVDB">24258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1588" published="2006-04-03" name="CVE-2006-1588" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17312" source="BID" patch="1" adv="1">17312</ref>
      <ref url="http://securitytracker.com/id?1015846" source="SECTRACK" patch="1">1015846</ref>
      <ref url="http://secunia.com/advisories/19464" source="SECUNIA" adv="1">19464</ref>
      <ref url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc" source="NETBSD" adv="1">NetBSD-SA2006-005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25582" source="XF">bsd-ifbridge-information-disclosure(25582)</ref>
      <ref url="http://www.osvdb.org/24262" source="OSVDB">24262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1589" published="2006-04-03" name="CVE-2006-1589" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which triggers a null dereference.</descript>
    </desc>
    <sols>
      <sol source="nvd">The NetBSD 2.x versions are only affected if the kernel is compiled with the USE_TOPDOWN_VM option (not default in generic kernels).</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015848" source="SECTRACK" patch="1">1015848</ref>
      <ref url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-008.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA2006-008</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25690" source="XF">netbsd-elfloadfile-dos(25690)</ref>
      <ref url="http://www.osvdb.org/24576" source="OSVDB">24576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1590" published="2006-04-03" name="CVE-2006-1590" modified="2011-03-07" discovered="2006-03-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask parameter to base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php within BASE, or (d) query string to acid_main.php in ACID, which causes the request URI ($_SERVER['REQUEST_URI']) to be inserted into a refresh operation.</descript>
    </desc>
    <sols>
      <sol source="nvd">Analysis Console for Intrusion Databases - The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem.

Basic Analysis and Security Engine - Upgrade to cvs version or version 1.2.5 (daiga) or higher, as it has been reported to fix this vulnerability. </sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1264" source="VUPEN">ADV-2006-1264</ref>
      <ref url="http://www.osvdb.org/24307" source="OSVDB">24307</ref>
      <ref url="http://www.osvdb.org/20835" source="OSVDB">20835</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=10064470&amp;forum_id=42223" source="MLIST">[secureideas-base-devel] 20060328 3 XSS in BASE 1.2.4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25671" source="XF">base-multiple-scripts-xss(25671)</ref>
      <ref url="http://www.securityfocus.com/bid/17391" source="BID">17391</ref>
      <ref url="http://secunia.com/advisories/19544" source="SECUNIA">19544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kevin_johnson" name="basic_analysis_and_security_engine">
        <vers num="0.9.7" />
        <vers num="0.9.7.1" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.4" />
      </prod>
      <prod vendor="roman_danyliw" name="analysis_console_for_intrusion_databases_(acid)">
        <vers num="0.9.6b23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1591" published="2006-04-03" name="CVE-2006-1591" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25573" source="XF">win-winhlp32-hlp-bo(25573)</ref>
      <ref url="http://www.securityfocus.com/bid/17325" source="BID">17325</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430871/100/0/threaded" source="BUGTRAQ">20060413 Windows Help Heap Overflow</ref>
      <ref url="http://www.open-security.org/advisories/15" source="MISC" adv="1">http://www.open-security.org/advisories/15</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044748.html" source="FULLDISC">20060331 Windows Help Heap Overflow</ref>
      <ref url="http://securityreason.com/securityalert/700" source="SREASON">700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1" />
        <vers num="web" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:enterprise" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp4:enterprise" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:enterprise" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:enterprise" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1592" published="2006-04-03" name="CVE-2006-1592" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the is_client_wad_ok function in w_wad.cpp for (1) Zdaemon 1.08.01 and (2) X-Doom allows remote attackers to execute arbitrary code via a long filename argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1199" source="VUPEN">ADV-2006-1199</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1198" source="VUPEN">ADV-2006-1198</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429521/100/0/threaded" source="BUGTRAQ" adv="1">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref>
      <ref url="http://secunia.com/advisories/19509" source="SECUNIA" adv="1">19509</ref>
      <ref url="http://aluigi.altervista.org/adv/zdaebof-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/zdaebof-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25592" source="XF">zdaemon-isclientwadok-bo(25592)</ref>
      <ref url="http://www.securityfocus.com/bid/17340" source="BID">17340</ref>
      <ref url="http://secunia.com/advisories/19496" source="SECUNIA">19496</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044775.html" source="FULLDISC">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-doom" name="x-doom">
        <vers num="1.06.07" />
      </prod>
      <prod vendor="zdaemon" name="zdaemon">
        <vers num="1.08.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1593" published="2006-04-03" name="CVE-2006-1593" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25593" source="XF">zdaemon-memory-access-dos(25593)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1199" source="VUPEN" adv="1">ADV-2006-1199</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1198" source="VUPEN" adv="1">ADV-2006-1198</ref>
      <ref url="http://www.securityfocus.com/bid/17340" source="BID">17340</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429521/100/0/threaded" source="BUGTRAQ">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref>
      <ref url="http://securityreason.com/securityalert/662" source="SREASON">662</ref>
      <ref url="http://secunia.com/advisories/19509" source="SECUNIA" adv="1">19509</ref>
      <ref url="http://secunia.com/advisories/19496" source="SECUNIA" adv="1">19496</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044775.html" source="FULLDISC">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref>
      <ref url="http://aluigi.altervista.org/adv/zdaebof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/zdaebof-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-doom" name="x-doom">
        <vers num="1.06.07" />
      </prod>
      <prod vendor="zdaemon" name="zdaemon">
        <vers prev="1" num="1.08.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1594" published="2006-04-03" name="CVE-2006-1594" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use ".." (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1187" source="VUPEN">ADV-2006-1187</ref>
      <ref url="http://www.milw0rm.com/exploits/1627" source="MILW0RM">1627</ref>
      <ref url="http://secunia.com/advisories/19461" source="SECUNIA" adv="1">19461</ref>
      <ref url="http://retrogod.altervista.org/claroline_174_incl_xpl.html" source="MISC">http://retrogod.altervista.org/claroline_174_incl_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25561" source="XF">claroline-rqmkhtml-directory-traversal(25561)</ref>
      <ref url="http://www.securityfocus.com/bid/17343" source="BID">17343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.6" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
        <vers num="1.7.2" />
        <vers prev="1" num="1.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1595" published="2006-04-03" name="CVE-2006-1595" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25562" source="XF">claroline-rqmkhtml-xss(25562)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1187" source="VUPEN">ADV-2006-1187</ref>
      <ref url="http://www.securityfocus.com/bid/17344" source="BID">17344</ref>
      <ref url="http://www.osvdb.org/24285" source="OSVDB">24285</ref>
      <ref url="http://secunia.com/advisories/19461" source="SECUNIA" adv="1">19461</ref>
      <ref url="http://retrogod.altervista.org/claroline_174_incl_xpl.html" source="MISC">http://retrogod.altervista.org/claroline_174_incl_xpl.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1905.html" source="FULLDISC">20060331 Re: [Full-disclosure] Claroline &lt;= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod</ref>
      <ref url="http://www.osvdb.org/24284" source="OSVDB">24284</ref>
      <ref url="http://milw0rm.com/exploits/1627" source="MILW0RM">1627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.6" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
        <vers num="1.7.2" />
        <vers prev="1" num="1.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1596" published="2006-04-03" name="CVE-2006-1596" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute arbitrary PHP code via the includePath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25563" source="XF">claroline-scormexportinc-file-include(25563)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1187" source="VUPEN">ADV-2006-1187</ref>
      <ref url="http://www.securityfocus.com/bid/17341" source="BID">17341</ref>
      <ref url="http://secunia.com/advisories/19461" source="SECUNIA" adv="1">19461</ref>
      <ref url="http://retrogod.altervista.org/claroline_174_incl_xpl.html" source="MISC">http://retrogod.altervista.org/claroline_174_incl_xpl.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1888.html" source="FULLDISC">20060331 Claroline &lt;= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod</ref>
      <ref url="http://www.osvdb.org/24286" source="OSVDB">24286</ref>
      <ref url="http://milw0rm.com/exploits/1627" source="MILW0RM">1627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.5" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.6" />
        <vers num="1.6_beta" />
        <vers num="1.6_rc1" />
        <vers num="1.7.2" />
        <vers num="1.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1598" published="2006-04-03" name="CVE-2006-1598" modified="2011-03-07" discovered="2006-03-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with (1) dot and (2) space characters in the file extension.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17350" source="BID" patch="1">17350</ref>
      <ref url="http://secunia.com/advisories/19326" source="SECUNIA" patch="1" adv="1">19326</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1200" source="VUPEN">ADV-2006-1200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429667/100/0/threaded" source="BUGTRAQ" adv="1">20060403 Secunia Research: AN HTTPD Script Source Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2006-21/advisory" source="MISC" adv="1">http://secunia.com/secunia_research/2006-21/advisory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25591" source="XF">anhttpd-script-source-disclosure(25591)</ref>
      <ref url="http://www.osvdb.org/24323" source="OSVDB">24323</ref>
      <ref url="http://securitytracker.com/id?1015858" source="SECTRACK">1015858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-httpd">
        <vers num="1.2b" />
        <vers num="1.38" />
        <vers num="1.39" />
        <vers num="1.40" />
        <vers num="1.41" />
        <vers num="1.41b" />
        <vers num="1.41c" />
        <vers prev="1" num="1.42n" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1599" published="2006-04-03" name="CVE-2006-1599" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in VCEngine.php in v-creator before 1.3-pre3, when the VC_CRYPTO_METHOD option is OPENSSL, allows remote attackers to execute arbitrary commands, possibly due to problems in the (1) enrypt and (2) decrypt functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25560" source="XF" patch="1">vcreator-vcengine-command-execution(25560)</ref>
      <ref url="http://secunia.com/advisories/19453" source="SECUNIA" patch="1" adv="1">19453</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1189" source="VUPEN">ADV-2006-1189</ref>
      <ref url="http://www.securityfocus.com/bid/17328" source="BID">17328</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=557129" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=557129</ref>
      <ref url="http://www.osvdb.org/24304" source="OSVDB">24304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="v-creator.com" name="v-creator">
        <vers num="1.3_pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1600" published="2006-04-03" name="CVE-2006-1600" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429665/100/0/threaded" source="BUGTRAQ">20060403 Phpwebgallery &lt;= 1.4.1 SQL injection Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/669" source="SREASON">669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebgallery" name="phpwebgallery">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1601" published="2006-04-04" name="CVE-2006-1601" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19444" source="SECUNIA" patch="1" adv="1">19444</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1175" source="VUPEN">ADV-2006-1175</ref>
      <ref url="http://www.securityfocus.com/bid/17313" source="BID">17313</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102278-1" source="SUNALERT" adv="1">102278</ref>
      <ref url="http://securitytracker.com/id?1015849" source="SECTRACK">1015849</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25543" source="XF">suncluster-sunplex-information-disclosure(25543)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cluster">
        <vers num="3.1" edition="4_04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1602" published="2006-04-04" name="CVE-2006-1602" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions_common.php in the VWar Account module (vWar_Account) in PHPNuke Clan 3.0.1 allows remote attackers to include arbitrary files via a URL in the vwar_root2 parameter.  NOTE: it is possible that this issue stems from a problem in VWar itself, but this is not clear.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1202" source="VUPEN">ADV-2006-1202</ref>
      <ref url="http://www.securityfocus.com/bid/17356" source="BID">17356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429615/100/0/threaded" source="BUGTRAQ">20060401 PHPNuke-Clan 3.0.1 Remote File Inclusion Exploit</ref>
      <ref url="http://secunia.com/advisories/19501" source="SECUNIA" adv="1">19501</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25609" source="XF">phpnukeclan-functionscommon-file-include(25609)</ref>
      <ref url="http://www.osvdb.org/24481" source="OSVDB">24481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnuke-clan" name="phpnuke-clan">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1603" published="2006-04-04" name="CVE-2006-1603" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1191" source="VUPEN">ADV-2006-1191</ref>
      <ref url="http://www.securityfocus.com/bid/17355" source="BID">17355</ref>
      <ref url="http://secunia.com/advisories/19494" source="SECUNIA" adv="1">19494</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25599" source="XF">phpbb-profile-script-xss(25599)</ref>
      <ref url="http://www.osvdb.org/24353" source="OSVDB">24353</ref>
      <ref url="http://osvdb.org/ref/24/24353-phpbb.txt" source="MISC">http://osvdb.org/ref/24/24353-phpbb.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1604" published="2006-04-04" name="CVE-2006-1604" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not "typecasted."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17357" source="BID" patch="1">17357</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524</ref>
      <ref url="http://secunia.com/advisories/19498" source="SECUNIA" patch="1" adv="1">19498</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1201" source="VUPEN">ADV-2006-1201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent_cms">
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96.1" />
        <vers num="0.96.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1605" published="2006-04-04" name="CVE-2006-1605" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknown vectors involving "parsed PHP."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17357" source="BID" patch="1">17357</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524</ref>
      <ref url="http://secunia.com/advisories/19498" source="SECUNIA" patch="1" adv="1">19498</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1201" source="VUPEN">ADV-2006-1201</ref>
      <ref url="http://www.osvdb.org/24358" source="OSVDB">24358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent_cms">
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96.1" />
        <vers num="0.96.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1606" published="2006-04-04" name="CVE-2006-1606" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17357" source="BID" patch="1">17357</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524</ref>
      <ref url="http://secunia.com/advisories/19498" source="SECUNIA" patch="1" adv="1">19498</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1201" source="VUPEN">ADV-2006-1201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent_cms">
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96.1" />
        <vers num="0.96.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1607" published="2006-04-04" name="CVE-2006-1607" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17357" source="BID" patch="1">17357</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524</ref>
      <ref url="http://secunia.com/advisories/19498" source="SECUNIA" patch="1" adv="1">19498</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1201" source="VUPEN">ADV-2006-1201</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25610" source="XF">exponent-banner-php-command-execution(25610)</ref>
      <ref url="http://www.osvdb.org/24358" source="OSVDB">24358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exponent" name="exponent_cms">
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96.1" />
        <vers num="0.96.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1608" published="2006-04-10" name="CVE-2006-1608" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securityreason.com/achievement_securityalert/37" source="SREASONRES" patch="1">20060408 copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://secunia.com/advisories/19599" source="SECUNIA" patch="1" adv="1">19599</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1290" source="VUPEN">ADV-2006-1290</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25706" source="XF">php-copy-safemode-bypass(25706)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-320-1" source="UBUNTU">USN-320-1</ref>
      <ref url="http://www.securityfocus.com/bid/17439" source="BID">17439</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441210/100/0/threaded" source="BUGTRAQ">20060723 Re: new shell bypass safe mode</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440869/100/0/threaded" source="BUGTRAQ">20060718 new shell bypass safe mode</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430461/100/0/threaded" source="BUGTRAQ">20060409 copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2</ref>
      <ref url="http://www.osvdb.org/24487" source="OSVDB">24487</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:074" source="MANDRIVA">MDKSA-2006:074</ref>
      <ref url="http://us.php.net/releases/5_1_3.php" source="CONFIRM">http://us.php.net/releases/5_1_3.php</ref>
      <ref url="http://securitytracker.com/id?1015882" source="SECTRACK">1015882</ref>
      <ref url="http://securityreason.com/securityalert/678" source="SREASON">678</ref>
      <ref url="http://secunia.com/advisories/21125" source="SECUNIA">21125</ref>
      <ref url="http://secunia.com/advisories/19775" source="SECUNIA">19775</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1609" published="2006-04-04" name="CVE-2006-1609" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Hitachi XFIT/S, XFIT/S/JCA, XFIT/S/ZGN, and XFIT/S ZENGIN TCP/IP Procedure allows remote attackers to cause a denial of service (server process and transfer control process stop) when the products "receive data unexpectedly".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17329" source="BID">17329</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-004_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-004_e/index-e.html</ref>
      <ref url="http://secunia.com/advisories/19472" source="SECUNIA">19472</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25567" source="XF">xfits-data-dos(25567)</ref>
      <ref url="http://www.osvdb.org/24309" source="OSVDB">24309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="xfit_s">
        <vers num="0" />
      </prod>
      <prod vendor="hitachi" name="xfit_s_jca">
        <vers num="0" />
      </prod>
      <prod vendor="hitachi" name="xfit_s_zengin">
        <vers num="0" />
      </prod>
      <prod vendor="hitachi" name="xfit_s_zgin">
        <vers num="0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1610" published="2006-04-04" name="CVE-2006-1610" modified="2011-08-22" discovered="2006-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.  NOTE: this only occurs when register_globals is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25605" source="XF">squery-file-include(25605)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1204" source="VUPEN" adv="1">ADV-2006-1204</ref>
      <ref url="http://www.securityfocus.com/bid/17434" source="BID">17434</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429611/100/0/threaded" source="BUGTRAQ">20060401 SQuery &lt;= 4.5 Remote File Inclusion Exploit</ref>
      <ref url="http://www.osvdb.org/24400" source="OSVDB">24400</ref>
      <ref url="http://secunia.com/advisories/19482" source="SECUNIA" adv="1">19482</ref>
      <ref url="http://milw0rm.com/exploits/1629" source="MILW0RM">1629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squery" name="squery">
        <vers prev="1" num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1611" published="2006-04-04" name="CVE-2006-1611" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in KGB Archiver before 1.1.5.22 allows remote attackers to overwrite arbitrary files wile decompressing an archive, possibly due to directory traversal sequences in a filename.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of KGB, Archiver before 1.1.5.22</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=162546&amp;release_id=406411" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=162546&amp;release_id=406411</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1207" source="VUPEN">ADV-2006-1207</ref>
      <ref url="http://secunia.com/advisories/19511" source="SECUNIA" adv="1">19511</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25606" source="XF">kgb-archiver-archive-directory-traversal(25606)</ref>
      <ref url="http://www.securityfocus.com/bid/17363" source="BID">17363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kgb" name="archiver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1612" published="2006-04-04" name="CVE-2006-1612" modified="2011-03-07" discovered="2006-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in visview.php in aWebNews 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) yname, (2) emailadd, (3) subject, and (4) comment parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1196" source="VUPEN">ADV-2006-1196</ref>
      <ref url="http://secunia.com/advisories/19487" source="SECUNIA" adv="1">19487</ref>
      <ref url="http://evuln.com/vulns/116/summary.html" source="MISC">http://evuln.com/vulns/116/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25589" source="XF">awebnews-visview-xss(25589)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431007/100/0/threaded" source="BUGTRAQ">20060414 [eVuln] aWebNews Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24333" source="OSVDB">24333</ref>
      <ref url="http://securityreason.com/securityalert/707" source="SREASON">707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb_labs" name="awebnews">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1613" published="2006-04-04" name="CVE-2006-1613" modified="2011-03-07" discovered="2006-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Condition: magic_quotes_gpc = off
</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1196" source="VUPEN">ADV-2006-1196</ref>
      <ref url="http://secunia.com/advisories/19487" source="SECUNIA" adv="1">19487</ref>
      <ref url="http://evuln.com/vulns/116/summary.html" source="MISC">http://evuln.com/vulns/116/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25590" source="XF">awebnews-multiple-sql-injection(25590)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431007/100/0/threaded" source="BUGTRAQ">20060414 [eVuln] aWebNews Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24336" source="OSVDB">24336</ref>
      <ref url="http://www.osvdb.org/24335" source="OSVDB">24335</ref>
      <ref url="http://www.osvdb.org/24334" source="OSVDB">24334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb_labs" name="awebnews">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1614" published="2006-04-06" name="CVE-2006-1614" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1024" source="DEBIAN" patch="1" adv="1">DSA-1024</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638</ref>
      <ref url="http://secunia.com/advisories/19536" source="SECUNIA" patch="1" adv="1">19536</ref>
      <ref url="http://secunia.com/advisories/19534" source="SECUNIA" patch="1" adv="1">19534</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1258" source="VUPEN">ADV-2006-1258</ref>
      <ref url="http://www.trustix.org/errata/2006/0020" source="TRUSTIX">2006-0020</ref>
      <ref url="http://www.securityfocus.com/bid/17388" source="BID">17388</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430405/100/0/threaded" source="BUGTRAQ">20060406 [Overflow.pl] Clam AntiVirus Win32-UPX Heap Overflow (not default configuration)</ref>
      <ref url="http://www.overflow.pl/adv/clamavupxinteger.txt" source="MISC" adv="1">http://www.overflow.pl/adv/clamavupxinteger.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml" source="GENTOO">GLSA-200604-06</ref>
      <ref url="http://secunia.com/advisories/19570" source="SECUNIA">19570</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25660" source="XF">clamav-pe-overflow(25660)</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/24457" source="OSVDB">24457</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:067" source="MANDRIVA">MDKSA-2006:067</ref>
      <ref url="http://up2date.astaro.com/2006/05/low_up2date_6202.html" source="CONFIRM">http://up2date.astaro.com/2006/05/low_up2date_6202.html</ref>
      <ref url="http://securitytracker.com/id?1015887" source="SECTRACK">1015887</ref>
      <ref url="http://secunia.com/advisories/23719" source="SECUNIA">23719</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
      <ref url="http://secunia.com/advisories/19608" source="SECUNIA">19608</ref>
      <ref url="http://secunia.com/advisories/19567" source="SECUNIA">19567</ref>
      <ref url="http://secunia.com/advisories/19564" source="SECUNIA">19564</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html" source="SUSE">SUSE-SA:2006:020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE">APPLE-SA-2006-05-11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" />
        <vers num="0.75.1" />
        <vers num="0.80" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.80_rc4" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1615" published="2006-04-06" name="CVE-2006-1615" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code.  NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.securityfocus.com/bid/17388" source="BID" patch="1">17388</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml" source="GENTOO" patch="1" adv="1">GLSA-200604-06</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1024" source="DEBIAN" patch="1" adv="1">DSA-1024</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638</ref>
      <ref url="http://secunia.com/advisories/19608" source="SECUNIA" patch="1" adv="1">19608</ref>
      <ref url="http://secunia.com/advisories/19570" source="SECUNIA" patch="1" adv="1">19570</ref>
      <ref url="http://secunia.com/advisories/19564" source="SECUNIA" patch="1" adv="1">19564</ref>
      <ref url="http://secunia.com/advisories/19536" source="SECUNIA" patch="1" adv="1">19536</ref>
      <ref url="http://secunia.com/advisories/19534" source="SECUNIA" patch="1" adv="1">19534</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:020</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25661" source="XF">clamav-output-format-string(25661)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1258" source="VUPEN" adv="1">ADV-2006-1258</ref>
      <ref url="http://www.trustix.org/errata/2006/0020" source="TRUSTIX">2006-0020</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/24458" source="OSVDB">24458</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:067" source="MANDRIVA">MDKSA-2006:067</ref>
      <ref url="http://up2date.astaro.com/2006/05/low_up2date_6202.html" source="CONFIRM">http://up2date.astaro.com/2006/05/low_up2date_6202.html</ref>
      <ref url="http://secunia.com/advisories/23719" source="SECUNIA" adv="1">23719</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" adv="1">20077</ref>
      <ref url="http://secunia.com/advisories/19567" source="SECUNIA" adv="1">19567</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE">APPLE-SA-2006-05-11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.3" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.67-1" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" edition="rc" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.8" edition="rc3" />
        <vers num="0.80" edition="rc" />
        <vers num="0.80" edition="rc1" />
        <vers num="0.80" edition="rc2" />
        <vers num="0.80" edition="rc3" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.81" edition="rc1" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" edition="rc1" />
        <vers num="0.84" edition="rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" edition="rc1" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers prev="1" num="0.88" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1616" published="2006-04-05" name="CVE-2006-1616" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Advanced Poll 2.02 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to comments.php or (2) poll_id parameter to page.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ns79.hosteur.com/~secuti/advancedpoll.txt" source="MISC">http://ns79.hosteur.com/~secuti/advancedpoll.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25676" source="XF">advancedpoll-comments-page-sql-injection(25676)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1617" published="2006-04-05" name="CVE-2006-1617" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Advanced Poll 2.02 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to comments.php or (2) poll_id parameter to page.php.  NOTE: it is possible that this issue is resultant from CVE-2006-1616.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ns79.hosteur.com/~secuti/advancedpoll.txt" source="MISC">http://ns79.hosteur.com/~secuti/advancedpoll.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25677" source="XF">advancedpoll-comments-page-xss(25677)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1618" published="2006-04-05" name="CVE-2006-1618" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execute arbitrary code via format string specifiers in an argument to the JOIN command, and possibly other command arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1221" source="VUPEN">ADV-2006-1221</ref>
      <ref url="http://secunia.com/advisories/19515" source="SECUNIA" adv="1">19515</ref>
      <ref url="http://aluigi.altervista.org/adv/doomsdayfs-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/doomsdayfs-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25622" source="XF">doomsday-conmessage-conprintf-format-string(25622)</ref>
      <ref url="http://www.securityfocus.com/bid/17369" source="BID">17369</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429857/100/0/threaded" source="BUGTRAQ">20060403 Format string in Doomsday 1.8.6</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-05.xml" source="GENTOO">GLSA-200604-05</ref>
      <ref url="http://securitytracker.com/id?1015860" source="SECTRACK">1015860</ref>
      <ref url="http://secunia.com/advisories/19519" source="SECUNIA">19519</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044865.html" source="FULLDISC">20060403 Format string in Doomsday 1.8.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="doomsday" name="doomsday">
        <vers num="1.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1619" published="2006-04-05" name="CVE-2006-1619" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1214" source="VUPEN">ADV-2006-1214</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21053738" source="AIXAPAR">PQ62144</ref>
      <ref url="http://securitytracker.com/id?1015857" source="SECTRACK">1015857</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25619" source="XF">websphere-http-header-dos(25619)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1620" published="2006-04-05" name="CVE-2006-1620" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE.  It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39038" source="XF">hostingcontroller-multiple-security-bypass(39038)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25673" source="XF">hosting-controller-accountactions-password(25673)</ref>
      <ref url="http://www.securityfocus.com/bid/26862" source="BID">26862</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485028/100/0/threaded" source="BUGTRAQ">20071213 Hosting Controller - Multiple Security Bugs (Extremely Critical)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429731/100/0/threaded" source="BUGTRAQ">20060402 Hosting Controller AccountActions.asp and saveuploadfiles.asp vulns (PoC)</ref>
      <ref url="http://www.osvdb.org/24773" source="OSVDB">24773</ref>
      <ref url="http://www.milw0rm.com/exploits/4730" source="MILW0RM">4730</ref>
      <ref url="http://secunia.com/advisories/28973" source="SECUNIA">28973</ref>
      <ref url="http://hostingcontroller.com/english/logs/Post-Hotfix-3_3-sec-Patch-ReleaseNotes.html" source="CONFIRM">http://hostingcontroller.com/english/logs/Post-Hotfix-3_3-sec-Patch-ReleaseNotes.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="2002_rc_1" />
        <vers prev="1" num="6.1_hotfix_3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1621" published="2006-04-05" name="CVE-2006-1621" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429731/100/0/threaded" source="BUGTRAQ">20060402 Hosting Controller AccountActions.asp and saveuploadfiles.asp vulns (PoC)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25675" source="XF">hosting-controller-Saveupload-file-upload(25675)</ref>
      <ref url="http://www.osvdb.org/24772" source="OSVDB">24772</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="2002_rc_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1622" published="2006-04-05" name="CVE-2006-1622" modified="2008-09-05" discovered="2006-04-01" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPSelect linksubmit allows remote attackers to inject arbitrary web script or HTML via (1) the description parameter to linklist.php and possibly other vectors involving (2) index.php and (3) linksubmit.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429608/100/0/threaded" source="BUGTRAQ">20060401 linksubmit &lt;= All version Html Tag Injector in index.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25607" source="XF">linksubmit-linksubmit-xss(25607)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpselect" name="phpselect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1623" published="2006-04-05" name="CVE-2006-1623" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in main.php in an unspecified "file created by Andries Bruinsma," possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code.  NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability type.  In addition, there is little public information on the named product. Finally, an XSS vector is implied in the subject line, but because there is no other information and evidence of a cut-and-paste error, it will not be assigned a separate CVE identifier unless additional information is provided.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25603" source="XF">flexible-development-main-xss(25603)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25600" source="XF">flexible-development-main-command-execution(25600)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430334/100/0/threaded" source="BUGTRAQ">20060405 Re: FleXiBle Development Script Remote Command Exucetion And XSS Attacking</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429613/100/0/threaded" source="BUGTRAQ">20060401 FleXiBle Development Script Remote Command Exucetion And XSS Attacking</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000680.html" source="VIM">20060404 FleXiBle Development Script Remote Command Exucetion And XSS Attacking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_bruinsma" name="flexible_development">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1624" published="2006-04-05" name="CVE-2006-1624" modified="2008-09-05" discovered="2006-03-31" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The default configuration of syslogd in the Linux sysklogd package does not enable the -x (disable name lookups) option, which allows remote attackers to cause a denial of service (traffic amplification) via messages with spoofed source IP addresses.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429739/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060402 RE: DoS-ing sysklogd?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429618/100/0/threaded" source="BUGTRAQ" adv="1">20060331 DoS-ing sysklogd?</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25672" source="XF">sysklogd-sourceip-dos(25672)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1625" published="2006-04-05" name="CVE-2006-1625" modified="2011-03-07" discovered="2006-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode email tag, as demonstrated using the onmousemove event.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25615" source="XF">mybb-email-bbcode-xss(25615)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25615" source="XF">mybb-email-bbcode-xss(25615)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1216" source="VUPEN">ADV-2006-1216</ref>
      <ref url="http://www.securityfocus.com/bid/17368" source="BID">17368</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429748/100/0/threaded" source="BUGTRAQ" adv="1">20060402 MyBB 1.10 New CrossSiteScripting</ref>
      <ref url="http://www.osvdb.org/24375" source="OSVDB">24375</ref>
      <ref url="http://secunia.com/advisories/19516" source="SECUNIA">19516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1626" published="2006-04-05" name="CVE-2006-1626" modified="2011-10-11" discovered="2006-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects any version of Windows OS previous to XP SP2 that is using Internet Explorer 6.0</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25634" source="XF">ie-swf-addressbar-spoofing(25634)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2319" source="VUPEN" adv="1">ADV-2006-2319</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1218" source="VUPEN">ADV-2006-1218</ref>
      <ref url="http://www.securityfocus.com/bid/17404" source="BID">17404</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440851/100/100/threaded" source="BUGTRAQ">20060721 about bid 17404</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429891/100/0/threaded" source="BUGTRAQ">20060404 Another way to spoof Internet Explorer Address Bar</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429719/100/0/threaded" source="BUGTRAQ" adv="1">20060403 Another Internet Explorer Address Bar Spoofing Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx" source="MS">MS06-021</ref>
      <ref url="http://securitytracker.com/id?1016291" source="SECTRACK">1016291</ref>
      <ref url="http://secunia.com/Internet_Explorer_Address_Bar_Spoofing_Vulnerability_Test/" source="MISC" adv="1">http://secunia.com/Internet_Explorer_Address_Bar_Spoofing_Vulnerability_Test/</ref>
      <ref url="http://secunia.com/advisories/19521" source="SECUNIA" adv="1">19521</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1918" source="OVAL" sig="1">oval:org.mitre.oval:def:1918</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1881" source="OVAL" sig="1">oval:org.mitre.oval:def:1881</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1842" source="OVAL" sig="1">oval:org.mitre.oval:def:1842</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1806" source="OVAL" sig="1">oval:org.mitre.oval:def:1806</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1604" source="OVAL" sig="1">oval:org.mitre.oval:def:1604</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1600" source="OVAL" sig="1">oval:org.mitre.oval:def:1600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1627" published="2006-04-13" name="CVE-2006-1627" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.  NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues.  Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1342" source="VUPEN">ADV-2006-1342</ref>
      <ref url="http://www.adobe.com/support/techdocs/322699.html" source="CONFIRM">http://www.adobe.com/support/techdocs/322699.html</ref>
      <ref url="http://secunia.com/secunia_research/2005-68/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-68/advisory/</ref>
      <ref url="http://secunia.com/advisories/15924" source="SECUNIA" adv="1">15924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25769" source="XF">adobe-access-control-bypass(25769)</ref>
      <ref url="http://www.securityfocus.com/bid/17500" source="BID">17500</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded" source="BUGTRAQ">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015905" source="SECTRACK">1015905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="6.0" edition="" />
        <vers prev="1" num="6.0" edition=":reader_extensions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1628" published="2006-04-13" name="CVE-2006-1628" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/333036.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/333036.html</ref>
      <ref url="http://secunia.com/advisories/19620" source="SECUNIA" patch="1" adv="1">19620</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1343" source="VUPEN">ADV-2006-1343</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25779" source="XF">adobe-livecycle-information-disclosure(25779)</ref>
      <ref url="http://www.securityfocus.com/bid/17511" source="BID">17511</ref>
      <ref url="http://securitytracker.com/id?1015906" source="SECTRACK">1015906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="livecycle_form_manager">
        <vers num="7.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1629" published="2006-04-06" name="CVE-2006-1629" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.</descript>
    </desc>
    <sols>
      <sol source="nvd">OpenVPN version 2.0.6 fixes this vulnerability. </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17392" source="BID" patch="1">17392</ref>
      <ref url="http://secunia.com/advisories/19531" source="SECUNIA" patch="1" adv="1">19531</ref>
      <ref url="http://openvpn.net/changelog.html" source="CONFIRM" patch="1">http://openvpn.net/changelog.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1261" source="VUPEN">ADV-2006-1261</ref>
      <ref url="http://www.osreviews.net/reviews/security/openvpn-print" source="MISC">http://www.osreviews.net/reviews/security/openvpn-print</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=10093825&amp;forum_id=8482" source="CONFIRM">http://sourceforge.net/mailarchive/forum.php?thread_id=10093825&amp;forum_id=8482</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25667" source="XF">openvpn-ldpreload-code-execution(25667)</ref>
      <ref url="http://www.osvdb.org/24444" source="OSVDB">24444</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:069" source="MANDRIVA">MDKSA-2006:069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1045" source="DEBIAN">DSA-1045</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
      <ref url="http://secunia.com/advisories/19837" source="SECUNIA">19837</ref>
      <ref url="http://secunia.com/advisories/19598" source="SECUNIA">19598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openvpn" name="openvpn">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1630" published="2006-04-06" name="CVE-2006-1630" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1024" source="DEBIAN" patch="1" adv="1">DSA-1024</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638</ref>
      <ref url="http://secunia.com/advisories/19536" source="SECUNIA" patch="1" adv="1">19536</ref>
      <ref url="http://secunia.com/advisories/19534" source="SECUNIA" patch="1" adv="1">19534</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1258" source="VUPEN">ADV-2006-1258</ref>
      <ref url="http://www.securityfocus.com/bid/17388" source="BID">17388</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25662" source="XF">clamav-others-dos(25662)</ref>
      <ref url="http://www.trustix.org/errata/2006/0020" source="TRUSTIX">2006-0020</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.osvdb.org/24459" source="OSVDB">24459</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:067" source="MANDRIVA">MDKSA-2006:067</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml" source="GENTOO">GLSA-200604-06</ref>
      <ref url="http://up2date.astaro.com/2006/05/low_up2date_6202.html" source="CONFIRM">http://up2date.astaro.com/2006/05/low_up2date_6202.html</ref>
      <ref url="http://secunia.com/advisories/23719" source="SECUNIA">23719</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
      <ref url="http://secunia.com/advisories/19608" source="SECUNIA">19608</ref>
      <ref url="http://secunia.com/advisories/19570" source="SECUNIA">19570</ref>
      <ref url="http://secunia.com/advisories/19567" source="SECUNIA">19567</ref>
      <ref url="http://secunia.com/advisories/19564" source="SECUNIA">19564</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html" source="SUSE">SUSE-SA:2006:020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE">APPLE-SA-2006-05-11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" />
        <vers num="0.75.1" />
        <vers num="0.80" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.80_rc4" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1631" published="2006-04-05" name="CVE-2006-1631" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-css.shtml" source="CISCO" patch="1" adv="1">20060405 Cisco 11500 Content Services Switch HTTP Request Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1257" source="VUPEN">ADV-2006-1257</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25642" source="XF">cisco-css-http-comp-dos(25642)</ref>
      <ref url="http://www.securityfocus.com/bid/17383" source="BID">17383</ref>
      <ref url="http://www.osvdb.org/24433" source="OSVDB">24433</ref>
      <ref url="http://securitytracker.com/id?1015870" source="SECTRACK">1015870</ref>
      <ref url="http://secunia.com/advisories/19552" source="SECUNIA">19552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1634" published="2006-04-06" name="CVE-2006-1634" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17360" source="BID">17360</ref>
      <ref url="http://www.securityfocus.com/archive/1/429744" source="BUGTRAQ">20060402 Multiple Vulnerabilities in LucidCMS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25632" source="XF">lucidcms-index-login-panel-xss(25632)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucidcms" name="lucidcms">
        <vers num="2.0.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1635" published="2006-04-06" name="CVE-2006-1635" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/429744" source="BUGTRAQ">20060402 Multiple Vulnerabilities in LucidCMS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25633" source="XF">lucidcms-translator-path-disclosure(25633)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucidcms" name="lucidcms">
        <vers num="2.0.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1636" published="2006-04-06" name="CVE-2006-1636" modified="2011-08-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter.  NOTE: this is a different vulnerability than CVE-2006-1503.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19524" source="SECUNIA" patch="1" adv="1">19524</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1228" source="VUPEN" adv="1">ADV-2006-1228</ref>
      <ref url="http://www.securityfocus.com/bid/17358" source="BID">17358</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429742/100/0/threaded" source="BUGTRAQ">20060402 VWar &lt;= 1.5.0 R12 Remote File Inclusion Exploit</ref>
      <ref url="http://www.osvdb.org/24480" source="OSVDB">24480</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/VWar_1.5.0_R12.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/VWar_1.5.0_R12.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vwar" name="virtual_war">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5.0_r1" />
        <vers num="1.5.0_r10" />
        <vers num="1.5.0_r11" />
        <vers num="1.5.0_r12" />
        <vers num="1.5.0_r2" />
        <vers num="1.5.0_r3" />
        <vers num="1.5.0_r4" />
        <vers num="1.5.0_r5" />
        <vers num="1.5.0_r6" />
        <vers num="1.5.0_r7" />
        <vers num="1.5.0_r8" />
        <vers num="1.5.0_r9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1637" published="2006-04-06" name="CVE-2006-1637" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in aWebBB 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) tname or (2) fpost parameters to (a) post.php; (3) fullname, (4) emailadd, (5) country, (6) sig, or (7) otherav parameters to (b) editac.php; or (8) fullname, (9) emailadd, or (10) country parameters to (c) register.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25585" source="XF">awebbb-multiple-xss(25585)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1197" source="VUPEN">ADV-2006-1197</ref>
      <ref url="http://www.securityfocus.com/bid/17352" source="BID">17352</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431064/100/0/threaded" source="BUGTRAQ">20060415 [eVuln] aWebBB Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24339" source="OSVDB">24339</ref>
      <ref url="http://www.osvdb.org/24338" source="OSVDB">24338</ref>
      <ref url="http://www.osvdb.org/24337" source="OSVDB">24337</ref>
      <ref url="http://secunia.com/advisories/19486" source="SECUNIA" adv="1">19486</ref>
      <ref url="http://evuln.com/vulns/117/summary.html" source="MISC">http://evuln.com/vulns/117/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb_labs" name="awebbb">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1638" published="2006-04-06" name="CVE-2006-1638" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in aWebBB 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter to (a) accounts.php, (b) changep.php, (c) editac.php, (d) feedback.php, (e) fpass.php, (f) login.php, (g) post.php, (h) reply.php, or (i) reply_log.php; (2) p parameter to (j) dpost.php; (3) c parameter to (k) list.php or (l) ndis.php; or (12) q parameter to (m) search.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires "magic_quotes_gpc" to be disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1197" source="VUPEN">ADV-2006-1197</ref>
      <ref url="http://secunia.com/advisories/19486" source="SECUNIA" adv="1">19486</ref>
      <ref url="http://evuln.com/vulns/117/summary.html" source="MISC">http://evuln.com/vulns/117/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25587" source="XF">awebbb-multiple-sql-injection(25587)</ref>
      <ref url="http://www.securityfocus.com/bid/17352" source="BID">17352</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431064/100/0/threaded" source="BUGTRAQ">20060415 [eVuln] aWebBB Multiple XSS and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24352" source="OSVDB">24352</ref>
      <ref url="http://www.osvdb.org/24351" source="OSVDB">24351</ref>
      <ref url="http://www.osvdb.org/24350" source="OSVDB">24350</ref>
      <ref url="http://www.osvdb.org/24349" source="OSVDB">24349</ref>
      <ref url="http://www.osvdb.org/24348" source="OSVDB">24348</ref>
      <ref url="http://www.osvdb.org/24347" source="OSVDB">24347</ref>
      <ref url="http://www.osvdb.org/24346" source="OSVDB">24346</ref>
      <ref url="http://www.osvdb.org/24345" source="OSVDB">24345</ref>
      <ref url="http://www.osvdb.org/24344" source="OSVDB">24344</ref>
      <ref url="http://www.osvdb.org/24343" source="OSVDB">24343</ref>
      <ref url="http://www.osvdb.org/24342" source="OSVDB">24342</ref>
      <ref url="http://www.osvdb.org/24341" source="OSVDB">24341</ref>
      <ref url="http://www.osvdb.org/24340" source="OSVDB">24340</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb_labs" name="awebbb">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1639" published="2006-04-06" name="CVE-2006-1639" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.  This vulnerability may affect all previous versions of Wire Plastik Design, wpBlog before 0.4</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1238" source="VUPEN">ADV-2006-1238</ref>
      <ref url="http://secunia.com/advisories/19538" source="SECUNIA" adv="1">19538</ref>
      <ref url="http://evuln.com/vulns/119/summary.html" source="MISC">http://evuln.com/vulns/119/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25628" source="XF">wpblog-index-sql-injection(25628)</ref>
      <ref url="http://www.securityfocus.com/bid/17381" source="BID">17381</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431186/100/0/threaded" source="BUGTRAQ">20060417 [eVuln] Wire Plastik wpBlog SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/24385" source="OSVDB">24385</ref>
      <ref url="http://securitytracker.com/id?1015951" source="SECTRACK">1015951</ref>
      <ref url="http://securityreason.com/securityalert/734" source="SREASON">734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wire_plastik_design" name="wpblog">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1640" published="2006-04-06" name="CVE-2006-1640" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14 allows remote attackers to inject arbitrary web script or HTML via the email parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1237" source="VUPEN">ADV-2006-1237</ref>
      <ref url="http://secunia.com/advisories/19541" source="SECUNIA" adv="1">19541</ref>
      <ref url="http://evuln.com/vulns/118/summary.html" source="MISC">http://evuln.com/vulns/118/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25623" source="XF">czarnews-news-xss(25623)</ref>
      <ref url="http://www.securityfocus.com/bid/17380" source="BID">17380</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431132/100/0/threaded" source="BUGTRAQ">20060417 [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24381" source="OSVDB">24381</ref>
      <ref url="http://securitytracker.com/id?1015957" source="SECTRACK">1015957</ref>
      <ref url="http://securityreason.com/securityalert/732" source="SREASON">732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="czaries_network" name="czarnews">
        <vers num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1641" published="2006-04-06" name="CVE-2006-1641" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CzarNews 1.14 allow remote attackers to execute arbitrary SQL commands via the (1) usern or (2) passw parameters to (a) cn_auth.php, (3) s parameter to (b) news.php, or (4) a parameter to (c) dpost.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1237" source="VUPEN">ADV-2006-1237</ref>
      <ref url="http://secunia.com/advisories/19541" source="SECUNIA" adv="1">19541</ref>
      <ref url="http://evuln.com/vulns/118/summary.html" source="MISC">http://evuln.com/vulns/118/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25624" source="XF">czarnews-multiple-sql-injection(25624)</ref>
      <ref url="http://www.securityfocus.com/bid/17380" source="BID">17380</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431132/100/0/threaded" source="BUGTRAQ">20060417 [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24384" source="OSVDB">24384</ref>
      <ref url="http://www.osvdb.org/24383" source="OSVDB">24383</ref>
      <ref url="http://www.osvdb.org/24382" source="OSVDB">24382</ref>
      <ref url="http://securitytracker.com/id?1015957" source="SECTRACK">1015957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="czaries_network" name="czarnews">
        <vers num="1.13b" />
        <vers prev="1" num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1642" published="2006-04-06" name="CVE-2006-1642" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) the search_terms parameter to (a) search.php, and (2) the first_name, (3) last_name, (4) email, (5) password, and (6) confirm_password parameters to (b) userinput.php.  NOTE: the provenance of this information is unknown; the details are obtained from third party.  In addition, the lack of precision in the third party descriptions makes it unclear whether the named vectors are correct.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1244" source="VUPEN">ADV-2006-1244</ref>
      <ref url="http://secunia.com/advisories/19488" source="SECUNIA" adv="1">19488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25652" source="XF">interact-search-xss(25652)</ref>
      <ref url="http://www.osvdb.org/24461" source="OSVDB">24461</ref>
      <ref url="http://www.osvdb.org/24389" source="OSVDB">24389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interact" name="interact">
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1643" published="2006-04-06" name="CVE-2006-1643" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Interact 2.1.1 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1244" source="VUPEN">ADV-2006-1244</ref>
      <ref url="http://secunia.com/advisories/19488" source="SECUNIA" adv="1">19488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25653" source="XF">interact-login-sql-injection(25653)</ref>
      <ref url="http://www.securityfocus.com/bid/17385" source="BID">17385</ref>
      <ref url="http://www.osvdb.org/24390" source="OSVDB">24390</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interact" name="interact">
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1644" published="2006-04-06" name="CVE-2006-1644" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">login.php in Interact 2.1.1 generates different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1244" source="VUPEN">ADV-2006-1244</ref>
      <ref url="http://secunia.com/advisories/19488" source="SECUNIA" adv="1">19488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25651" source="XF">interact-login-error-info-disclosure(25651)</ref>
      <ref url="http://www.osvdb.org/24388" source="OSVDB">24388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interact" name="interact">
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1645" published="2006-04-06" name="CVE-2006-1645" modified="2011-03-07" discovered="2006-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitrary web script or HTML and gain leverage to execute arbitrary PHP code via the User-Agent HTTP header, which is displayed by admin/modules/general/statistic.php in the administration panel.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1193" source="VUPEN">ADV-2006-1193</ref>
      <ref url="http://www.securityfocus.com/bid/17353" source="BID">17353</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429666/100/0/threaded" source="BUGTRAQ">20060402 ReloadCMS &lt;= 1.2.5stable Cross site scripting / remote command execution</ref>
      <ref url="http://secunia.com/advisories/19470" source="SECUNIA" adv="1">19470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25604" source="XF">reloadcms-useragent-xss(25604)</ref>
      <ref url="http://www.osvdb.org/24327" source="OSVDB">24327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reloadcms" name="reloadcms">
        <vers num="1.2.0" />
        <vers num="1.2.0_p1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1646" published="2006-04-06" name="CVE-2006-1646" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to cause a denial of service (daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en" source="MISC">http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/</ref>
      <ref url="http://secunia.com/advisories/19463" source="SECUNIA" adv="1">19463</ref>
      <ref url="http://mail-index.netbsd.org/source-changes/2006/01/19/0017.html" source="CONFIRM">http://mail-index.netbsd.org/source-changes/2006/01/19/0017.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="internet_key_exchange" name="internet_key_exchange">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1647" published="2006-04-06" name="CVE-2006-1647" modified="2011-03-07" discovered="2006-02-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1241" source="VUPEN">ADV-2006-1241</ref>
      <ref url="http://www.securityfocus.com/bid/17373" source="BID">17373</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429843/100/0/threaded" source="BUGTRAQ" adv="1">20060404 SMART Technologies SynchronEyes Remote Denial of Services</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25659" source="XF">synchroneyes-datagram-dos(25659)</ref>
      <ref url="http://securitytracker.com/id?1015869" source="SECTRACK">1015869</ref>
      <ref url="http://secunia.com/advisories/19535" source="SECUNIA">19535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smart_technologies" name="synchroneyes">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1648" published="2006-04-06" name="CVE-2006-1648" modified="2011-03-07" discovered="2006-02-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker's machine and read a value that is used as a parameter to malloc.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1241" source="VUPEN">ADV-2006-1241</ref>
      <ref url="http://www.securityfocus.com/bid/17373" source="BID">17373</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429843/100/0/threaded" source="BUGTRAQ" adv="1">20060404 SMART Technologies SynchronEyes Remote Denial of Services</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25663" source="XF">synchroneyes-packet-dos(25663)</ref>
      <ref url="http://www.osvdb.org/24392" source="OSVDB">24392</ref>
      <ref url="http://securitytracker.com/id?1015869" source="SECTRACK">1015869</ref>
      <ref url="http://secunia.com/advisories/19535" source="SECUNIA">19535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smart_technologies" name="synchroneyes">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1649" published="2006-04-06" name="CVE-2006-1649" modified="2011-03-07" discovered="2006-03-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The "restore to" selection in the "quarantine a file" capability of ESET NOD32 before 2.51.26 allows a restore to any directory that permits read access by the invoking user, which allows local users to create new files despite write-access directory permissions.</descript>
    </desc>
    <sols>
      <sol source="nvd">ESET NOD32 Antivirus version 2.51.26 fixes this vulnerability.  All versions of this product prior to 2.51.26 are vulnerable.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17374" source="BID" patch="1">17374</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429892/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060404 NOD32 local privilege escalation vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25640" source="XF">nod32-restoreto-file-upload(25640)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1242" source="VUPEN">ADV-2006-1242</ref>
      <ref url="http://www.osvdb.org/24393" source="OSVDB">24393</ref>
      <ref url="http://securitytracker.com/id?1015867" source="SECTRACK">1015867</ref>
      <ref url="http://secunia.com/advisories/19054" source="SECUNIA">19054</ref>
      <ref url="http://securityreason.com/securityalert/672" source="SREASON">672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1650" published="2006-04-06" name="CVE-2006-1650" modified="2008-09-05" discovered="2006-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: a followup was unable to replicate this issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25634" source="XF">ie-swf-addressbar-spoofing(25634)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430348/30/5730/threaded" source="BUGTRAQ">20060406 Re: Re: Another Internet Explorer Address Bar Spoofing Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429927/100/0/threaded" source="BUGTRAQ" adv="1">20060404 Re: Another Internet Explorer Address Bar Spoofing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1651" published="2006-04-06" name="CVE-2006-1651" modified="2008-09-05" discovered="2006-04-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets.  NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been disputed.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429846/100/0/threaded" source="BUGTRAQ" adv="1">20060404 Re: Bypassing ISA Server 2004 with IPv6</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429816/100/0/threaded" source="BUGTRAQ" adv="1">20060403 Bypassing ISA Server 2004 with IPv6</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430684/100/0/threaded" source="BUGTRAQ">20060410 Re: Bypassing ISA Server 2004 with IPv6</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430281/100/0/threaded" source="BUGTRAQ">20060405 Re: Re: Bypassing ISA Server 2004 with IPv6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1652" published="2006-04-06" name="CVE-2006-1652" modified="2011-03-07" discovered="2006-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port 5900, which triggers an overflow in Log::ReallyPrint; and (2) allow remote attackers to cause a denial of service (server crash) via a long HTTP GET request to TCP port 5800, which triggers an overflow in VNCLog::ReallyPrint.</descript>
    </desc>
    <sols>
      <sol source="nvd">There are two seperate vulnerabilities here;  One allows escalated priveleges to authenticated users, the other allows remote unauthenticated users to cause a Denial of Service (DoS).</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25650" source="XF">ultr@vnc-vnclogreallyprint-bo(25650)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25648" source="XF">untr@vnc-error-bo(25648)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1240" source="VUPEN" adv="1">ADV-2006-1240</ref>
      <ref url="http://www.securityfocus.com/bid/17378" source="BID">17378</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430711/100/0/threaded" source="BUGTRAQ">20060411 Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer POC</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430287/100/0/threaded" source="BUGTRAQ">20060405 Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer and server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429930/100/0/threaded" source="BUGTRAQ" adv="1">20060404 Buffer-overflow in Ultr@VNC 1.0.1 viewer and server</ref>
      <ref url="http://securityreason.com/securityalert/674" source="SREASON">674</ref>
      <ref url="http://secunia.com/advisories/19513" source="SECUNIA" adv="1">19513</ref>
      <ref url="http://milw0rm.com/exploits/1643" source="MILW0RM">1643</ref>
      <ref url="http://milw0rm.com/exploits/1642" source="MILW0RM">1642</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044901.html" source="FULLDISC">20060404 Buffer-overflow in Ultr@VNC 1.0.1 viewer and server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultravnc" name="tabbed_viewer">
        <vers num="1.29" />
      </prod>
      <prod vendor="ultravnc" name="vnc_viewer">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1653" published="2006-04-06" name="CVE-2006-1653" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in loadkernel.php in AngelineCMS 0.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the installPath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17371" source="BID">17371</ref>
      <ref url="http://advisories.echo.or.id/adv/adv27-K-159-2006.txt" source="MISC">http://advisories.echo.or.id/adv/adv27-K-159-2006.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25658" source="XF">angelinecms-loadkernel-file-include(25658)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429983/100/0/threaded" source="BUGTRAQ">20060404 [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion</ref>
      <ref url="http://www.osvdb.org/24610" source="OSVDB">24610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angelinecms" name="angelinecms">
        <vers num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1654" published="2006-04-06" name="CVE-2006-1654" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429893/100/0/threaded" source="HP" patch="1">SSRT061141</ref>
      <ref url="http://securitytracker.com/id?1015862" source="SECTRACK" patch="1">1015862</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0085.html" source="FULLDISC" patch="1">20060404 [SEC-1 LTD] HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1230" source="VUPEN">ADV-2006-1230</ref>
      <ref url="http://www.securityfocus.com/bid/17367" source="BID">17367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429893/100/0/threaded" source="HP">HPSBPI2109</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25627" source="XF">hp-laserjet-toolbox-directory-traversal(25627)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429984/100/0/threaded" source="BUGTRAQ">20060404 [SEC-1 LTD] HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability</ref>
      <ref url="http://www.osvdb.org/24396" source="OSVDB">24396</ref>
      <ref url="http://secunia.com/advisories/19529" source="SECUNIA">19529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="color_laserjet_2500_toolbox">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600_toolbox">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet">
        <vers num="4600dn" />
        <vers num="4600dtn" />
        <vers num="4600hdn" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500l">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500lse">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500tn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1655" published="2006-04-06" name="CVE-2006-1655" modified="2010-04-02" discovered="2006-04-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3.  NOTE: this issue might be related to CVE-2004-0991, but it is not clear.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17365" source="BID">17365</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1074" source="DEBIAN">DSA-1074</ref>
      <ref url="http://secunia.com/advisories/20281" source="SECUNIA">20281</ref>
      <ref url="http://secunia.com/advisories/20275" source="SECUNIA">20275</ref>
      <ref url="http://secunia.com/advisories/20240" source="SECUNIA">20240</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.pl</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:092" source="MANDRIVA">MDKSA-2006:092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59r" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1656" published="2006-04-06" name="CVE-2006-1656" modified="2008-09-05" discovered="2006-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17361" source="BID" patch="1">17361</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360438" source="MISC" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360438</ref>
      <ref url="https://savannah.nongnu.org/patch/?func=detailitem&amp;item_id=4966" source="CONFIRM">https://savannah.nongnu.org/patch/?func=detailitem&amp;item_id=4966</ref>
      <ref url="https://savannah.nongnu.org/bugs/?func=detailitem&amp;item_id=15996" source="MISC">https://savannah.nongnu.org/bugs/?func=detailitem&amp;item_id=15996</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vserver" name="util-vserver">
        <vers num="0.30.209" />
        <vers prev="1" num="0.30.210" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1657" published="2006-04-07" name="CVE-2006-1657" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Chucky A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not filtered when the administrator views the "Login Log" page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1243" source="VUPEN">ADV-2006-1243</ref>
      <ref url="http://secunia.com/advisories/19526" source="SECUNIA" adv="1">19526</ref>
      <ref url="http://evuln.com/vulns/121/summary.html" source="MISC">http://evuln.com/vulns/121/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25638" source="XF">nt-index-xss(25638)</ref>
      <ref url="http://www.securityfocus.com/bid/17387" source="BID">17387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431344/100/0/threaded" source="BUGTRAQ">20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24397" source="OSVDB">24397</ref>
      <ref url="http://securityreason.com/securityalert/741" source="SREASON">741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chucky_a._ivey" name="n.t.">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1658" published="2006-04-07" name="CVE-2006-1658" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T.  1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1243" source="VUPEN">ADV-2006-1243</ref>
      <ref url="http://secunia.com/advisories/19526" source="SECUNIA" adv="1">19526</ref>
      <ref url="http://evuln.com/vulns/121/summary.html" source="MISC">http://evuln.com/vulns/121/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25639" source="XF">nt-ticker-file-include(25639)</ref>
      <ref url="http://www.securityfocus.com/bid/17387" source="BID">17387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431344/100/0/threaded" source="BUGTRAQ">20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24398" source="OSVDB">24398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chucky_a._ivey" name="n.t.">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1659" published="2006-04-07" name="CVE-2006-1659" modified="2011-03-07" discovered="2006-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability most likely affects all versions of Softbiz, Image Gallery.</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1217" source="VUPEN">ADV-2006-1217</ref>
      <ref url="http://www.securityfocus.com/bid/17339" source="BID">17339</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429763/100/0/threaded" source="BUGTRAQ" adv="1">20060331 SQL Injection in Softbiz Image Gallery</ref>
      <ref url="http://www.osvdb.org/24372" source="OSVDB">24372</ref>
      <ref url="http://www.osvdb.org/24371" source="OSVDB">24371</ref>
      <ref url="http://www.osvdb.org/24370" source="OSVDB">24370</ref>
      <ref url="http://www.osvdb.org/24369" source="OSVDB">24369</ref>
      <ref url="http://www.osvdb.org/24368" source="OSVDB">24368</ref>
      <ref url="http://secunia.com/advisories/19523" source="SECUNIA" adv="1">19523</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25616" source="XF">softbizimagegallery-multiple-sql-injection(25616)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softbiz" name="image_gallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1660" published="2006-04-07" name="CVE-2006-1660" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability most likely affects all versions of Softbiz, Image Gallery.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1217" source="VUPEN">ADV-2006-1217</ref>
      <ref url="http://secunia.com/advisories/19523" source="SECUNIA" adv="1">19523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softbiz" name="image_gallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1661" published="2006-04-07" name="CVE-2006-1661" modified="2011-03-07" discovered="2006-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time parameter in planning.View.action, and (3) userID parameter in user.View.action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25641" source="XF">skforum-multiple-xss(25641)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1260" source="VUPEN">ADV-2006-1260</ref>
      <ref url="http://www.securityfocus.com/bid/17389" source="BID">17389</ref>
      <ref url="http://www.osvdb.org/24432" source="OSVDB">24432</ref>
      <ref url="http://www.osvdb.org/24431" source="OSVDB">24431</ref>
      <ref url="http://www.osvdb.org/24430" source="OSVDB">24430</ref>
      <ref url="http://secunia.com/advisories/19484" source="SECUNIA" adv="1">19484</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/skforum-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/skforum-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sk_soft" name="skforum">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1662" published="2006-04-07" name="CVE-2006-1662" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429946/100/0/threaded" source="BUGTRAQ" patch="1">20060404 Re: Limbo CMS code execution</ref>
      <ref url="http://www.securityfocus.com/bid/16902" source="BID">16902</ref>
      <ref url="http://www.securityfocus.com/archive/1/426428" source="BUGTRAQ">20060228 Limbo CMS code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24992" source="XF">limbocms-index-code-execution(24992)</ref>
      <ref url="http://securityreason.com/securityalert/519" source="SREASON">519</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0728.html" source="FULLDISC">20060228 Limbo CMS code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limbo_cms" name="limbo_cms">
        <vers num="1.0.4.1" />
        <vers num="1.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-1663" reject="1" published="2006-04-07" name="CVE-2006-1663" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0996.  Reason: This candidate is a reservation duplicate of CVE-2006-0996.  Notes: All CVE users should reference CVE-2006-0996 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2006-1664" published="2006-04-07" name="CVE-2006-1664" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/xinelib_poc.pl" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/xinelib_poc.pl</ref>
      <ref url="http://www.securityfocus.com/bid/17370" source="BID">17370</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00976.html" source="FEDORA">FEDORA-2008-1047</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00956.html" source="FEDORA">FEDORA-2008-1043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25670" source="XF">xinelib-mpeg-bo(25670)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-16.xml" source="GENTOO">GLSA-200604-16</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=571608" source="MISC">http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=571608</ref>
      <ref url="http://securitytracker.com/id?1015868" source="SECTRACK">1015868</ref>
      <ref url="http://secunia.com/advisories/28666" source="SECUNIA">28666</ref>
      <ref url="http://secunia.com/advisories/19856" source="SECUNIA">19856</ref>
      <ref url="http://secunia.com/advisories/19853" source="SECUNIA">19853</ref>
      <ref url="http://milw0rm.com/exploits/1641" source="MILW0RM">1641</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=128838" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=128838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers num="0.9.13" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3a" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1665" published="2006-04-07" name="CVE-2006-1665" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0.1 stable allow remote attackers to inject arbitrary web script or HTML via the (1) adminJump and (2) forum_middle parameters in (a) forum.php, and the (3) form parameter in (b) members.php, (c) pm.php, and (d) mail.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25657" source="XF">arabportal-multiple-xss(25657)</ref>
      <ref url="http://www.securityfocus.com/bid/17375" source="BID">17375</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429940/100/0/threaded" source="BUGTRAQ">20060404 ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting &amp; 1 SQL Injection ] MultBugz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arab_portal" name="arab_portal">
        <vers num="2.0.1_stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1666" published="2006-04-07" name="CVE-2006-1666" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forum.php in Arab Portal 2.0.1 stable allows remote attackers to execute arbitrary SQL commands via the mineID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25656" source="XF">arabportal-forum-sql-injection(25656)</ref>
      <ref url="http://www.securityfocus.com/bid/17375" source="BID">17375</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429940/100/0/threaded" source="BUGTRAQ">20060404 ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting &amp; 1 SQL Injection ] MultBugz</ref>
      <ref url="http://securityreason.com/securityalert/644" source="SREASON">644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arab_portal" name="arab_portal">
        <vers num="2.0.1_stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1667" published="2006-04-07" name="CVE-2006-1667" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s from being set within slides.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1239" source="VUPEN">ADV-2006-1239</ref>
      <ref url="http://www.securityfocus.com/bid/17379" source="BID">17379</ref>
      <ref url="http://secunia.com/advisories/19478" source="SECUNIA" adv="1">19478</ref>
      <ref url="http://milw0rm.com/exploits/1645" source="MILW0RM">1645</ref>
      <ref url="http://bash-x.net/undef/exploits/crappy_syntax.txt" source="MISC">http://bash-x.net/undef/exploits/crappy_syntax.txt</ref>
      <ref url="http://bash-x.net/undef/adv/craftygallery.html" source="MISC">http://bash-x.net/undef/adv/craftygallery.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25654" source="XF">crafty-slides-sql-injection(25654)</ref>
      <ref url="http://www.osvdb.org/24386" source="OSVDB">24386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crafty_syntax_image_gallery" name="crafty_syntax_image_gallery">
        <vers num="3.1g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1668" published="2006-04-07" name="CVE-2006-1668" modified="2011-03-07" discovered="2006-04-04" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires privileges to upload images.  This product is also known as PHP thumbnail Photo Gallery.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1239" source="VUPEN">ADV-2006-1239</ref>
      <ref url="http://www.securityfocus.com/bid/17379" source="BID">17379</ref>
      <ref url="http://secunia.com/advisories/19478" source="SECUNIA" adv="1">19478</ref>
      <ref url="http://milw0rm.com/exploits/1645" source="MILW0RM">1645</ref>
      <ref url="http://bash-x.net/undef/exploits/crappy_syntax.txt" source="MISC">http://bash-x.net/undef/exploits/crappy_syntax.txt</ref>
      <ref url="http://bash-x.net/undef/adv/craftygallery.html" source="MISC">http://bash-x.net/undef/adv/craftygallery.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25655" source="XF">crafty-http-post-code-execution(25655)</ref>
      <ref url="http://www.osvdb.org/24387" source="OSVDB">24387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crafty_syntax_image_gallery" name="crafty_syntax_image_gallery">
        <vers prev="1" num="3.1g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1669" published="2006-04-07" name="CVE-2006-1669" modified="2008-09-05" discovered="2006-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitrary SQL commands via the T parameter.  NOTE: this issue can be leveraged to execute arbitrary shell commands since the username is later processed in an eval() call, but since the username originated from the SQL injection, it could be a resultant issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17382" source="BID">17382</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430358/100/0/threaded" source="BUGTRAQ">20060405 PHPMyChat &lt;= 0.14.5 remote commands execution</ref>
      <ref url="http://securitytracker.com/id?1015873" source="SECTRACK">1015873</ref>
      <ref url="http://milw0rm.com/exploits/1646" source="MILW0RM">1646</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25687" source="XF">phpmychat-messagesl-sql-injection(25687)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpheaven" name="phpmychat">
        <vers num="0.14.4" />
        <vers prev="1" num="0.14.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1670" published="2006-04-07" name="CVE-2006-1670" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memory exhaustion and possibly card reset) by sending an invalid response when the final ACK is expected, aka bug ID CSCei45910.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17384" source="BID" patch="1">17384</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml" source="CISCO" patch="1" adv="1">20060405 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1256" source="VUPEN">ADV-2006-1256</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25643" source="XF">cisco-ons-iplan-ack-dos(25643)</ref>
      <ref url="http://www.osvdb.org/24434" source="OSVDB">24434</ref>
      <ref url="http://securitytracker.com/id?1015872" source="SECTRACK">1015872</ref>
      <ref url="http://secunia.com/advisories/19553" source="SECUNIA">19553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15310-cl_series">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.14" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_mspp">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ons_15454_mstp">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1671" published="2006-04-07" name="CVE-2006-1671" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSCsc51390; (2) a "crafted" IP packet to a device with IP on the LAN interface, aka bug ID CSCsd04168; and (3) a "malformed" OSPF packet, aka bug ID CSCsc54558.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has released fixes to address these issues.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1256" source="VUPEN">ADV-2006-1256</ref>
      <ref url="http://www.securityfocus.com/bid/17384" source="BID">17384</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml" source="CISCO">20060405 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25646" source="XF">cisco-ons-ospf-dos(25646)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25645" source="XF">cisco-ons-cc-ip-dos(25645)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25644" source="XF">cisco-ons-cc-ems-dos(25644)</ref>
      <ref url="http://www.osvdb.org/24437" source="OSVDB">24437</ref>
      <ref url="http://www.osvdb.org/24436" source="OSVDB">24436</ref>
      <ref url="http://www.osvdb.org/24435" source="OSVDB">24435</ref>
      <ref url="http://securitytracker.com/id?1015872" source="SECTRACK">1015872</ref>
      <ref url="http://secunia.com/advisories/19553" source="SECUNIA">19553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="transport_controller">
        <vers num="4.0.x" />
      </prod>
      <prod vendor="cisco" name="ons_15310-cl_series">
        <vers num="0" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="0" />
      </prod>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.14" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_mspp">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1672" published="2006-04-07" name="CVE-2006-1672" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1256" source="VUPEN">ADV-2006-1256</ref>
      <ref url="http://www.securityfocus.com/bid/17384" source="BID">17384</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml" source="CISCO">20060405 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25647" source="XF">cisco-ons-ctc-code-execution(25647)</ref>
      <ref url="http://www.osvdb.org/24438" source="OSVDB">24438</ref>
      <ref url="http://securitytracker.com/id?1015871" source="SECTRACK">1015871</ref>
      <ref url="http://secunia.com/advisories/19553" source="SECUNIA">19553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="transport_controller">
        <vers num="4.0.x" />
      </prod>
      <prod vendor="cisco" name="ons_15310-cl_series">
        <vers num="0" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="0" />
      </prod>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.14" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_mspp">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1673" published="2006-04-07" name="CVE-2006-1673" modified="2011-03-07" discovered="2006-04-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1267" source="VUPEN">ADV-2006-1267</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25649" source="XF">vbulletin-vbugtracker-vbugs-xss(25649)</ref>
      <ref url="http://www.securityfocus.com/bid/17407" source="BID">17407</ref>
      <ref url="http://www.osvdb.org/24448" source="OSVDB">24448</ref>
      <ref url="http://secunia.com/advisories/19562" source="SECUNIA">19562</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/vbug-tracker-for-vbulletin-35x-xss.html" source="MISC">http://pridels0.blogspot.com/2006/04/vbug-tracker-for-vbulletin-35x-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbug_tracker">
        <vers prev="1" num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1674" published="2006-04-10" name="CVE-2006-1674" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-1675.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.Silitix.com/phpwebgallery" source="MISC">http://www.Silitix.com/phpwebgallery</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebgallery" name="phpwebgallery">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1675" published="2006-04-10" name="CVE-2006-1675" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) num, and (3) search parameters to (a) category.php, and the (4) slideshow, (5) show_metadata, and (6) start parameters to (b) picture.php, a different vulnerability than CVE-2006-1674.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1301" source="VUPEN">ADV-2006-1301</ref>
      <ref url="http://www.securityfocus.com/bid/17421" source="BID">17421</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25733" source="XF">phpwebgallery-category-picture-xss(25733)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430481/100/0/threaded" source="BUGTRAQ">20060410 PHPWebGallery Multiple Cross Site Scripting Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19610" source="SECUNIA">19610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebgallery" name="phpwebgallery">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1676" published="2006-04-10" name="CVE-2006-1676" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25710" source="XF">mdpro-index-sql-injection(25710)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1282" source="VUPEN" adv="1">ADV-2006-1282</ref>
      <ref url="http://www.securityfocus.com/bid/17399" source="BID">17399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437831/100/100/threaded" source="BUGTRAQ">20060620 Re: MAXDEV CMS Multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430370/100/0/threaded" source="BUGTRAQ">20060406 MAXDEV CMS Multiple vulnerabilities</ref>
      <ref url="http://www.maxdev.com/Article592.phtml" source="CONFIRM">http://www.maxdev.com/Article592.phtml</ref>
      <ref url="http://secunia.com/advisories/19578" source="SECUNIA" adv="1">19578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxdev" name="md-pro">
        <vers num="1.0.72" />
        <vers num="1.0.73" />
        <vers prev="1" num="1.0.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1677" published="2006-04-10" name="CVE-2006-1677" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25714" source="XF">mdpro-legacy-path-disclosure(25714)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1282" source="VUPEN" adv="1">ADV-2006-1282</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437831/100/100/threaded" source="BUGTRAQ">20060620 Re: MAXDEV CMS Multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430370/100/0/threaded" source="BUGTRAQ">20060406 MAXDEV CMS Multiple vulnerabilities</ref>
      <ref url="http://www.maxdev.com/Article592.phtml" source="CONFIRM">http://www.maxdev.com/Article592.phtml</ref>
      <ref url="http://secunia.com/advisories/19578" source="SECUNIA" adv="1">19578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxdev" name="md-pro">
        <vers num="1.0.72" />
        <vers num="1.0.73" />
        <vers prev="1" num="1.0.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1678" published="2006-04-10" name="CVE-2006-1678" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-1" source="CONFIRM" patch="1">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-1</ref>
      <ref url="http://secunia.com/advisories/19556" source="SECUNIA" patch="1" adv="1">19556</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1263" source="VUPEN">ADV-2006-1263</ref>
      <ref url="http://www.securityfocus.com/bid/17390" source="BID">17390</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25689" source="XF">phpmyadmin-themes-xss(25689)</ref>
      <ref url="http://www.osvdb.org/24450" source="OSVDB">24450</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1207" source="DEBIAN">DSA-1207</ref>
      <ref url="http://secunia.com/advisories/22781" source="SECUNIA">22781</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.0" />
        <vers num="2.2.0_pre1" />
        <vers num="2.2.0_pre2" />
        <vers num="2.2.0_rc1" />
        <vers num="2.2.0_rc2" />
        <vers num="2.2.0_rc3" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
        <vers num="2.5.6_rc1" />
        <vers num="2.5.7" />
        <vers num="2.5.7_pl1" />
        <vers num="2.6.0_pl1" />
        <vers num="2.6.0_pl2" />
        <vers num="2.6.0_pl3" />
        <vers num="2.6.1" />
        <vers num="2.6.1_pl1" />
        <vers num="2.6.1_pl3" />
        <vers num="2.6.1_rc1" />
        <vers num="2.6.2" />
        <vers num="2.6.2_rc1" />
        <vers num="2.6.3_pl1" />
        <vers num="2.6.4_pl1" />
        <vers num="2.6.4_pl3" />
        <vers num="2.6.4_pl4" />
        <vers num="2.6.4_rc1" />
        <vers num="2.7.0" />
        <vers num="2.7.0_beta1" />
        <vers num="2.7.0_pl1" />
        <vers num="2.7.0_pl2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1679" published="2006-04-10" name="CVE-2006-1679" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules/online.php in Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the layout parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1302" source="VUPEN">ADV-2006-1302</ref>
      <ref url="http://www.securityfocus.com/bid/17405" source="BID">17405</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430391/100/0/threaded" source="BUGTRAQ">20060407 Multiple vulnerability in jupiter CMS</ref>
      <ref url="http://secunia.com/advisories/19582" source="SECUNIA" adv="1">19582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25700" source="XF">jupitercm-index-xss(25700)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1680" published="2006-04-10" name="CVE-2006-1680" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Jupiter CMS 1.1.5, when display_errors is enabled, allows remote attackers to obtain the full server path via a direct request to modules/online.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1302" source="VUPEN">ADV-2006-1302</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430391/100/0/threaded" source="BUGTRAQ">20060407 Multiple vulnerability in jupiter CMS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25703" source="XF">jupitercm-online-path-disclosure(25703)</ref>
      <ref url="http://secunia.com/advisories/19582" source="SECUNIA">19582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1681" published="2006-04-10" name="CVE-2006-1681" modified="2011-03-07" discovered="2006-04-04" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19587" source="SECUNIA" patch="1">19587</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1292" source="VUPEN">ADV-2006-1292</ref>
      <ref url="http://www.securityfocus.com/bid/17408" source="BID">17408</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430385/100/0/threaded" source="BUGTRAQ">20060406 XSS Bug in Cherokee Webserver</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25698" source="XF">cherokee-handlererror-xss(25698)</ref>
      <ref url="http://www.osvdb.org/24469" source="OSVDB">24469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cherokee" name="cherokee_httpd">
        <vers num="0.1" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.2" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.4.17" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" />
        <vers num="0.4.9" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1682" published="2006-04-10" name="CVE-2006-1682" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1289" source="VUPEN">ADV-2006-1289</ref>
      <ref url="http://www.securityfocus.com/bid/17418" source="BID">17418</ref>
      <ref url="http://secunia.com/advisories/19594" source="SECUNIA" adv="1">19594</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25721" source="XF">webshop-deptname-xss(25721)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/web-shop-50-xss.html" source="MISC">http://pridels0.blogspot.com/2006/04/web-shop-50-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="talentsoft" name="web+_shop">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1683" published="2006-04-10" name="CVE-2006-1683" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1323" source="VUPEN">ADV-2006-1323</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430315/100/0/threaded" source="BUGTRAQ">20060407 SQL Injection in Chipmunk Guestbook</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25695" source="XF">chipmunk-guestbook-login-sql-injection(25695)</ref>
      <ref url="http://www.securityfocus.com/bid/17483" source="BID">17483</ref>
      <ref url="http://secunia.com/advisories/19584" source="SECUNIA">19584</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="chipmunk_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1684" published="2006-04-10" name="CVE-2006-1684" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in ecotwo Shopsystem 1.0-192 and earlier allows remote attackers to include arbitrary local files via (1) the lang parameter in news.php and (2) other unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://pridels0.blogspot.com/2006/04/ecotwo-shopsystem-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/ecotwo-shopsystem-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecotwo" name="shopsystem">
        <vers num="1.0_192" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1685" published="2006-04-10" name="CVE-2006-1685" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality.  NOTE: this vulnerability also allows resultant path disclosure when the SQL queries are invalid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1293" source="VUPEN">ADV-2006-1293</ref>
      <ref url="http://secunia.com/advisories/19592" source="SECUNIA" adv="1">19592</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25731" source="XF">apt-webshop-sql-injection(25731)</ref>
      <ref url="http://www.securityfocus.com/bid/17425" source="BID">17425</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apt" name="apt-webshop-system">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":basic" />
        <vers num="3.0" edition=":light" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1686" published="2006-04-10" name="CVE-2006-1686" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apt" name="apt-webshop-system">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":basic" />
        <vers num="3.0" edition=":light" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1687" published="2006-04-10" name="CVE-2006-1687" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1293" source="VUPEN">ADV-2006-1293</ref>
      <ref url="http://secunia.com/advisories/19592" source="SECUNIA" adv="1">19592</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apt" name="apt-webshop-system">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":basic" />
        <vers num="3.0" edition=":light" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1688" published="2006-04-10" name="CVE-2006-1688" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CVE-2006-1610. The provenance of most of these additional vectors is unknown, although likely from post-disclosure analysis.  NOTE: this only occurs when register_globals is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1284" source="VUPEN" adv="1">ADV-2006-1284</ref>
      <ref url="http://www.securityfocus.com/bid/17434" source="BID">17434</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441015/100/0/threaded" source="BUGTRAQ">20060724 SQuery v.x (devi.php) (armygame.php) Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439874/100/0/threaded" source="BUGTRAQ">20060710 SQuery &lt;= 4.5(libpath) Remote File Inclusion Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430289/100/0/threaded" source="BUGTRAQ">20060408 Autonomous LAN party File iNclusion</ref>
      <ref url="http://www.osvdb.org/24429" source="OSVDB">24429</ref>
      <ref url="http://www.osvdb.org/24428" source="OSVDB">24428</ref>
      <ref url="http://www.osvdb.org/24427" source="OSVDB">24427</ref>
      <ref url="http://www.osvdb.org/24426" source="OSVDB">24426</ref>
      <ref url="http://www.osvdb.org/24425" source="OSVDB">24425</ref>
      <ref url="http://www.osvdb.org/24424" source="OSVDB">24424</ref>
      <ref url="http://www.osvdb.org/24423" source="OSVDB">24423</ref>
      <ref url="http://www.osvdb.org/24422" source="OSVDB">24422</ref>
      <ref url="http://www.osvdb.org/24421" source="OSVDB">24421</ref>
      <ref url="http://www.osvdb.org/24420" source="OSVDB">24420</ref>
      <ref url="http://www.osvdb.org/24419" source="OSVDB">24419</ref>
      <ref url="http://www.osvdb.org/24418" source="OSVDB">24418</ref>
      <ref url="http://www.osvdb.org/24417" source="OSVDB">24417</ref>
      <ref url="http://www.osvdb.org/24416" source="OSVDB">24416</ref>
      <ref url="http://www.osvdb.org/24415" source="OSVDB">24415</ref>
      <ref url="http://www.osvdb.org/24414" source="OSVDB">24414</ref>
      <ref url="http://www.osvdb.org/24413" source="OSVDB">24413</ref>
      <ref url="http://www.osvdb.org/24412" source="OSVDB">24412</ref>
      <ref url="http://www.osvdb.org/24411" source="OSVDB">24411</ref>
      <ref url="http://www.osvdb.org/24410" source="OSVDB">24410</ref>
      <ref url="http://www.osvdb.org/24409" source="OSVDB">24409</ref>
      <ref url="http://www.osvdb.org/24408" source="OSVDB">24408</ref>
      <ref url="http://www.osvdb.org/24407" source="OSVDB">24407</ref>
      <ref url="http://www.osvdb.org/24406" source="OSVDB">24406</ref>
      <ref url="http://www.osvdb.org/24405" source="OSVDB">24405</ref>
      <ref url="http://www.osvdb.org/24404" source="OSVDB">24404</ref>
      <ref url="http://www.osvdb.org/24403" source="OSVDB">24403</ref>
      <ref url="http://www.osvdb.org/24402" source="OSVDB">24402</ref>
      <ref url="http://www.osvdb.org/24401" source="OSVDB">24401</ref>
      <ref url="http://www.blogcu.com/Liz0ziM/431845/" source="MISC">http://www.blogcu.com/Liz0ziM/431845/</ref>
      <ref url="http://securitytracker.com/id?1015884" source="SECTRACK">1015884</ref>
      <ref url="http://securityreason.com/securityalert/679" source="SREASON">679</ref>
      <ref url="http://secunia.com/advisories/19588" source="SECUNIA" adv="1">19588</ref>
      <ref url="http://secunia.com/advisories/19482" source="SECUNIA" adv="1">19482</ref>
      <ref url="http://liz0zim.no-ip.org/alp.txt" source="MISC">http://liz0zim.no-ip.org/alp.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squery" name="squery">
        <vers prev="1" num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1689" published="2006-04-10" name="CVE-2006-1689" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.</descript>
    </desc>
    <sols>
      <sol source="nvd">HP-UX B.11.11:
Install PHCO_34545 or later.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1272" source="VUPEN">ADV-2006-1272</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430411/100/0/threaded" source="HP">SSRT061132</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430411/100/0/threaded" source="HP">SSRT061132</ref>
      <ref url="http://www.osvdb.org/24449" source="OSVDB">24449</ref>
      <ref url="http://securitytracker.com/id?1015874" source="SECTRACK">1015874</ref>
      <ref url="http://secunia.com/advisories/19560" source="SECUNIA" adv="1">19560</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25691" source="XF">hpux-su-ldap-privilege-escalation(25691)</ref>
      <ref url="http://www.securityfocus.com/bid/17400" source="BID">17400</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1754" source="OVAL" sig="1">oval:org.mitre.oval:def:1754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1690" published="2006-04-11" name="CVE-2006-1690" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1270" source="VUPEN">ADV-2006-1270</ref>
      <ref url="http://secunia.com/advisories/19568" source="SECUNIA" adv="1">19568</ref>
      <ref url="http://evuln.com/vulns/123/summary.html" source="MISC">http://evuln.com/vulns/123/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25684" source="XF">mwnewsletter-subscribe-xss(25684)</ref>
      <ref url="http://www.securityfocus.com/bid/17412" source="BID">17412</ref>
      <ref url="http://www.osvdb.org/24446" source="OSVDB">24446</ref>
      <ref url="http://securityreason.com/securityalert/752" source="SREASON">752</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0447.html" source="BUGTRAQ">20060421 [eVuln] MWNewsletter SQL Injection and XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manic_web" name="mwnewsletter">
        <vers prev="1" num="1.0.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1691" published="2006-04-11" name="CVE-2006-1691" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1270" source="VUPEN">ADV-2006-1270</ref>
      <ref url="http://secunia.com/advisories/19568" source="SECUNIA" adv="1">19568</ref>
      <ref url="http://evuln.com/vulns/123/summary.html" source="MISC">http://evuln.com/vulns/123/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25683" source="XF">mwnewsletter-unsubscribe-sql-injection(25683)</ref>
      <ref url="http://www.securityfocus.com/bid/17412" source="BID">17412</ref>
      <ref url="http://www.osvdb.org/24905" source="OSVDB">24905</ref>
      <ref url="http://www.osvdb.org/24445" source="OSVDB">24445</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0447.html" source="BUGTRAQ">20060421 [eVuln] MWNewsletter SQL Injection and XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manic_web" name="mwnewsletter">
        <vers num="1.0.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1692" published="2006-04-11" name="CVE-2006-1692" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or the (2) user_name parameter to subscribe.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that this was discovered during post-disclosure analysis.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1270" source="VUPEN">ADV-2006-1270</ref>
      <ref url="http://secunia.com/advisories/19568" source="SECUNIA" adv="1">19568</ref>
      <ref url="http://www.osvdb.org/24905" source="OSVDB">24905</ref>
      <ref url="http://www.osvdb.org/24445" source="OSVDB">24445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manic_web" name="mwnewsletter">
        <vers num="1.0.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1693" published="2006-04-11" name="CVE-2006-1693" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in GlobalSCAPE Secure FTP Server before 3.1.4 Build 01.10.2006 allows attackers to cause a denial of service (application crash) via a "custom command" with a long argument.</descript>
    </desc>
    <sols>
      <sol source="nvd">This issue is addressed in Secure FTP Server 3.1.4 Build 01.10.2006.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17398" source="BID" patch="1">17398</ref>
      <ref url="http://secunia.com/advisories/19547" source="SECUNIA" patch="1">19547</ref>
      <ref url="http://www.globalscape.com/gsftps/history.asp" source="CONFIRM">http://www.globalscape.com/gsftps/history.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25665" source="XF">globalscape-custom-commands-dos(25665)</ref>
      <ref url="http://www.osvdb.org/24451" source="OSVDB">24451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalscape" name="secure_ftp_server">
        <vers num="2.0_build2004-03-11" />
        <vers num="2.0_build2004-03-16" />
        <vers num="3.0" />
        <vers num="3.0.2_build2005-04-12" />
        <vers num="3.0.3_build2005-04-29" />
        <vers num="3.0.4_build2005-06-15" />
        <vers num="3.1.1_build2005-08-08" />
        <vers num="3.1.3_build2005-10-10" />
        <vers num="3.1_build2005-07-06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1694" published="2006-04-11" name="CVE-2006-1694" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1283" source="VUPEN">ADV-2006-1283</ref>
      <ref url="http://www.securityfocus.com/bid/17424" source="BID">17424</ref>
      <ref url="http://secunia.com/advisories/19602" source="SECUNIA" adv="1">19602</ref>
      <ref url="http://milw0rm.com/exploits/1655" source="MILW0RM">1655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25708" source="XF">xbritemembers-id-sql-injection(25708)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xbrite" name="xbrite_members">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1695" published="2006-04-11" name="CVE-2006-1695" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/fbps-[PID].</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1281" source="VUPEN">ADV-2006-1281</ref>
      <ref url="http://secunia.com/advisories/19559" source="SECUNIA" adv="1">19559</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361370" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361370</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25729" source="XF">fbida-fbgs-tmpdir-symlink(25729)</ref>
      <ref url="http://www.securityfocus.com/bid/17436" source="BID">17436</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_19_sr.html" source="SUSE">SUSE-SR:2006:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-13.xml" source="GENTOO">GLSA-200604-13</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1068" source="DEBIAN">DSA-1068</ref>
      <ref url="http://secunia.com/advisories/21459" source="SECUNIA">21459</ref>
      <ref url="http://secunia.com/advisories/20166" source="SECUNIA">20166</ref>
      <ref url="http://secunia.com/advisories/19766" source="SECUNIA">19766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fbida" name="fbida">
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1696" published="2006-04-11" name="CVE-2006-1696" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=408602&amp;group_id=7130" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=408602&amp;group_id=7130</ref>
      <ref url="http://secunia.com/advisories/19580" source="SECUNIA" patch="1" adv="1">19580</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1285" source="VUPEN">ADV-2006-1285</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25707" source="XF">gallery-unspecified-xss(25707)</ref>
      <ref url="http://www.securityfocus.com/bid/17437" source="BID">17437</ref>
      <ref url="http://www.osvdb.org/24466" source="OSVDB">24466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.4" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_pl1" />
        <vers num="1.4.3_pl2" />
        <vers num="1.4.4_pl2" />
        <vers num="1.4.4_pl3" />
        <vers num="1.4.4_pl4" />
        <vers num="1.4.4_pl5" />
        <vers num="1.4_pl1" />
        <vers num="1.4_pl2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1_rc2" />
        <vers num="1.5.2" />
        <vers num="1.5.2_pl1" />
        <vers num="1.5.2_pl2" />
        <vers num="1.5.2_rc2" />
        <vers num="1.5.2_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1697" published="2006-04-11" name="CVE-2006-1697" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1287" source="VUPEN">ADV-2006-1287</ref>
      <ref url="http://www.securityfocus.com/bid/17438" source="BID">17438</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430356/100/0/threaded" source="BUGTRAQ">20060408 Matt Wright Guestbook Xss Script &amp;#304;njection</ref>
      <ref url="http://www.osvdb.org/24479" source="OSVDB">24479</ref>
      <ref url="http://secunia.com/advisories/19586" source="SECUNIA" adv="1">19586</ref>
      <ref url="http://liz0zim.no-ip.org/mattguestbook.html" source="MISC">http://liz0zim.no-ip.org/mattguestbook.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25697" source="XF">guestbook-guestbook-parameters-xss(25697)</ref>
      <ref url="http://securityreason.com/securityalert/681" source="SREASON">681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="matt_wright_guestbook">
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1698" published="2006-04-11" name="CVE-2006-1698" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that they are the result of post-disclosure analysis.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1287" source="VUPEN">ADV-2006-1287</ref>
      <ref url="http://secunia.com/advisories/19586" source="SECUNIA" adv="1">19586</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25697" source="XF">guestbook-guestbook-parameters-xss(25697)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="matt_wright_guestbook">
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1699" published="2006-04-11" name="CVE-2006-1699" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1348" source="VUPEN">ADV-2006-1348</ref>
      <ref url="http://www.securityfocus.com/bid/17416" source="BID">17416</ref>
      <ref url="http://securitytracker.com/id?1015877" source="SECTRACK">1015877</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25782" source="XF">awebbannergenerator-index-xss(25782)</ref>
      <ref url="http://secunia.com/advisories/19621" source="SECUNIA">19621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb" name="banner_generator">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1700" published="2006-04-11" name="CVE-2006-1700" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buy.php in Aweb Scripts Seller uses predictable cookies for authentication based on the time and the script number, which allows remote attackers to bypass authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17417" source="BID">17417</ref>
      <ref url="http://securitytracker.com/id?1015878" source="SECTRACK">1015878</ref>
      <ref url="http://secunia.com/advisories/19626" source="SECUNIA">19626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb" name="scripts_seller">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1701" published="2006-04-11" name="CVE-2006-1701" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Pages module in Shadowed Portal allows remote attackers to inject arbitrary web script or HTML via the page parameter to load.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1286" source="VUPEN">ADV-2006-1286</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430376/100/0/threaded" source="BUGTRAQ">20060408 Shadowed Portal Cross Site Scripting</ref>
      <ref url="http://secunia.com/advisories/19595" source="SECUNIA" adv="1">19595</ref>
      <ref url="http://liz0zim.no-ip.org/shad0w.txt" source="MISC">http://liz0zim.no-ip.org/shad0w.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25716" source="XF">shadowedportal-load-xss(25716)</ref>
      <ref url="http://www.securityfocus.com/bid/17430" source="BID">17430</ref>
      <ref url="http://securityreason.com/securityalert/685" source="SREASON">685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shadowed_portal" name="shadowed_portal">
        <vers prev="1" num="5.7d2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1702" published="2006-04-11" name="CVE-2006-1702" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17423" source="BID">17423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430443/100/0/threaded" source="BUGTRAQ">20060409 Vulnerabilities in SPIP</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25711" source="XF">spip-spiplogin-file-include(25711)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spip" name="spip">
        <vers num="1.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1703" published="2006-04-11" name="CVE-2006-1703" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lire.php in Sire 2.0 nws allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17428" source="BID">17428</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430301/100/0/threaded" source="BUGTRAQ">20060407 Sire 2.0 Nws Remote File inclusion &amp; Arbitary Files Upload</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25726" source="XF">sire-lire-file-include(25726)</ref>
      <ref url="http://securitytracker.com/id?1015885" source="SECTRACK">1015885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hubert_plisson" name="sire">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1704" published="2006-04-11" name="CVE-2006-1704" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17431" source="BID">17431</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430301/100/0/threaded" source="BUGTRAQ">20060407 Sire 2.0 Nws Remote File inclusion &amp; Arbitary Files Upload</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25727" source="XF">sire-upload-auth-bypass(25727)</ref>
      <ref url="http://securitytracker.com/id?1015885" source="SECTRACK">1015885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hubert_plisson" name="sire">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1705" published="2006-04-11" name="CVE-2006-1705" modified="2011-03-07" discovered="2006-02-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Oracle Database 9.2.0.0 to 10.2.0.3 allows local users with "SELECT" privileges for a base table to insert, update, or delete data by creating a crafted view then performing the operations on that view.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/805737" source="CERT-VN">VU#805737</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1297" source="VUPEN">ADV-2006-1297</ref>
      <ref url="http://www.securityfocus.com/bid/17426" source="BID">17426</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430434/100/0/threaded" source="BUGTRAQ">20060410 Oracle read-only user can insert/update/delete data via specially crafted views</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_modify_data_via_views.html" source="MISC">http://www.red-database-security.com/advisory/oracle_modify_data_via_views.html</ref>
      <ref url="http://securitytracker.com/id?1015886" source="SECTRACK">1015886</ref>
      <ref url="http://secunia.com/advisories/19574" source="SECUNIA" adv="1">19574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25696" source="XF">oracle-base-table-data-manipulation(25696)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044990.html" source="FULLDISC">20060410 Oracle read-only user can insert/update/delete data via specially crafted views</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_10.1.0.3" />
        <vers num="enterprise_10.1.0.3.1" />
        <vers num="enterprise_10.1.0.4" />
        <vers num="enterprise_10.2.3" />
        <vers num="personal_10.1.0.2" />
        <vers num="personal_10.1.0.3" />
        <vers num="personal_10.1.0.3.1" />
        <vers num="personal_10.1.0.4" />
        <vers num="personal_10.2.3" />
        <vers num="standard_10.1.0.2" />
        <vers num="standard_10.1.0.3" />
        <vers num="standard_10.1.0.3.1" />
        <vers num="standard_10.1.0.4" />
        <vers num="standard_10.1.0.4.2" />
        <vers num="standard_10.1.0.5" />
        <vers num="standard_10.2.0.1" />
        <vers num="standard_10.2.3" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="enterprise_9.2.0.6" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.5" />
        <vers num="personal_9.2.0.6" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.5" />
        <vers num="standard_9.2.0.6" />
        <vers num="standard_9.2.0.7" />
        <vers num="standard_9.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1706" published="2006-04-11" name="CVE-2006-1706" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php.  NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1291" source="VUPEN">ADV-2006-1291</ref>
      <ref url="http://www.securityfocus.com/bid/17441" source="BID">17441</ref>
      <ref url="http://secunia.com/advisories/19593" source="SECUNIA" adv="1">19593</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25724" source="XF">shopweezle-multiple-path-disclosure(25724)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25723" source="XF">shopweezle-multiple-sql-injection(25723)</ref>
      <ref url="http://www.osvdb.org/24473" source="OSVDB">24473</ref>
      <ref url="http://www.osvdb.org/24472" source="OSVDB">24472</ref>
      <ref url="http://www.osvdb.org/24471" source="OSVDB">24471</ref>
      <ref url="http://www.osvdb.org/24470" source="OSVDB">24470</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kansok_communications" name="shopweezle">
        <vers num="2.0" />
        <vers num="2.0_personal" />
        <vers num="2.0_professional" />
        <vers num="2.0_professional_plus" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1707" published="2006-04-11" name="CVE-2006-1707" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25725" source="XF">shopweezle-index-file-include(25725)</ref>
      <ref url="http://www.osvdb.org/24474" source="OSVDB">24474</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kansok_communications" name="shopweezle">
        <vers num="2.0" />
        <vers num="2.0_personal" />
        <vers num="2.0_professional" />
        <vers num="2.0_professional_plus" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1708" published="2006-04-11" name="CVE-2006-1708" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via the showid parameter in the member page to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1295" source="VUPEN">ADV-2006-1295</ref>
      <ref url="http://secunia.com/advisories/19609" source="SECUNIA" adv="1">19609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25746" source="XF">clansys-index-sql-injection(25746)</ref>
      <ref url="http://www.securityfocus.com/bid/17456" source="BID">17456</ref>
      <ref url="http://securitytracker.com/id?1015935" source="SECTRACK">1015935</ref>
      <ref url="http://milw0rm.com/exploits/1662" source="MILW0RM">1662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clansys" name="clansys">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1709" published="2006-04-11" name="CVE-2006-1709" modified="2011-03-07" discovered="2006-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1326" source="VUPEN">ADV-2006-1326</ref>
      <ref url="http://www.securityfocus.com/bid/17485" source="BID">17485</ref>
      <ref url="http://www.osvdb.org/24557" source="OSVDB">24557</ref>
      <ref url="http://secunia.com/advisories/19622" source="SECUNIA" adv="1">19622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25739" source="XF">interaktiv-shopmain-xss(25739)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/interaktivshop-v5-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/interaktivshop-v5-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interaktiv" name="interaktiv.shop">
        <vers prev="1" num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1710" published="2006-04-11" name="CVE-2006-1710" modified="2011-03-07" discovered="2006-04-08" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25699" source="XF">dnguestbook-admin-sql-injection(25699)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1299" source="VUPEN">ADV-2006-1299</ref>
      <ref url="http://www.securityfocus.com/bid/17435" source="BID">17435</ref>
      <ref url="http://secunia.com/advisories/19601" source="SECUNIA" adv="1">19601</ref>
      <ref url="http://milw0rm.com/exploits/1653" source="MILW0RM">1653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="design_nation" name="dnguestbook">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1711" published="2006-04-11" name="CVE-2006-1711" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://svn.plone.org/svn/plone/PloneHotfix20060410/trunk/README.txt" source="CONFIRM">https://svn.plone.org/svn/plone/PloneHotfix20060410/trunk/README.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1340" source="VUPEN">ADV-2006-1340</ref>
      <ref url="http://dev.plone.org/plone/ticket/5432" source="MISC">http://dev.plone.org/plone/ticket/5432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25781" source="XF">plone-memberid-data-manipulation(25781)</ref>
      <ref url="http://www.securityfocus.com/bid/17484" source="BID">17484</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1032" source="DEBIAN">DSA-1032</ref>
      <ref url="http://secunia.com/advisories/19640" source="SECUNIA">19640</ref>
      <ref url="http://secunia.com/advisories/19633" source="SECUNIA">19633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plone" name="plone">
        <vers num="2.0.5" />
        <vers num="2.1.2" />
        <vers num="2.5_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1712" published="2006-04-11" name="CVE-2006-1712" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17403" source="BID" patch="1">17403</ref>
      <ref url="http://securitytracker.com/id?1015876" source="SECTRACK" patch="1">1015876</ref>
      <ref url="http://secunia.com/advisories/19558" source="SECUNIA" patch="1" adv="1">19558</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1269" source="VUPEN">ADV-2006-1269</ref>
      <ref url="http://www.osvdb.org/24442" source="OSVDB">24442</ref>
      <ref url="http://mail.python.org/pipermail/mailman-announce/2006-April/000084.html" source="MLIST">[Mailman-Announce] 20060407 Released: Mailman 2.1.8 release candidate</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=129136" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=129136</ref>
      <ref url="http://www.mail-archive.com/mailman-checkins@python.org/msg06273.html" source="CONFIRM">http://www.mail-archive.com/mailman-checkins@python.org/msg06273.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1713" published="2006-04-11" name="CVE-2006-1713" modified="2008-09-05" discovered="2006-04-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17420" source="BID">17420</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430480/100/0/threaded" source="BUGTRAQ" adv="1">20060410 phpMyForum Cross Site Scripting &amp; CRLF injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25742" source="XF">phpmyforum-index-xss(25742)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432455/100/0/threaded" source="BUGTRAQ">20060425 Re: phpMyForum Cross Site Scripting &amp; CRLF injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyforum" name="phpmyforum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1714" published="2006-04-11" name="CVE-2006-1714" modified="2008-09-05" discovered="2006-04-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject HTTP headers via hex-encoded CRLF sequences in the type parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17420" source="BID">17420</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430480/100/0/threaded" source="BUGTRAQ" adv="1">20060410 phpMyForum Cross Site Scripting &amp; CRLF injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25750" source="XF">phpmyforum-index-crlf-injection(25750)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432455/100/0/threaded" source="BUGTRAQ">20060425 Re: phpMyForum Cross Site Scripting &amp; CRLF injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyforum" name="phpmyforum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1715" published="2006-04-11" name="CVE-2006-1715" modified="2008-09-05" discovered="2006-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Christian Kindahl TUGZip 3.4.0.0, 3.3.0.0, and 3.1.0.2 allow user-assisted attackers to create files in arbitrary directories via a .. (dot dot) in an archive pack with a crafted (1) .gz, (2) .jar, (3) .rar, or (4) .zip file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25713" source="XF">tugzip-archive-directory-traversal(25713)</ref>
      <ref url="http://www.securityfocus.com/bid/17432" source="BID">17432</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430433/100/0/threaded" source="BUGTRAQ" adv="1">20060410 TUGZip Archive Extraction Directory traversal</ref>
      <ref url="http://www.hamid.ir/security/tugzip.txt" source="MISC">http://www.hamid.ir/security/tugzip.txt</ref>
      <ref url="http://securityreason.com/securityalert/686" source="SREASON">686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tugzip" name="tugzip">
        <vers num="3.1.0.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1716" published="2006-04-11" name="CVE-2006-1716" modified="2011-03-07" discovered="2006-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.  NOTE: the email vector is already covered by CVE-2006-1625, although it might stem from the same core issue.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that unauthenticated users are allowed to post new threads (not the default setting).</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25615" source="XF">mybb-email-img-bbcode-xss(25615)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25615" source="XF">mybb-email-bbcode-xss(25615)</ref>
      <ref url="http://www.securityfocus.com/bid/17413" source="BID">17413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430344/100/0/threaded" source="BUGTRAQ" adv="1">20060407 [KAPDA::#38] - MyBB 1.1.0~functions_post.php~XSS Attack</ref>
      <ref url="http://www.osvdb.org/24375" source="OSVDB">24375</ref>
      <ref url="http://secunia.com/advisories/19516" source="SECUNIA" adv="1">19516</ref>
      <ref url="http://myimei.com/security/2006-03-12/mybb-110functions_postphpxss-attack.html" source="MISC">http://myimei.com/security/2006-03-12/mybb-110functions_postphpxss-attack.html</ref>
      <ref url="http://kapda.ir/advisory-305.html" source="MISC" adv="1">http://kapda.ir/advisory-305.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1717" published="2006-04-11" name="CVE-2006-1717" modified="2008-09-05" discovered="2006-04-09" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that unauthenticated users are allowed to post new threads (not the default setting).</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17427" source="BID">17427</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430464/100/0/threaded" source="BUGTRAQ" adv="1">20060409 MyBB 1.10 'newthread.php' &lt; CrossSiteScripting ></ref>
      <ref url="http://secunia.com/advisories/19516" source="SECUNIA" adv="1">19516</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25730" source="XF">mybb-newthread-xss(25730)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1718" published="2006-04-11" name="CVE-2006-1718" modified="2011-03-07" discovered="2006-04-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database username and password via a direct request for connect.inc.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1316" source="VUPEN">ADV-2006-1316</ref>
      <ref url="http://www.securityfocus.com/bid/17461" source="BID">17461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430369/100/0/threaded" source="BUGTRAQ" adv="1">20060407 [ECHO_ADV_28$2006] Clever Copy &lt;= 3.0 Connect.inc Critical Information Disclosure</ref>
      <ref url="http://secunia.com/advisories/19579" source="SECUNIA" adv="1">19579</ref>
      <ref url="http://advisories.echo.or.id/adv/adv28-K-159-2006.txt" source="MISC" adv="1">http://advisories.echo.or.id/adv/adv28-K-159-2006.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25720" source="XF">clevercopy-connect-disclose-information(25720)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="2.0" />
        <vers num="2.0a" />
        <vers num="23.0" />
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1719" published="2006-04-11" name="CVE-2006-1719" modified="2008-09-10" discovered="2006-04-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) via any scrollbar Cascading Style Sheets (CSS) property.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430431/100/0/threaded" source="BUGTRAQ" adv="1">20060410 Re: IE6 Crash</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430408/100/0/threaded" source="BUGTRAQ">20060407 IE6 Crash</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25852" source="XF">ie-css-scrollbar-dos(25852)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1720" published="2006-04-11" name="CVE-2006-1720" modified="2011-03-07" discovered="2006-04-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter.  NOTE: it is possible that this issue is resultant from SQL injection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1317" source="VUPEN">ADV-2006-1317</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430293/100/0/threaded" source="BUGTRAQ" adv="1">20060407 Xss In SaphpLesson3.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25719" source="XF">saphplesson-search-xss(25719)</ref>
      <ref url="http://www.securityfocus.com/bid/17414" source="BID">17414</ref>
      <ref url="http://securitytracker.com/id?1015883" source="SECTRACK">1015883</ref>
      <ref url="http://securityreason.com/securityalert/683" source="SREASON">683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arabless" name="saphplesson">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1721" published="2006-04-11" name="CVE-2006-1721" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17446" source="BID" patch="1">17446</ref>
      <ref url="http://secunia.com/advisories/19618" source="SECUNIA" patch="1" adv="1">19618</ref>
      <ref url="http://labs.musecurity.com/advisories/MU-200604-01.txt" source="MISC" patch="1">http://labs.musecurity.com/advisories/MU-200604-01.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25738" source="XF">cyrus-sasl-digest-dos(25738)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1744" source="VUPEN" adv="1">ADV-2008-1744</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3852" source="VUPEN" adv="1">ADV-2006-3852</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1306" source="VUPEN" adv="1">ADV-2006-1306</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2008-0009.html</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-272-1" source="UBUNTU">USN-272-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded" source="BUGTRAQ">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0878.html" source="REDHAT">RHSA-2007:0878</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0795.html" source="REDHAT">RHSA-2007:0795</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_05.html" source="SUSE">SUSE-SA:2006:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:073" source="MANDRIVA">MDKSA-2006:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-09.xml" source="GENTOO">GLSA-200604-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1042" source="DEBIAN">DSA-1042</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-426.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-426.htm</ref>
      <ref url="http://securitytracker.com/id?1016960" source="SECTRACK">1016960</ref>
      <ref url="http://secunia.com/advisories/30535" source="SECUNIA" adv="1">30535</ref>
      <ref url="http://secunia.com/advisories/27237" source="SECUNIA" adv="1">27237</ref>
      <ref url="http://secunia.com/advisories/26857" source="SECUNIA" adv="1">26857</ref>
      <ref url="http://secunia.com/advisories/26708" source="SECUNIA" adv="1">26708</ref>
      <ref url="http://secunia.com/advisories/22187" source="SECUNIA" adv="1">22187</ref>
      <ref url="http://secunia.com/advisories/20014" source="SECUNIA" adv="1">20014</ref>
      <ref url="http://secunia.com/advisories/19964" source="SECUNIA" adv="1">19964</ref>
      <ref url="http://secunia.com/advisories/19825" source="SECUNIA" adv="1">19825</ref>
      <ref url="http://secunia.com/advisories/19809" source="SECUNIA" adv="1">19809</ref>
      <ref url="http://secunia.com/advisories/19753" source="SECUNIA" adv="1">19753</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9861" source="OVAL">oval:org.mitre.oval:def:9861</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044992.html" source="FULLDISC">20060410 [MU-200604-01] Cyrus SASL DIGEST-MD5 Pre-Authentication Denial of Service</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html" source="APPLE">APPLE-SA-2006-09-29</ref>
      <ref url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&amp;msg=7775" source="CONFIRM">http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&amp;msg=7775</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc" source="SGI">20070901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyrus" name="sasl">
        <vers num="2.1.18" />
        <vers num="2.1.18_r1" />
        <vers num="2.1.18_r2" />
        <vers num="2.1.19" />
        <vers num="2.1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1722" published="2006-04-11" name="CVE-2006-1722" modified="2008-11-03" discovered="2006-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0 allows remote attackers to inject arbitrary web script or HTML via the Suchstring1 (aka search) parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25715" source="XF">shopxs-search-xss(25715)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/shopxs-v40-xss-vuln_10.html" source="MISC">http://pridels0.blogspot.com/2006/04/shopxs-v40-xss-vuln_10.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suche" name="shopxs">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1723" published="2006-04-14" name="CVE-2006-1723" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/350262" source="CERT-VN">VU#350262</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-20.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://securitytracker.com/id?1015921" source="SECTRACK">1015921</ref>
      <ref url="http://securitytracker.com/id?1015920" source="SECTRACK">1015920</ref>
      <ref url="http://securitytracker.com/id?1015919" source="SECTRACK">1015919</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1574" source="OVAL" sig="1">oval:org.mitre.oval:def:1574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="preview_release" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1724" published="2006-04-14" name="CVE-2006-1724" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: 
  Firefox 1.5.0.2
  Thunderbird 1.5.0.2
  SeaMonkey 1.0.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/350262" source="CERT-VN">VU#350262</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=282105" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=282105</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-20.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10243" source="OVAL">oval:org.mitre.oval:def:10243</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015921" source="SECTRACK">1015921</ref>
      <ref url="http://securitytracker.com/id?1015920" source="SECTRACK">1015920</ref>
      <ref url="http://securitytracker.com/id?1015919" source="SECTRACK">1015919</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1901" source="OVAL" sig="1">oval:org.mitre.oval:def:1901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1725" published="2006-04-14" name="CVE-2006-1725" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: 
  Firefox 1.5.0.2
  SeaMonkey 1.0.1</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=327014" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=327014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25827" source="XF">mozilla-xul-window-spoofing(25827)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN" adv="1">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN" adv="1">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN" adv="1">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-29.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-29.html</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA" adv="1">22066</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA" adv="1">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1471" source="OVAL" sig="1">oval:org.mitre.oval:def:1471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1726" published="2006-04-14" name="CVE-2006-1726" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/968814" source="CERT-VN">VU#968814</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-28.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-28.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25825" source="XF">mozilla-valuetofunctionobject-sec-bypass(25825)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://securitytracker.com/id?1015933" source="SECTRACK">1015933</ref>
      <ref url="http://securitytracker.com/id?1015932" source="SECTRACK">1015932</ref>
      <ref url="http://securitytracker.com/id?1015931" source="SECTRACK">1015931</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA" adv="1">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA" adv="1">22065</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA" adv="1">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1968" source="OVAL" sig="1">oval:org.mitre.oval:def:1968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="preview_release" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1727" published="2006-04-14" name="CVE-2006-1727" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  Thunderbird 1.5.0.2
  Thunderbird 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-25.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-25.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015929" source="SECTRACK">1015929</ref>
      <ref url="http://securitytracker.com/id?1015928" source="SECTRACK">1015928</ref>
      <ref url="http://securitytracker.com/id?1015927" source="SECTRACK">1015927</ref>
      <ref url="http://securitytracker.com/id?1015926" source="SECTRACK">1015926</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10364" source="OVAL">oval:org.mitre.oval:def:10364</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25824" source="XF">mozilla-printpreview-privilege-escalation(25824)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1649" source="OVAL" sig="1">oval:org.mitre.oval:def:1649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1728" published="2006-04-14" name="CVE-2006-1728" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  Thunderbird 1.5.0.2
  Thunderbird 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/932734" source="CERT-VN">VU#932734</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0058" source="VUPEN">ADV-2007-0058</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-24.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-24.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://securitytracker.com/id?1015925" source="SECTRACK">1015925</ref>
      <ref url="http://securitytracker.com/id?1015924" source="SECTRACK">1015924</ref>
      <ref url="http://securitytracker.com/id?1015923" source="SECTRACK">1015923</ref>
      <ref url="http://securitytracker.com/id?1015922" source="SECTRACK">1015922</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10508" source="OVAL">oval:org.mitre.oval:def:10508</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25812" source="XF">mozilla-generatecrmfrequest-code-execution(25812)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1" source="SUNALERT">102763</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1698" source="OVAL" sig="1">oval:org.mitre.oval:def:1698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1729" published="2006-04-14" name="CVE-2006-1729" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25823" source="XF">mozilla-textbox-file-access(25823)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN" adv="1">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN" adv="1">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN" adv="1">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN" adv="1">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT" adv="1">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT" adv="1">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_35_mozilla.html" source="SUSE">SUSE-SA:2006:035</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-23.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-23.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA" adv="1">22066</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA" adv="1">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA" adv="1">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA" adv="1">19696</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA" adv="1">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10922" source="OVAL">oval:org.mitre.oval:def:10922</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1929" source="OVAL" sig="1">oval:org.mitre.oval:def:1929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1730" published="2006-04-14" name="CVE-2006-1730" modified="2011-03-07" discovered="2006-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  Thunderbird 1.5.0.2
  Thunderbird 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/179014" source="CERT-VN" adv="1">VU#179014</ref>
      <ref url="http://securitytracker.com/id?1015918" source="SECTRACK" patch="1">1015918</ref>
      <ref url="http://securitytracker.com/id?1015917" source="SECTRACK" patch="1">1015917</ref>
      <ref url="http://securitytracker.com/id?1015916" source="SECTRACK" patch="1">1015916</ref>
      <ref url="http://securitytracker.com/id?1015915" source="SECTRACK" patch="1">1015915</ref>
      <ref url="http://secunia.com/advisories/19649" source="SECUNIA" patch="1" adv="1">19649</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" patch="1" adv="1">19631</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-010.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-06-010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431060/100/0/threaded" source="BUGTRAQ">20060415 ZDI-06-010: Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT" adv="1">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT" adv="1">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT" adv="1">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-22.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-22.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA" adv="1">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA" adv="1">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10055" source="OVAL">oval:org.mitre.oval:def:10055</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25826" source="XF">mozilla-css-letterspacing-overflow(25826)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://securityreason.com/securityalert/720" source="SREASON">720</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA">22066</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1614" source="OVAL" sig="1">oval:org.mitre.oval:def:1614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1731" published="2006-04-14" name="CVE-2006-1731" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-19.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-19.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9604" source="OVAL">oval:org.mitre.oval:def:9604</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25820" source="XF">mozilla-valueof-xss(25820)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1955" source="OVAL" sig="1">oval:org.mitre.oval:def:1955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1732" published="2006-04-14" name="CVE-2006-1732" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability also affects Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 
This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5
Mozilla, Firefox, 1.0.8
Mozilla, Thunderbird, 1.5
Mozilla, Thunderbird, 1.0.8
Mozilla, SeaMonkey, 1.0
Mozilla, Suite, 1.7.13
</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=313373" source="MISC" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=313373</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-17.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-17.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10232" source="OVAL">oval:org.mitre.oval:def:10232</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25818" source="XF">mozilla-windows-controllers-xss(25818)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1887" source="OVAL" sig="1">oval:org.mitre.oval:def:1887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1733" published="2006-04-14" name="CVE-2006-1733" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inserting an XBL method into the DOM's document.body prototype chain."</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability also affects Mozilla, SeaMonkey, 1.0 and Mozilla, Suite, 1.7.13

This vulnerabiloity is addressed in the following product releases:
Mozilla, Firefox, 1.5
Mozilla, Firefox, 1.0.8
Mozilla, Thunderbird, 1.5
Mozilla, Thunderbird, 1.0.8
Mozilla, SeaMonkey, 1.0
Mozilla, Suite, 1.7.13
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/488774" source="CERT-VN">VU#488774</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-16.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-16.html</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI" patch="1">20060404-01-U</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA" adv="1">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA" adv="1">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10815" source="OVAL">oval:org.mitre.oval:def:10815</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25817" source="XF">mozilla-valueof-code-execution(25817)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2020" source="OVAL" sig="1">oval:org.mitre.oval:def:2020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1734" published="2006-04-14" name="CVE-2006-1734" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/842094" source="CERT-VN">VU#842094</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-15.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-15.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10755" source="OVAL">oval:org.mitre.oval:def:10755</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25816" source="XF">mozilla-cloneparent-code-execution(25816)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1247" source="OVAL" sig="1">oval:org.mitre.oval:def:1247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1735" published="2006-04-14" name="CVE-2006-1735" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/813230" source="CERT-VN">VU#813230</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-14.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-14.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10930" source="OVAL">oval:org.mitre.oval:def:10930</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25815" source="XF">mozilla-xbl-code-execution(25815)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1037" source="OVAL" sig="1">oval:org.mitre.oval:def:1037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1736" published="2006-04-14" name="CVE-2006-1736" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option.  NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=293527" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=293527</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-13.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-13.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25814" source="XF">mozilla-saveimageas-ext-spoofing(25814)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1548" source="OVAL" sig="1">oval:org.mitre.oval:def:1548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1737" published="2006-04-14" name="CVE-2006-1737" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/329500" source="CERT-VN">VU#329500</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-11.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10817" source="OVAL">oval:org.mitre.oval:def:10817</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25808" source="XF">mozilla-javascript-regexpr-memory-corruption(25808)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1829" source="OVAL" sig="1">oval:org.mitre.oval:def:1829</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1738" published="2006-04-14" name="CVE-2006-1738" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/252324" source="CERT-VN">VU#252324</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-11.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9405" source="OVAL">oval:org.mitre.oval:def:9405</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25811" source="XF">mozilla-mozgrid-memory-corruption(25811)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1687" source="OVAL" sig="1">oval:org.mitre.oval:def:1687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1739" published="2006-04-14" name="CVE-2006-1739" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html" source="CERT">TA06-107A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/935556" source="CERT-VN">VU#935556</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID" patch="1">17516</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-11.html</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" patch="1" adv="1">19631</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=265736" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=265736</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">HPSBTU02118</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA" adv="1">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA" adv="1">19794</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA" adv="1">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA" adv="1">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA" adv="1">19696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9817" source="OVAL">oval:org.mitre.oval:def:9817</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25810" source="XF">mozilla-css-memory-corruption(25810)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1667" source="OVAL" sig="1">oval:org.mitre.oval:def:1667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1740" published="2006-04-14" name="CVE-2006-1740" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=271194" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=271194</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-12.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-12.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10424" source="OVAL">oval:org.mitre.oval:def:10424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25813" source="XF">mozilla-secure-site-spoofing(25813)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1811" source="OVAL" sig="1">oval:org.mitre.oval:def:1811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1741" published="2006-04-14" name="CVE-2006-1741" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Mozilla Suite 1.7.13
  SeaMonkey 1.0</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25806" source="XF">mozilla-eventhandler-xss(25806)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-09.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-09.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA" adv="1">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA" adv="1">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA" adv="1">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA" adv="1">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA" adv="1">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA" adv="1">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA" adv="1">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA" adv="1">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA" adv="1">19821</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA" adv="1">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA" adv="1">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA" adv="1">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA" adv="1">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA" adv="1">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA" adv="1">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9167" source="OVAL">oval:org.mitre.oval:def:9167</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1855" source="OVAL" sig="1">oval:org.mitre.oval:def:1855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
        <vers prev="1" num="1.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1742" published="2006-04-14" name="CVE-2006-1742" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/492382" source="CERT-VN">VU#492382</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-10.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-10.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11808" source="OVAL">oval:org.mitre.oval:def:11808</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25807" source="XF">mozilla-garbage-memory-corruption(25807)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA">19794</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19696" source="SECUNIA">19696</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA">19631</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1087" source="OVAL" sig="1">oval:org.mitre.oval:def:1087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
      </prod>
      <prod vendor="mozilla" name="mozilla_suite">
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers prev="1" num="1.7.12" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":alpha" />
        <vers prev="1" num="1.0" edition="beta" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
        <vers num="1.5" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1743" published="2006-04-12" name="CVE-2006-1743" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in form.php in JBook 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) nom or (2) mail parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1315" source="VUPEN">ADV-2006-1315</ref>
      <ref url="http://www.securityfocus.com/bid/17458" source="BID">17458</ref>
      <ref url="http://secunia.com/advisories/19613" source="SECUNIA" adv="1">19613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25735" source="XF">jbook-form-sql-injection(25735)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbook" name="jbook">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1744" published="2006-04-12" name="CVE-2006-1744" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24634" source="OSVDB" patch="1">24634</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1036" source="DEBIAN" patch="1" adv="1">DSA-1036</ref>
      <ref url="http://secunia.com/advisories/19687" source="SECUNIA" patch="1" adv="1">19687</ref>
      <ref url="http://www.securityfocus.com/bid/17401" source="BID">17401</ref>
      <ref url="http://www.pulltheplug.org/fu/?q=node/56" source="MISC">http://www.pulltheplug.org/fu/?q=node/56</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360989" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360989</ref>
      <ref url="http://securityreason.com/securityalert/736" source="SREASON">736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joey_hess" name="bsdgames">
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.17" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1745" published="2006-04-12" name="CVE-2006-1745" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1370" source="VUPEN">ADV-2006-1370</ref>
      <ref url="http://www.securityfocus.com/bid/17406" source="BID">17406</ref>
      <ref url="http://secunia.com/advisories/19673" source="SECUNIA">19673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitweaver" name="bitweaver">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1746" published="2006-04-12" name="CVE-2006-1746" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/430597" source="BUGTRAQ" patch="1">20060411 Re: PHPList &lt;= 2.10.2 remote commands execution</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1296" source="VUPEN">ADV-2006-1296</ref>
      <ref url="http://www.securityfocus.com/bid/17429" source="BID">17429</ref>
      <ref url="http://www.securityfocus.com/archive/1/448411" source="BUGTRAQ">20061012 new version of phplist fix XSS vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/430475/30/30/threaded" source="BUGTRAQ">20060410 PHPList &lt;= 2.10.2 remote commands execution</ref>
      <ref url="http://tincan.co.uk/?lid=851" source="CONFIRM">http://tincan.co.uk/?lid=851</ref>
      <ref url="http://securitytracker.com/id?1015889" source="SECTRACK">1015889</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/PHPList-lfi.php" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/PHPList-lfi.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25701" source="XF">phplist-index-file-include(25701)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tincan" name="phplist">
        <vers num="2.10.1" />
        <vers prev="1" num="2.10.2" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.8.12" />
        <vers num="2.8.2" />
        <vers num="2.8.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1747" published="2006-04-12" name="CVE-2006-1747" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder.  NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17443" source="BID">17443</ref>
      <ref url="http://www.blogcu.com/Liz0ziM/431925/" source="MISC">http://www.blogcu.com/Liz0ziM/431925/</ref>
      <ref url="http://liz0zim.no-ip.org/vwar.txt" source="MISC">http://liz0zim.no-ip.org/vwar.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28265" source="XF">virtualwar-member-file-include(28265)</ref>
      <ref url="http://www.securityfocus.com/bid/19387" source="BID">19387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430389/100/0/threaded" source="BUGTRAQ">20060408 Virtual War File &amp;#304;nclusion</ref>
      <ref url="http://milw0rm.com/exploits/1658" source="MILW0RM">1658</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=115497619330609&amp;w=2" source="BUGTRAQ">20060807 Virtual War v1.5.0 Remote File Include (vwar_root)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vwar" name="virtual_war">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1748" published="2006-04-12" name="CVE-2006-1748" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling ActionScript.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17445" source="BID">17445</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430432/100/0/threaded" source="BUGTRAQ">20060409 XMB Forum 1.9.5-Final XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25737" source="XF">xmb-swf-geturl-xss(25737)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_software" name="xmb_forum">
        <vers num="1.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1749" published="2006-04-12" name="CVE-2006-1749" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter.  NOTE: this issue was later reported to affect 2.01 as well.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25760" source="XF">phplistpro-config-file-include(25760)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1325" source="VUPEN" adv="1">ADV-2006-1325</ref>
      <ref url="http://www.securityfocus.com/bid/17448" source="BID">17448</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433562/100/0/threaded" source="BUGTRAQ">20060508 PhpListPro 2.01 Remote File Include Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/430614" source="BUGTRAQ">20060411 phpListPro &lt;= 2.0 - Remote File Include Vulnerability</ref>
      <ref url="http://www.osvdb.org/24540" source="OSVDB">24540</ref>
      <ref url="http://secunia.com/advisories/19625" source="SECUNIA" adv="1">19625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartisoft" name="phplistpro">
        <vers prev="1" num="2.0" />
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1750" published="2006-04-12" name="CVE-2006-1750" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Autogallery 0.41 allow remote attackers to inject arbitrary web script or HTML via the (1) pic or (2) show parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25756" source="XF">autogallery-index-xss(25756)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1328" source="VUPEN" adv="1">ADV-2006-1328</ref>
      <ref url="http://www.securityfocus.com/bid/17480" source="BID">17480</ref>
      <ref url="http://www.elitemexico.org/12.txt" source="MISC">http://www.elitemexico.org/12.txt</ref>
      <ref url="http://secunia.com/advisories/19629" source="SECUNIA" adv="1">19629</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0220.html" source="FULLDISC">20060411 Autogallery Multiple Cross-Site Scripting Vulnerabilitie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jmb_software" name="autogallery">
        <vers num="0.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1751" published="2006-04-12" name="CVE-2006-1751" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17481" source="BID" patch="1">17481</ref>
      <ref url="http://secunia.com/advisories/19634" source="SECUNIA" patch="1" adv="1">19634</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25765" source="XF">mvblog-multiple-sql-injection(25765)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1330" source="VUPEN" adv="1">ADV-2006-1330</ref>
      <ref url="http://dev.mvblog.org/cgi-bin/trac.cgi/ticket/54" source="CONFIRM">http://dev.mvblog.org/cgi-bin/trac.cgi/ticket/54</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michiel_van_baak" name="mvblog">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1752" published="2006-04-12" name="CVE-2006-1752" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the backend in MvBlog before 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) body fields in a comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19634" source="SECUNIA" patch="1" adv="1">19634</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1330" source="VUPEN">ADV-2006-1330</ref>
      <ref url="http://www.securityfocus.com/bid/17481" source="BID">17481</ref>
      <ref url="http://dev.mvblog.org/cgi-bin/trac.cgi/ticket/55" source="CONFIRM">http://dev.mvblog.org/cgi-bin/trac.cgi/ticket/55</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25767" source="XF">mvblog-comment-xss(25767)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michiel_van_baak" name="mvblog">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1753" published="2006-04-18" name="CVE-2006-1753" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
Fcheck, 2.7.59-7sarge1
Fcheck, 2.7.59-8
</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us.debian.org/security/2006/dsa-1035" source="DEBIAN" patch="1" adv="1">DSA-1035</ref>
      <ref url="http://secunia.com/advisories/19675" source="SECUNIA" patch="1" adv="1">19675</ref>
      <ref url="http://www.securityfocus.com/bid/17524" source="BID">17524</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25830" source="XF">fcheck-tmpfile-symlink(25830)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":ia-32" />
        <vers num="3.1" edition="r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1754" published="2006-04-12" name="CVE-2006-1754" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19611" source="SECUNIA" patch="1" adv="1">19611</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1331" source="VUPEN">ADV-2006-1331</ref>
      <ref url="http://www.securityfocus.com/bid/17476" source="BID">17476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430671/100/0/threaded" source="BUGTRAQ">20060411 Confixx 3.1.2 &lt;= SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25749" source="XF">confixx-index-sql-injection(25749)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431421/100/0/threaded" source="BUGTRAQ">20060419 Confixx SQL Injection exploit (confixx_exploit.pl)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430890/100/0/threaded" source="BUGTRAQ">20060413 Re: Confixx 3.1.2 &lt;= SQL Injection</ref>
      <ref url="http://download1.swsoft.com/Confixx/security_hotfix/release_notes.txt" source="CONFIRM">http://download1.swsoft.com/Confixx/security_hotfix/release_notes.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swsoft" name="confixx">
        <vers num="3.0.6" />
        <vers num="3.0.8" />
        <vers num="3.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1755" published="2006-04-12" name="CVE-2006-1755" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1259" source="VUPEN">ADV-2006-1259</ref>
      <ref url="http://www.securityfocus.com/bid/17394" source="BID">17394</ref>
      <ref url="http://secunia.com/advisories/19530" source="SECUNIA" adv="1">19530</ref>
      <ref url="http://evuln.com/vulns/120/summary.html" source="MISC">http://evuln.com/vulns/120/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25635" source="XF">mdnews-admin-sql-injection(25635)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431429/100/0/threaded" source="BUGTRAQ">20060418 [eVuln] MD News Authentication Bypass and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24454" source="OSVDB">24454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthew_dingley" name="md_news">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1756" published="2006-04-12" name="CVE-2006-1756" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1259" source="VUPEN">ADV-2006-1259</ref>
      <ref url="http://www.securityfocus.com/bid/17394" source="BID">17394</ref>
      <ref url="http://secunia.com/advisories/19530" source="SECUNIA" adv="1">19530</ref>
      <ref url="http://evuln.com/vulns/120/summary.html" source="MISC">http://evuln.com/vulns/120/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25636" source="XF">mdnews-admin-security-bypass(25636)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431429/100/0/threaded" source="BUGTRAQ">20060418 [eVuln] MD News Authentication Bypass and SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24455" source="OSVDB">24455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthew_dingley" name="md_news">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1757" published="2006-04-12" name="CVE-2006-1757" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Vegadns 0.99 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17433" source="BID">17433</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430474/100/0/threaded" source="BUGTRAQ">20060410 Vegadns blind sql injection and cross site scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bill_shupp" name="vegadns">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1758" published="2006-04-12" name="CVE-2006-1758" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Vegadns 0.99 allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1298" source="VUPEN">ADV-2006-1298</ref>
      <ref url="http://www.securityfocus.com/bid/17433" source="BID">17433</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430474/100/0/threaded" source="BUGTRAQ">20060410 Vegadns blind sql injection and cross site scripting</ref>
      <ref url="http://secunia.com/advisories/19614" source="SECUNIA" adv="1">19614</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25741" source="XF">vegadns-index-sql-injection(25741)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bill_shupp" name="vegadns">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1759" published="2006-04-12" name="CVE-2006-1759" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19611" source="SECUNIA" patch="1" adv="1">19611</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1331" source="VUPEN">ADV-2006-1331</ref>
      <ref url="http://www.securityfocus.com/bid/17466" source="BID">17466</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430596/100/0/threaded" source="BUGTRAQ">20060410 Confixx 3.1.2 &lt;= Cross Site Scripting Vuln</ref>
      <ref url="http://securitytracker.com/id?1015890" source="SECTRACK">1015890</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25748" source="XF">confixx-transfer-xss(25748)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swsoft" name="confixx">
        <vers num="3.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1760" published="2006-04-12" name="CVE-2006-1760" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25745" source="XF">jetphoto-name-page-xss(25745)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1300" source="VUPEN">ADV-2006-1300</ref>
      <ref url="http://www.securityfocus.com/bid/17449" source="BID">17449</ref>
      <ref url="http://www.osvdb.org/24494" source="OSVDB">24494</ref>
      <ref url="http://www.osvdb.org/24493" source="OSVDB">24493</ref>
      <ref url="http://www.osvdb.org/24492" source="OSVDB">24492</ref>
      <ref url="http://www.osvdb.org/24491" source="OSVDB">24491</ref>
      <ref url="http://secunia.com/advisories/19603" source="SECUNIA" adv="1">19603</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114472089719033&amp;w=2" source="FULLDISC" adv="1">20060411 JetPhoto Multiple Cross-Site Scripting Vulnerabilitie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jetphotosoft.com" name="jetphoto">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1761" published="2006-04-12" name="CVE-2006-1761" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17465" source="BID">17465</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430607/100/0/threaded" source="BUGTRAQ">20060411 Multiple vulnerabilities in Blur6ex</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-April/000691.html" source="VIM">20060412 Multiple vulnerabilities in Blur6ex (fwd)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25757" source="XF">blur6ex-index-xss(25757)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430885/100/0/threaded" source="BUGTRAQ">20060413 Re: Multiple vulnerabilities in Blur6ex</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blursoft" name="blur6ex">
        <vers num="0.3.462" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1762" published="2006-04-12" name="CVE-2006-1762" modified="2009-04-08" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter.  NOTE: this issue can be exploited to produce resultant XSS when the parameter has XSS manipulations, and path disclosure with other invalid values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17465" source="BID">17465</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/491565/100/0/threaded" source="BUGTRAQ">20080502 blur6ex-0.3.462 LOCAL FILE INCLUSION Vulnerbility</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430607/100/0/threaded" source="BUGTRAQ" adv="1">20060411 Multiple vulnerabilities in Blur6ex</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-April/000691.html" source="VIM">20060412 Multiple vulnerabilities in Blur6ex (fwd)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25758" source="XF">blur6ex-index-path-disclosure(25758)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430885/100/0/threaded" source="BUGTRAQ">20060413 Re: Multiple vulnerabilities in Blur6ex</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blursoft" name="blur6ex">
        <vers num="0.3.462" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1763" published="2006-04-12" name="CVE-2006-1763" modified="2008-09-05" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_permaPost action to the blog shard (engine/shards/blog.php), or a (3) g_viewContent action to the content shard (engine/shards/content.php).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17465" source="BID">17465</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430607/100/0/threaded" source="BUGTRAQ" adv="1">20060411 Multiple vulnerabilities in Blur6ex</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25759" source="XF">blur6ex-index-sql-injection(25759)</ref>
      <ref url="http://securityreason.com/securityalert/689" source="SREASON">689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blursoft" name="blur6ex">
        <vers num="0.3.462" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1764" published="2006-04-12" name="CVE-2006-1764" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1268" source="VUPEN">ADV-2006-1268</ref>
      <ref url="http://www.osvdb.org/24447" source="OSVDB">24447</ref>
      <ref url="http://secunia.com/advisories/19569" source="SECUNIA" adv="1">19569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="1.1" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4b" />
        <vers num="2002" />
        <vers num="2002_rc_1" />
        <vers num="6.1" />
        <vers num="6.1_hotfix_1.4" />
        <vers num="6.1_hotfix_1.7" />
        <vers num="6.1_hotfix_1.9" />
        <vers num="6.1_hotfix_2.0" />
        <vers num="6.1_hotfix_2.1" />
        <vers num="6.1_hotfix_2.3" />
        <vers num="6.1_hotfix_2.8" />
        <vers prev="1" num="6.1_hotfix_2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1765" published="2006-04-13" name="CVE-2006-1765" modified="2008-09-05" discovered="2006-04-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in JBook 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17419" source="BID">17419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430479/100/0/threaded" source="BUGTRAQ" adv="1">20060410 Jbook Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25734" source="XF">jbook-index-xss(25734)</ref>
      <ref url="http://secunia.com/advisories/19613" source="SECUNIA">19613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbook" name="jbook">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1766" published="2006-04-13" name="CVE-2006-1766" modified="2008-11-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.php, (3) menuid parameter in (b) plugin.php and (c) forumthread.php, and (4) msgid parameter in forumthread.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25728" source="XF">papoo-multiple-scripts-sql-injection(25728)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/papoo-multiple-sql-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/papoo-multiple-sql-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="papoo" name="papoo">
        <vers num="2.1.2" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers prev="1" num="3_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1767" published="2006-04-13" name="CVE-2006-1767" modified="2008-09-05" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6) detail.php, (7) fav.php, (8) get_rated.php, (9) login.php, (10) mailing_list.php, (11) new.php, (12) modify.php, (13) pick.php, (14) power_search.php, (15) rating.php, (16) register.php, (17) review.php, (18) rss.php, (19) search.php, (20) send_pwd.php, (21) sendmail.php, (22) tell_friend.php, (23) top_rated.php, (24) user_detail.php, and (25) user_search.php; and the (26) base_path parameter in invoice.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17470" source="BID">17470</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430599/100/0/threaded" source="BUGTRAQ" adv="1">20060411 INDEXU &lt;= 5.0.1 (theme_path)and (base_path) Remote File Inclusion Exploit</ref>
      <ref url="http://securitytracker.com/id?1015891" source="SECTRACK">1015891</ref>
      <ref url="http://www.osvdb.org/28427" source="OSVDB">28427</ref>
      <ref url="http://www.osvdb.org/28426" source="OSVDB">28426</ref>
      <ref url="http://www.osvdb.org/28425" source="OSVDB">28425</ref>
      <ref url="http://www.osvdb.org/28422" source="OSVDB">28422</ref>
      <ref url="http://www.osvdb.org/28419" source="OSVDB">28419</ref>
      <ref url="http://www.osvdb.org/28417" source="OSVDB">28417</ref>
      <ref url="http://www.osvdb.org/28416" source="OSVDB">28416</ref>
      <ref url="http://www.osvdb.org/28415" source="OSVDB">28415</ref>
      <ref url="http://www.osvdb.org/28413" source="OSVDB">28413</ref>
      <ref url="http://www.osvdb.org/28412" source="OSVDB">28412</ref>
      <ref url="http://www.osvdb.org/28410" source="OSVDB">28410</ref>
      <ref url="http://www.osvdb.org/28409" source="OSVDB">28409</ref>
      <ref url="http://www.osvdb.org/28406" source="OSVDB">28406</ref>
      <ref url="http://www.osvdb.org/24597" source="OSVDB">24597</ref>
      <ref url="http://www.osvdb.org/24596" source="OSVDB">24596</ref>
      <ref url="http://securitytracker.com/id?1016331" source="SECTRACK">1016331</ref>
      <ref url="http://ftp.kep.online.fr/Indexu_5.0.1_File_Inclusion_Exploit-by_King-Hacker_and-Khamaileon.txt" source="MISC">http://ftp.kep.online.fr/Indexu_5.0.1_File_Inclusion_Exploit-by_King-Hacker_and-Khamaileon.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicecoder" name="indexu">
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1768" published="2006-04-13" name="CVE-2006-1768" modified="2011-03-07" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">Succesful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1329" source="VUPEN">ADV-2006-1329</ref>
      <ref url="http://www.securityfocus.com/bid/17473" source="BID">17473</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430669/100/0/threaded" source="BUGTRAQ" adv="1">20060411 Tritanium Bulletin Board 1.2.3 - XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25751" source="XF">tritaniumbb-register-xss(25751)</ref>
      <ref url="http://www.osvdb.org/24556" source="OSVDB">24556</ref>
      <ref url="http://secunia.com/advisories/19635" source="SECUNIA">19635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tritanium_scripts" name="tritanium_bulletin_board">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1769" published="2006-04-13" name="CVE-2006-1769" modified="2008-09-05" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila 9.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the mode parameter in msgReader$1 and (2) the end of the URI in viewDepartment$.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17475" source="BID">17475</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430668/100/0/threaded" source="BUGTRAQ" adv="1">20060411 Manila &lt;= 9.5 - XSS Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25753" source="XF">manila-multiple-xss(25753)</ref>
      <ref url="http://www.osvdb.org/24554" source="OSVDB">24554</ref>
      <ref url="http://securityreason.com/securityalert/692" source="SREASON">692</ref>
      <ref url="http://secunia.com/advisories/19636" source="SECUNIA">19636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="userland" name="manila">
        <vers num="9.4" />
        <vers prev="1" num="9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1770" published="2006-04-13" name="CVE-2006-1770" modified="2011-03-07" discovered="2006-04-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design &amp; Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1324" source="VUPEN">ADV-2006-1324</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430691/100/0/threaded" source="BUGTRAQ" adv="1">20060411 AzDGVote File inclusion</ref>
      <ref url="http://secunia.com/advisories/19630" source="SECUNIA" adv="1">19630</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25762" source="XF">azdgvote-intpath-file-inclusion(25762)</ref>
      <ref url="http://www.securityfocus.com/bid/17447" source="BID">17447</ref>
      <ref url="http://securityreason.com/securityalert/695" source="SREASON">695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azerbaijan_development_group" name="azdgvote">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1771" published="2006-04-13" name="CVE-2006-1771" modified="2011-03-07" discovered="2006-04-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote attackers to read arbitrary files and possibly execute arbitrary programs via a .. (dot dot) in the url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25768" source="XF">saxopress-pbcs-directory-traversal(25768)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1327" source="VUPEN">ADV-2006-1327</ref>
      <ref url="http://www.securityfocus.com/bid/17474" source="BID">17474</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431037/30/5580/threaded" source="BUGTRAQ">20060412 Re: SAXoPRESS - directory traversal aka Saxotech Online</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430707/100/0/threaded" source="BUGTRAQ" adv="1">20060411 SAXoPRESS - directory traversal</ref>
      <ref url="http://secunia.com/advisories/19566" source="SECUNIA" adv="1">19566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saxotech" name="saxopress">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1772" published="2006-04-13" name="CVE-2006-1772" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cleartext database administrator password in the mnogosearch-common/database_admin_pass record, which allows local users to view the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17477" source="BID">17477</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361775" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361775</ref>
      <ref url="http://secunia.com/advisories/19589" source="SECUNIA">19589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1773" published="2006-04-13" name="CVE-2006-1773" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17467" source="BID">17467</ref>
      <ref url="http://www.hamid.ir/security/phpkit.txt" source="MISC">http://www.hamid.ir/security/phpkit.txt</ref>
      <ref url="http://securitytracker.com/id?1015888" source="SECTRACK">1015888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25743" source="XF">phpkit-contentid-sql-injection(25743)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers prev="1" num="1.6.1" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1774" published="2006-04-13" name="CVE-2006-1774" modified="2008-09-05" discovered="2005-12-12" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.</descript>
    </desc>
    <sols>
      <sol source="nvd">The only way to prevent this is to set the Trust level to "Trust by Certificates"</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430688/100/0/threaded" source="BUGTRAQ">20060411 [SRC-Telindus advisory] - HP System Management Homepage Remote Unauthorized Access</ref>
      <ref url="http://src.telindus.com/articles/hpsm_vulnerability.html" source="MISC">http://src.telindus.com/articles/hpsm_vulnerability.html</ref>
      <ref url="http://securitytracker.com/id?1015901" source="SECTRACK">1015901</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25761" source="XF">hp-smh-auth-bypass(25761)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="compaqhttpserver">
        <vers num="9.9" />
      </prod>
      <prod vendor="hp" name="system_management_homepage">
        <vers num="2.1.3.132" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1775" published="2006-04-13" name="CVE-2006-1775" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php.  NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24357" source="OSVDB">24357</ref>
      <ref url="http://www.osvdb.org/24356" source="OSVDB">24356</ref>
      <ref url="http://www.osvdb.org/24355" source="OSVDB">24355</ref>
      <ref url="http://www.osvdb.org/24354" source="OSVDB">24354</ref>
      <ref url="http://osvdb.org/ref/24/24353-phpbb.txt" source="MISC">http://osvdb.org/ref/24/24353-phpbb.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1776" published="2006-04-13" name="CVE-2006-1776" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the s parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1332" source="VUPEN">ADV-2006-1332</ref>
      <ref url="http://www.securityfocus.com/bid/17490" source="BID">17490</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" source="BUGTRAQ">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24559" source="OSVDB">24559</ref>
      <ref url="http://securitytracker.com/id?1015904" source="SECTRACK">1015904</ref>
      <ref url="http://secunia.com/advisories/19628" source="SECUNIA" adv="1">19628</ref>
      <ref url="http://retrogod.altervista.org/simplog_092_incl_xpl.html" source="MISC">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
      <ref url="http://milw0rm.com/exploits/1663" source="MILW0RM">1663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25775" source="XF">simplog-index-file-include(25775)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1777" published="2006-04-13" name="CVE-2006-1777" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1332" source="VUPEN">ADV-2006-1332</ref>
      <ref url="http://www.securityfocus.com/bid/17490" source="BID">17490</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" source="BUGTRAQ">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24559" source="OSVDB">24559</ref>
      <ref url="http://securitytracker.com/id?1015904" source="SECTRACK">1015904</ref>
      <ref url="http://secunia.com/advisories/19628" source="SECUNIA" adv="1">19628</ref>
      <ref url="http://retrogod.altervista.org/simplog_092_incl_xpl.html" source="MISC">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
      <ref url="http://milw0rm.com/exploits/1663" source="MILW0RM">1663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25775" source="XF">simplog-index-file-include(25775)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1778" published="2006-04-13" name="CVE-2006-1778" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) blogid parameter in (a) index.php and (b) archive.php, the (2) m and (3) y parameters in archive.php, and the (4) sql parameter in (c) server.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1332" source="VUPEN">ADV-2006-1332</ref>
      <ref url="http://www.securityfocus.com/bid/17491" source="BID">17491</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" source="BUGTRAQ">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24561" source="OSVDB">24561</ref>
      <ref url="http://www.osvdb.org/24560" source="OSVDB">24560</ref>
      <ref url="http://securitytracker.com/id?1015904" source="SECTRACK">1015904</ref>
      <ref url="http://secunia.com/advisories/19628" source="SECUNIA" adv="1">19628</ref>
      <ref url="http://retrogod.altervista.org/simplog_092_incl_xpl.html" source="MISC">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
      <ref url="http://milw0rm.com/exploits/1663" source="MILW0RM">1663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25776" source="XF">simplog-index-archive-sql-injection(25776)</ref>
      <ref url="http://securityreason.com/securityalert/702" source="SREASON">702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1779" published="2006-04-13" name="CVE-2006-1779" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1332" source="VUPEN">ADV-2006-1332</ref>
      <ref url="http://www.securityfocus.com/bid/17493" source="BID">17493</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" source="BUGTRAQ">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24562" source="OSVDB">24562</ref>
      <ref url="http://securitytracker.com/id?1015904" source="SECTRACK">1015904</ref>
      <ref url="http://secunia.com/advisories/19628" source="SECUNIA" adv="1">19628</ref>
      <ref url="http://retrogod.altervista.org/simplog_092_incl_xpl.html" source="MISC">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
      <ref url="http://milw0rm.com/exploits/1663" source="MILW0RM">1663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25778" source="XF">simplog-login-xss(25778)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1780" published="2006-04-13" name="CVE-2006-1780" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patches.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19627" source="SECUNIA" patch="1" adv="1">19627</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1333" source="VUPEN">ADV-2006-1333</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102282-1" source="SUNALERT">102282</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25744" source="XF">solaris-sh-dos(25744)</ref>
      <ref url="http://www.securityfocus.com/bid/17478" source="BID">17478</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm</ref>
      <ref url="http://securitytracker.com/id?1015902" source="SECTRACK">1015902</ref>
      <ref url="http://secunia.com/advisories/21493" source="SECUNIA">21493</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:881" source="OVAL" sig="1">oval:org.mitre.oval:def:881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1781" published="2006-04-13" name="CVE-2006-1781" modified="2011-08-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.  NOTE: It was later reported that 1.4.2 and earlier are affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25774" source="XF">monstertoplist-functions-file-include(25774)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1350" source="VUPEN" adv="1">ADV-2006-1350</ref>
      <ref url="http://www.securityfocus.com/bid/23074" source="BID">23074</ref>
      <ref url="http://www.securityfocus.com/bid/17546" source="BID">17546</ref>
      <ref url="http://www.osvdb.org/24650" source="OSVDB">24650</ref>
      <ref url="http://www.milw0rm.com/exploits/3530" source="MILW0RM">3530</ref>
      <ref url="http://secunia.com/advisories/19688" source="SECUNIA" adv="1">19688</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/monstertoplist.html" source="MISC">http://pridels0.blogspot.com/2006/04/monstertoplist.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="circle_r" name="monster_top_list">
        <vers prev="1" num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1782" published="2006-04-13" name="CVE-2006-1782" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1334" source="VUPEN">ADV-2006-1334</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102113-1" source="SUNALERT">102113</ref>
      <ref url="http://secunia.com/advisories/19638" source="SECUNIA" adv="1">19638</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25747" source="XF">solaris-ldap2-password-disclosure(25747)</ref>
      <ref url="http://www.securityfocus.com/bid/17479" source="BID">17479</ref>
      <ref url="http://www.osvdb.org/24568" source="OSVDB">24568</ref>
      <ref url="http://www.osvdb.org/24567" source="OSVDB">24567</ref>
      <ref url="http://www.osvdb.org/24566" source="OSVDB">24566</ref>
      <ref url="http://www.osvdb.org/24565" source="OSVDB">24565</ref>
      <ref url="http://www.osvdb.org/24564" source="OSVDB">24564</ref>
      <ref url="http://www.osvdb.org/24563" source="OSVDB">24563</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm</ref>
      <ref url="http://securitytracker.com/id?1015903" source="SECTRACK">1015903</ref>
      <ref url="http://secunia.com/advisories/21493" source="SECUNIA">21493</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1840" source="OVAL" sig="1">oval:org.mitre.oval:def:1840</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1783" published="2006-04-13" name="CVE-2006-1783" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17495" source="BID">17495</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430868/100/0/threaded" source="BUGTRAQ">20060412 PatroNet CMS Xss Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="patronet" name="cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1784" published="2006-04-13" name="CVE-2006-1784" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1341" source="VUPEN">ADV-2006-1341</ref>
      <ref url="http://www.securityfocus.com/bid/17514" source="BID">17514</ref>
      <ref url="http://secunia.com/advisories/19642" source="SECUNIA" adv="1">19642</ref>
      <ref url="http://milw0rm.com/exploits/1665" source="MILW0RM">1665</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25780" source="XF">sphider-configset-file-inclusion(25780)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sphider" name="sphider">
        <vers num="1.3" />
        <vers num="1.3_rc1" />
        <vers num="1.3_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1785" published="2006-04-13" name="CVE-2006-1785" modified="2011-03-07" discovered="2005-07-26" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext.  NOTE: it is not clear whether the vendor advisory addresses this issue.  In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1342" source="VUPEN">ADV-2006-1342</ref>
      <ref url="http://www.adobe.com/support/techdocs/322699.html" source="MISC" adv="1">http://www.adobe.com/support/techdocs/322699.html</ref>
      <ref url="http://secunia.com/secunia_research/2005-68/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-68/advisory/</ref>
      <ref url="http://secunia.com/advisories/15924" source="SECUNIA" adv="1">15924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25770" source="XF">adobe-readerurl-xss(25770)</ref>
      <ref url="http://www.securityfocus.com/bid/17500" source="BID">17500</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded" source="BUGTRAQ">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24588" source="OSVDB">24588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="document_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":reader_extensions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1786" published="2006-04-13" name="CVE-2006-1786" modified="2011-03-07" discovered="2005-07-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op paremeter in AlterCast.  NOTE: it is not clear whether the vendor advisory addresses this issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1342" source="VUPEN">ADV-2006-1342</ref>
      <ref url="http://www.adobe.com/support/techdocs/322699.html" source="MISC" adv="1">http://www.adobe.com/support/techdocs/322699.html</ref>
      <ref url="http://secunia.com/secunia_research/2005-68/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-68/advisory/</ref>
      <ref url="http://secunia.com/advisories/15924" source="SECUNIA" adv="1">15924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25771" source="XF">adobe-actionid-op-xss(25771)</ref>
      <ref url="http://www.securityfocus.com/bid/17500" source="BID">17500</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded" source="BUGTRAQ">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/24590" source="OSVDB">24590</ref>
      <ref url="http://www.osvdb.org/24589" source="OSVDB">24589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="document_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":reader_extensions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1787" published="2006-04-13" name="CVE-2006-1787" modified="2011-03-07" discovered="2005-07-26" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/331915.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/331915.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1342" source="VUPEN">ADV-2006-1342</ref>
      <ref url="http://www.adobe.com/support/techdocs/322699.html" source="MISC" adv="1">http://www.adobe.com/support/techdocs/322699.html</ref>
      <ref url="http://secunia.com/secunia_research/2005-68/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-68/advisory/</ref>
      <ref url="http://secunia.com/advisories/15924" source="SECUNIA" adv="1">15924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25773" source="XF">adobe-jsessionid-information-disclosure(25773)</ref>
      <ref url="http://www.securityfocus.com/bid/17500" source="BID">17500</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded" source="BUGTRAQ">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="document_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":reader_extensions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1788" published="2006-04-13" name="CVE-2006-1788" modified="2011-03-07" discovered="2005-07-26" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/techdocs/331917.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/techdocs/331917.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1342" source="VUPEN">ADV-2006-1342</ref>
      <ref url="http://secunia.com/secunia_research/2005-68/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2005-68/advisory/</ref>
      <ref url="http://secunia.com/advisories/15924" source="SECUNIA" adv="1">15924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25772" source="XF">adobe-error-account-enumeration(25772)</ref>
      <ref url="http://www.securityfocus.com/bid/17500" source="BID">17500</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded" source="BUGTRAQ">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="document_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":reader_extensions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1789" published="2006-04-13" name="CVE-2006-1789" modified="2011-03-07" discovered="2006-03-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to read arbitrary files via the $className variable.</descript>
    </desc>
    <sols>
      <sol source="nvd">Users of PAJAX should upgrade to the latest version pajax-0.5.2 [1].</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1353" source="VUPEN">ADV-2006-1353</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2006-001.php" source="MISC">http://www.redteam-pentesting.de/advisories/rt-sa-2006-001.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25860" source="XF">pajax-pajaxcalldispatcher-dir-traversal(25860)</ref>
      <ref url="http://www.securityfocus.com/bid/17519" source="BID">17519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431029/100/0/threaded" source="BUGTRAQ">20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref>
      <ref url="http://www.osvdb.org/24862" source="OSVDB">24862</ref>
      <ref url="http://secunia.com/advisories/19653" source="SECUNIA">19653</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0270.html" source="FULLDISC">20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="georges_auberger" name="pajax">
        <vers prev="1" num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1790" published="2006-04-14" name="CVE-2006-1790" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25809" source="XF">mozilla-installtrigger-memory-corruption(25809)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1356" source="VUPEN">ADV-2006-1356</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/17516" source="BID">17516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded" source="FEDORA">FLSA:189137-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded" source="FEDORA">FLSA:189137-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0329.html" source="REDHAT">RHSA-2006:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0328.html" source="REDHAT">RHSA-2006:0328</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html" source="FEDORA">FEDORA-2006-411</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html" source="FEDORA">FEDORA-2006-410</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-11.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076" source="MANDRIVA">MDKSA-2006:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075" source="MANDRIVA">MDKSA-2006:075</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA" adv="1">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA" adv="1">19852</ref>
      <ref url="http://secunia.com/advisories/19811" source="SECUNIA" adv="1">19811</ref>
      <ref url="http://secunia.com/advisories/19794" source="SECUNIA" adv="1">19794</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA" adv="1">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19729" source="SECUNIA">19729</ref>
      <ref url="http://secunia.com/advisories/19721" source="SECUNIA">19721</ref>
      <ref url="http://secunia.com/advisories/19714" source="SECUNIA">19714</ref>
      <ref url="http://secunia.com/advisories/19631" source="SECUNIA" adv="1">19631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11202" source="OVAL">oval:org.mitre.oval:def:11202</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html" source="SUSE">SUSE-SA:2006:021</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc" source="SGI">20060404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1266" source="OVAL" sig="1">oval:org.mitre.oval:def:1266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1791" published="2006-04-14" name="CVE-2006-1791" modified="2008-09-05" discovered="2005-06-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter.  NOTE: this issue can also produce resultant XSS when the associated include statement fails.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430878/100/0/threaded" source="BUGTRAQ" adv="1">20060412 QuickBlogger v1.4 Cross-Site Scripting</ref>
      <ref url="http://secunia.com/advisories/15942" source="SECUNIA" adv="1">15942</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25795" source="XF">quickblogger-acc-xss(25795)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431059/100/0/threaded" source="BUGTRAQ">20060414 Re: QuickBlogger v1.4 Cross-Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jl_webworks" name="quickblogger">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1792" published="2006-04-15" name="CVE-2006-1792" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits".  NOTE: this is a different set of affected versions, and probably a different vulnerability than CVE-2006-1337.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mailenable.com/standardhistory.asp" source="CONFIRM">http://www.mailenable.com/standardhistory.asp</ref>
      <ref url="http://www.mailenable.com/professionalhistory.asp" source="CONFIRM">http://www.mailenable.com/professionalhistory.asp</ref>
      <ref url="http://www.mailenable.com/enterprisehistory.asp" source="CONFIRM">http://www.mailenable.com/enterprisehistory.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.21" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.71" />
        <vers num="1.72" />
        <vers num="1.73" />
      </prod>
      <prod vendor="mailenable" name="mailenable_standard">
        <vers num="1.701" />
        <vers num="1.702" />
        <vers num="1.703" />
        <vers num="1.704" />
        <vers num="1.71" />
        <vers num="1.72" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="1.91" />
        <vers num="1.92" />
        <vers num="1.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1793" published="2006-04-17" name="CVE-2006-1793" modified="2008-09-05" discovered="2006-02-09" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.</descript>
    </desc>
    <sols>
      <sol source="nvd">Succesful exploitation requires that register_globals = On &amp; allow_url_fopen = On</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/424708" source="BUGTRAQ" adv="1">20060209 runCMS &lt;= 1.3a2 possible remote code execution through the integrated FCKEditor package</ref>
      <ref url="http://retrogod.altervista.org/runcms_13a_xpl.html" source="MISC">http://retrogod.altervista.org/runcms_13a_xpl.html</ref>
      <ref url="http://www.securityfocus.com/bid/16578" source="BID">16578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runcms" name="runcms">
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1794" published="2006-04-17" name="CVE-2006-1794" modified="2011-03-07" discovered="2006-02-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16775" source="BID" patch="1">16775</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00104-02242006" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00104-02242006</ref>
      <ref url="http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/" source="CONFIRM" patch="1">http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html" source="BUGTRAQ" patch="1" adv="1">20060224 Mambo Multiple Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0719" source="VUPEN">ADV-2006-0719</ref>
      <ref url="http://www.osvdb.org/23503" source="OSVDB">23503</ref>
      <ref url="http://www.osvdb.org/23402" source="OSVDB">23402</ref>
      <ref url="http://secunia.com/advisories/18935" source="SECUNIA" adv="1">18935</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24951" source="XF">mambo-index2-sql-injection(24951)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers num="4.0.14" />
        <vers num="4.5.1_1.0.9" />
        <vers num="4.5.1a" edition="beta" />
        <vers num="4.5.1a" edition="beta_2" />
        <vers num="4.5.2" />
        <vers num="4.5.2.1" />
        <vers num="4.5.2.2" />
        <vers num="4.5.2.3" />
        <vers prev="1" num="4.5.3h" edition="h" />
        <vers num="4.5_1.0.0" />
        <vers num="4.5_1.0.1" />
        <vers num="4.5_1.0.2" />
        <vers num="4.5_1.0.3_beta" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1795" published="2006-04-17" name="CVE-2006-1795" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24238" source="MISC">http://www.osvdb.org/24238</ref>
      <ref url="http://www.osvdb.org/24238" source="MISC">http://www.osvdb.org/24238</ref>
      <ref url="http://www.securityfocus.com/bid/17642" source="BID">17642</ref>
      <ref url="http://secunia.com/advisories/19723" source="SECUNIA">19723</ref>
    </refs>
    <vuln_soft>
      <prod vendor="updi_network_enterprise" name="at1_event_publisher">
        <vers num="2006-03-23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1796" published="2006-04-17" name="CVE-2006-1796" modified="2008-09-05" discovered="2005-09-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).</descript>
    </desc>
    <sols>
      <sol source="nvd">The vulnerability manifests itself only when viewed by IE.
This vulnerability is addressed in the following product release:
Wordpress 2.0.1-1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://trac.wordpress.org/ticket/1686" source="MISC" patch="1">http://trac.wordpress.org/ticket/1686</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328909" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="0.6.2" edition="beta_2" />
        <vers num="0.6.2.1" edition="beta_2" />
        <vers num="0.7" />
        <vers num="0.71" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
        <vers num="1.5.1.3" />
        <vers num="1.5.2" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1797" published="2006-04-18" name="CVE-2006-1797" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17497" source="BID">17497</ref>
      <ref url="http://securitytracker.com/id?1015908" source="SECTRACK">1015908</ref>
      <ref url="http://secunia.com/advisories/19615" source="SECUNIA" adv="1">19615</ref>
      <ref url="http://archives.neohapsis.com/archives/netbsd/2006-q2/0014.html" source="NETBSD">NetBSD-SA2006-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25766" source="XF">bsd-siocgifalias-ioctl-dos(25766)</ref>
      <ref url="http://www.osvdb.org/24578" source="OSVDB">24578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1798" published="2006-04-18" name="CVE-2006-1798" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1358" source="VUPEN">ADV-2006-1358</ref>
      <ref url="http://secunia.com/advisories/19637" source="SECUNIA" adv="1">19637</ref>
      <ref url="http://evuln.com/vulns/124/summary.html" source="MISC">http://evuln.com/vulns/124/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25801" source="XF">rateit-rateit-sql-injection(25801)</ref>
      <ref url="http://www.securityfocus.com/bid/17518" source="BID">17518</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431859/100/0/threaded" source="BUGTRAQ">20060424 [eVuln] RateIt SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/24622" source="OSVDB">24622</ref>
      <ref url="http://securitytracker.com/id?1015983" source="SECTRACK">1015983</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rateit" name="rateit">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1799" published="2006-04-18" name="CVE-2006-1799" modified="2011-03-07" discovered="2006-04-13" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1352" source="VUPEN">ADV-2006-1352</ref>
      <ref url="http://www.securityfocus.com/bid/17515" source="BID">17515</ref>
      <ref url="http://secunia.com/advisories/19666" source="SECUNIA" adv="1">19666</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25905" source="XF">censtore-page-command-execution(25905)</ref>
      <ref url="http://milw0rm.com/exploits/1669" source="MILW0RM">1669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adcentrix" name="censtore">
        <vers prev="1" num="7.3.002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1800" published="2006-04-18" name="CVE-2006-1800" modified="2008-09-05" discovered="2006-04-12" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.worlddefacers.de/Public/WD-SMPL.txt" source="MISC">http://www.worlddefacers.de/Public/WD-SMPL.txt</ref>
      <ref url="http://www.securityfocus.com/bid/17501" source="BID">17501</ref>
      <ref url="http://www.securityfocus.com/archive/1/430872" source="BUGTRAQ" adv="1">20060412 SimpleBBS v1.1(posts.php) remote command execution</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/SimpleBBS-RCE-posts.php.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/SimpleBBS-RCE-posts.php.pl</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25788" source="XF">simplebbs-posts-command-execution(25788)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplemedia" name="simplebbs">
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1801" published="2006-04-18" name="CVE-2006-1801" modified="2011-03-07" discovered="2006-04-13" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1368" source="VUPEN">ADV-2006-1368</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431033/100/0/threaded" source="BUGTRAQ" adv="1">20060413 planetSearch+ - XSS Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19681" source="SECUNIA" adv="1">19681</ref>
      <ref url="http://d4igoro.blogspot.com/2006/04/planetsearch-xss-vulnerabilities.html" source="MISC">http://d4igoro.blogspot.com/2006/04/planetsearch-xss-vulnerabilities.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25832" source="XF">planetsearchplus-script-xss(25832)</ref>
      <ref url="http://www.securityfocus.com/bid/17527" source="BID">17527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="planet_concept" name="planetsearch+">
        <vers prev="1" num="2005-10-26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1802" published="2006-04-18" name="CVE-2006-1802" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1369" source="VUPEN">ADV-2006-1369</ref>
      <ref url="http://www.securityfocus.com/bid/17536" source="BID">17536</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431069/100/0/threaded" source="BUGTRAQ">20060415 Tiny Web Gallery &lt;= 1.4 XSS</ref>
      <ref url="http://secunia.com/advisories/19660" source="SECUNIA" adv="1">19660</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25831" source="XF">tinywebgallery-index-xss(25831)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436451/30/4560/threaded" source="BUGTRAQ">20060606 Re: Tiny Web Gallery &lt;= 1.4 XSS</ref>
      <ref url="http://securityreason.com/securityalert/717" source="SREASON">717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinywebgallery" name="tinywebgallery">
        <vers num="1.3" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1803" published="2006-04-18" name="CVE-2006-1803" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1372" source="VUPEN">ADV-2006-1372</ref>
      <ref url="http://www.securityfocus.com/bid/17487" source="BID">17487</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431013/100/0/threaded" source="BUGTRAQ">20060414 Re: phpMyAdmin 2.7.0-pl1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430902/100/0/threaded" source="BUGTRAQ">20060412 phpMyAdmin 2.7.0-pl1</ref>
      <ref url="http://secunia.com/advisories/19659" source="SECUNIA" adv="1">19659</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25796" source="XF">phpmyadmin-sql-xss(25796)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.8.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1804" published="2006-04-18" name="CVE-2006-1804" modified="2011-03-07" discovered="2006-04-12" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerbability may affect earlier versions of phpMyAdmin as well.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1372" source="VUPEN">ADV-2006-1372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431013/100/0/threaded" source="BUGTRAQ" adv="1">20060412 phpMyAdmin 2.7.0-pl1</ref>
      <ref url="http://secunia.com/advisories/19659" source="SECUNIA" adv="1">19659</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25858" source="XF">phpmyadmin-sql-sql-injection(25858)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.7.0_pl1" />
        <vers num="2.8.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1805" published="2006-04-18" name="CVE-2006-1805" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19689" source="SECUNIA" patch="1" adv="1">19689</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1371" source="VUPEN">ADV-2006-1371</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431005/100/0/threaded" source="BUGTRAQ">20060413 PowerClan 1.14 - SQL Injection</ref>
      <ref url="http://d4igoro.blogspot.com/2006/04/powerclan-114-sql-injection.html" source="MISC">http://d4igoro.blogspot.com/2006/04/powerclan-114-sql-injection.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25876" source="XF">powerclan-member-sql-injection(25876)</ref>
      <ref url="http://www.securityfocus.com/bid/17528" source="BID">17528</ref>
      <ref url="http://securityreason.com/securityalert/706" source="SREASON">706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerscripts" name="powerclan">
        <vers num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1806" published="2006-04-18" name="CVE-2006-1806" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1373" source="VUPEN">ADV-2006-1373</ref>
      <ref url="http://secunia.com/advisories/19672" source="SECUNIA" adv="1">19672</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27925" source="XF">musicbox-multiple-xss(27925)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25835" source="XF">musicbox-index-xss(25835)</ref>
      <ref url="http://www.securityfocus.com/bid/17545" source="BID">17545</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded" source="BUGTRAQ">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/musicbox-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/musicbox-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicbox" name="musicbox">
        <vers prev="1" num="2.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1807" published="2006-04-18" name="CVE-2006-1807" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1373" source="VUPEN">ADV-2006-1373</ref>
      <ref url="http://secunia.com/advisories/19672" source="SECUNIA" adv="1">19672</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27926" source="XF">musicbox-multiple-sql-injection(27926)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25836" source="XF">musicbox-index-sql-injection(25836)</ref>
      <ref url="http://www.securityfocus.com/bid/17545" source="BID">17545</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded" source="BUGTRAQ">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/musicbox-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/musicbox-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicbox" name="musicbox">
        <vers prev="1" num="2.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1808" published="2006-04-18" name="CVE-2006-1808" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1367" source="VUPEN">ADV-2006-1367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431008/100/0/threaded" source="BUGTRAQ">20060414 Vulnerabilities in lifetype</ref>
      <ref url="http://securitytracker.com/id?1015941" source="SECTRACK">1015941</ref>
      <ref url="http://secunia.com/advisories/19646" source="SECUNIA" adv="1">19646</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25899" source="XF">lifetype-index-xss(25899)</ref>
      <ref url="http://www.securityfocus.com/bid/17529" source="BID">17529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lifetype" name="lifetype">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1809" published="2006-04-18" name="CVE-2006-1809" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431008/100/0/threaded" source="BUGTRAQ">20060414 Vulnerabilities in lifetype</ref>
      <ref url="http://securitytracker.com/id?1015941" source="SECTRACK" adv="1">1015941</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25903" source="XF">lifetype-index-path-disclosure(25903)</ref>
      <ref url="http://securityreason.com/securityalert/711" source="SREASON">711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lifetype" name="lifetype">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1810" published="2006-04-18" name="CVE-2006-1810" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6) Website Address, (7) Email Address, (8) Location, (9) Signature, and (10) Sub-Titles fields in the user profile.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17539" source="BID">17539</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431121/100/0/threaded" source="BUGTRAQ">20060416 FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexbb" name="flexbb">
        <vers num="0.5.5_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1811" published="2006-04-18" name="CVE-2006-1811" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9) Website Address, (10) Email Address, (11) Location, (12) Signature, and (13) Sub-Titles fields in the user profile; or (14) flexbb_password field in a cookie.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431121/100/0/threaded" source="BUGTRAQ">20060416 FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]</ref>
      <ref url="http://www.securityfocus.com/bid/17574" source="BID">17574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexbb" name="flexbb">
        <vers num="0.5.5_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1812" published="2006-04-18" name="CVE-2006-1812" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17557" source="BID">17557</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431115/100/0/threaded" source="BUGTRAQ">20060417 PhpWebFTP 3.2 Login Script</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25921" source="XF">phpwebftp-scriptjs-obtain-information(25921)</ref>
      <ref url="http://secunia.com/advisories/19706" source="SECUNIA">19706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebftp" name="phpwebftp">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1813" published="2006-04-18" name="CVE-2006-1813" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1388" source="VUPEN">ADV-2006-1388</ref>
      <ref url="http://www.securityfocus.com/bid/17557" source="BID">17557</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431115/100/0/threaded" source="BUGTRAQ">20060417 PhpWebFTP 3.2 Login Script</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25920" source="XF">phpwebftp-index-directory-traversal(25920)</ref>
      <ref url="http://securityreason.com/securityalert/723" source="SREASON">723</ref>
      <ref url="http://secunia.com/advisories/19706" source="SECUNIA">19706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebftp" name="phpwebftp">
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1814" published="2006-04-18" name="CVE-2006-1814" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17498" source="BID">17498</ref>
      <ref url="http://securitytracker.com/id?1015909" source="SECTRACK">1015909</ref>
      <ref url="http://secunia.com/advisories/19616" source="SECUNIA" adv="1">19616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25764" source="XF">bsd-sysctl-dos(25764)</ref>
      <ref url="http://www.osvdb.org/24579" source="OSVDB">24579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1815" published="2006-04-18" name="CVE-2006-1815" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1329" source="VUPEN">ADV-2006-1329</ref>
      <ref url="http://www.osvdb.org/24556" source="OSVDB">24556</ref>
      <ref url="http://secunia.com/advisories/19635" source="SECUNIA" adv="1">19635</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25751" source="XF">tritaniumbb-register-xss(25751)</ref>
      <ref url="http://securityreason.com/securityalert/693" source="SREASON">693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tritanium_scripts" name="tritanium_bulletin_board">
        <vers prev="1" num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1816" published="2006-04-18" name="CVE-2006-1816" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430881/100/0/threaded" source="BUGTRAQ">20060412 Remote File Inclusion in VBulletin ImpEx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34095" source="XF">impex-systempath-file-include(34095)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25789" source="XF">impex-multiple-file-inclusion(25789)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467666/100/0/threaded" source="BUGTRAQ">20070504 Remote File Include In Script impex</ref>
      <ref url="http://www.osvdb.org/24692" source="OSVDB">24692</ref>
      <ref url="http://www.osvdb.org/24691" source="OSVDB">24691</ref>
      <ref url="http://www.osvdb.org/24690" source="OSVDB">24690</ref>
      <ref url="http://secunia.com/advisories/19352" source="SECUNIA">19352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1817" published="2006-04-18" name="CVE-2006-1817" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1359" source="VUPEN">ADV-2006-1359</ref>
      <ref url="http://evuln.com/vulns/125/summary.html" source="MISC">http://evuln.com/vulns/125/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25900" source="XF">warforgenews-authcheck-sql-injection(25900)</ref>
      <ref url="http://www.securityfocus.com/bid/17705" source="BID">17705</ref>
      <ref url="http://www.securityfocus.com/bid/17520" source="BID">17520</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432104/100/0/threaded" source="BUGTRAQ">20060426 [eVuln] warforge.NEWS SQL Injection and Multiple XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_war_forge" name="warforge.news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1818" published="2006-04-18" name="CVE-2006-1818" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php.  NOTE: portions of these details were obtained from third party sources instead of the original disclosure.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1359" source="VUPEN">ADV-2006-1359</ref>
      <ref url="http://evuln.com/vulns/125/summary.html" source="MISC">http://evuln.com/vulns/125/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/17520" source="BID">17520</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432104/100/0/threaded" source="BUGTRAQ">20060426 [eVuln] warforge.NEWS SQL Injection and Multiple XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_war_forge" name="warforge.news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1819" published="2006-04-18" name="CVE-2006-1819" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including access_log.  NOTE: in some cases, arbitrary remote file inclusion could be performed under PHP 5 using an SMB share argument such as "\\systemname\sharename".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1361" source="VUPEN">ADV-2006-1361</ref>
      <ref url="http://www.securityfocus.com/bid/17521" source="BID">17521</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/PHPWebSite_fi_poc" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/PHPWebSite_fi_poc</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25867" source="XF">phpwebsite-index-hubdir-file-include(25867)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-04.xml" source="GENTOO">GLSA-200605-04</ref>
      <ref url="http://securitytracker.com/id?1015942" source="SECTRACK">1015942</ref>
      <ref url="http://secunia.com/advisories/19914" source="SECUNIA">19914</ref>
      <ref url="http://secunia.com/advisories/19647" source="SECUNIA">19647</ref>
      <ref url="http://milw0rm.com/exploits/1673" source="MILW0RM">1673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers prev="1" num="0.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1820" published="2006-04-18" name="CVE-2006-1820" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: this might be resultant from the directory traversal vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1383" source="VUPEN">ADV-2006-1383</ref>
      <ref url="http://www.securityfocus.com/bid/17533" source="BID">17533</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431010/100/0/threaded" source="BUGTRAQ">20060414 Vulnerabilities in MODx</ref>
      <ref url="http://securitytracker.com/id?1015940" source="SECTRACK">1015940</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25894" source="XF">modx-index-xss(25894)</ref>
      <ref url="http://secunia.com/advisories/19645" source="SECUNIA">19645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modxcms" name="modxcms">
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1821" published="2006-04-18" name="CVE-2006-1821" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">To address this issue, the vendor has released a patch available at the following location:

http://modxcms.com/forums/index.php/topic,3982.0.html</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1383" source="VUPEN">ADV-2006-1383</ref>
      <ref url="http://www.securityfocus.com/bid/17533" source="BID">17533</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431010/100/0/threaded" source="BUGTRAQ">20060414 Vulnerabilities in MODx</ref>
      <ref url="http://securitytracker.com/id?1015940" source="SECTRACK">1015940</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25895" source="XF">modx-index-directory-traversal(25895)</ref>
      <ref url="http://secunia.com/advisories/19645" source="SECUNIA">19645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modxcms" name="modxcms">
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1822" published="2006-04-18" name="CVE-2006-1822" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1411" source="VUPEN">ADV-2006-1411</ref>
      <ref url="http://www.securityfocus.com/bid/17534" source="BID">17534</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431011/100/0/threaded" source="BUGTRAQ">20060414 Farsinews Cross-Site Scripting &amp; Path disclosure vulnerability</ref>
      <ref url="http://www.aria-security.net/advisory/farsinews/farsinews042006.txt" source="MISC" adv="1">http://www.aria-security.net/advisory/farsinews/farsinews042006.txt</ref>
      <ref url="http://securitytracker.com/id?1015943" source="SECTRACK">1015943</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25833" source="XF">farsinews-search-xss(25833)</ref>
      <ref url="http://securityreason.com/securityalert/710" source="SREASON">710</ref>
      <ref url="http://secunia.com/advisories/19648" source="SECUNIA">19648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="farsinews" name="farsinews">
        <vers num="2.1" />
        <vers num="2.1_beta2" />
        <vers num="2.5" />
        <vers num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1823" published="2006-04-18" name="CVE-2006-1823" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1411" source="VUPEN">ADV-2006-1411</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431011/100/0/threaded" source="BUGTRAQ">20060414 Farsinews Cross-Site Scripting &amp; Path disclosure vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015943" source="SECTRACK">1015943</ref>
      <ref url="http://securityreason.com/securityalert/710" source="SREASON">710</ref>
      <ref url="http://secunia.com/advisories/19648" source="SECUNIA">19648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="farsinews" name="farsinews">
        <vers num="2.1" />
        <vers num="2.1_beta2" />
        <vers num="2.5" />
        <vers num="2.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1824" published="2006-04-18" name="CVE-2006-1824" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1422" source="VUPEN">ADV-2006-1422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25850" source="XF">phpguestbook-script-xss(25850)</ref>
      <ref url="http://www.securityfocus.com/bid/17594" source="BID">17594</ref>
      <ref url="http://www.securityfocus.com/bid/17537" source="BID">17537</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431070/100/0/threaded" source="BUGTRAQ">20060415 PhpGuestbook &lt;= 1.0 XSS</ref>
      <ref url="http://secunia.com/advisories/19669" source="SECUNIA">19669</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/phpguestbook-v10-script-insertion.html" source="MISC">http://pridels0.blogspot.com/2006/04/phpguestbook-v10-script-insertion.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpguestbook" name="phpguestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1825" published="2006-04-18" name="CVE-2006-1825" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1378" source="VUPEN">ADV-2006-1378</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25890" source="XF">phplinks-index-xss(25890)</ref>
      <ref url="http://www.securityfocus.com/bid/17586" source="BID">17586</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/phplinks-2131-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/phplinks-2131-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phplinks" name="phplinks">
        <vers prev="1" num="2.1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1826" published="2006-04-18" name="CVE-2006-1826" modified="2008-09-05" discovered="2006-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php.  NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25803" source="XF">snipe-view-image-xss(25803)</ref>
      <ref url="http://www.securityfocus.com/bid/17543" source="BID">17543</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431123/100/0/threaded" source="BUGTRAQ" adv="1">20060416 Re: Snipe Gallery &lt;= 3.1.4 Multiple XSS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431074/100/0/threaded" source="BUGTRAQ" adv="1">20060415 Snipe Gallery &lt;= 3.1.4 Multiple XSS</ref>
      <ref url="http://securitytracker.com/id?1015947" source="SECTRACK">1015947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snipegallery" name="snipe_gallery">
        <vers prev="1" num="3.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1827" published="2006-04-18" name="CVE-2006-1827" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cipher.org.uk/index.php?p=advisories/Asterisk_Codec_Integer_Overflow_07-04-2006.advisory" source="MISC" patch="1">http://www.cipher.org.uk/index.php?p=advisories/Asterisk_Codec_Integer_Overflow_07-04-2006.advisory</ref>
      <ref url="http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz" source="CONFIRM" patch="1">http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1478" source="VUPEN">ADV-2006-1478</ref>
      <ref url="http://www.securityfocus.com/bid/17561" source="BID">17561</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1048" source="DEBIAN">DSA-1048</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
      <ref url="http://secunia.com/advisories/19872" source="SECUNIA">19872</ref>
      <ref url="http://secunia.com/advisories/19800" source="SECUNIA">19800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="0.1.10" />
        <vers num="0.1.11" />
        <vers num="0.1.12" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.1.9.1" />
        <vers num="0.2" />
        <vers num="0.2.0" />
        <vers num="0.3" />
        <vers num="0.3.0" />
        <vers num="0.4" />
        <vers num="0.4.0" />
        <vers num="0.5.0" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
        <vers num="1.2.0_beta1" />
        <vers prev="1" num="1.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1828" published="2006-04-19" name="CVE-2006-1828" modified="2011-03-07" discovered="2006-04-12" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php.  NOTE: the code execution occurs because the SQL query results are used in an include statement.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1349" source="VUPEN">ADV-2006-1349</ref>
      <ref url="http://secunia.com/advisories/19643" source="SECUNIA" adv="1">19643</ref>
      <ref url="http://milw0rm.com/exploits/1666" source="MILW0RM">1666</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25785" source="XF">php121-php121login-sql-injection(25785)</ref>
      <ref url="http://www.securityfocus.com/bid/17509" source="BID">17509</ref>
      <ref url="http://securitytracker.com/id?1015936" source="SECTRACK">1015936</ref>
      <ref url="http://retrogod.altervista.org/php121im_14_sql_xpl.html" source="MISC">http://retrogod.altervista.org/php121im_14_sql_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php121" name="php121_instant_messenger">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1829" published="2006-04-19" name="CVE-2006-1829" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1344" source="VUPEN">ADV-2006-1344</ref>
      <ref url="http://www.sybase.com/detail?id=1040117" source="CONFIRM" adv="1">http://www.sybase.com/detail?id=1040117</ref>
      <ref url="http://www.securityfocus.com/bid/17508" source="BID">17508</ref>
      <ref url="http://securitytracker.com/id?1015913" source="SECTRACK">1015913</ref>
      <ref url="http://secunia.com/advisories/19605" source="SECUNIA" adv="1">19605</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25777" source="XF">easerver-password-disclosure(25777)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="easerver">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1830" published="2006-04-19" name="CVE-2006-1830" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17517" source="BID" patch="1">17517</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102292-1" source="SUNALERT" patch="1">102292</ref>
      <ref url="http://secunia.com/advisories/19632" source="SECUNIA" patch="1" adv="1">19632</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1357" source="VUPEN">ADV-2006-1357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25822" source="XF">sun-javastudio-insecure-permissions(25822)</ref>
      <ref url="http://securitytracker.com/id?1015930" source="SECTRACK">1015930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_studio_enterprise">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1831" published="2006-04-19" name="CVE-2006-1831" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17523" source="BID" patch="1">17523</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25906" source="XF">sysinfo-sysinfo-command-execution(25906)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1360" source="VUPEN">ADV-2006-1360</ref>
      <ref url="http://secunia.com/advisories/19690" source="SECUNIA" adv="1">19690</ref>
      <ref url="http://milw0rm.com/exploits/1677" source="MILW0RM">1677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coder-world" name="sysinfo">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1832" published="2006-04-19" name="CVE-2006-1832" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17523" source="BID" patch="1">17523</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1360" source="VUPEN">ADV-2006-1360</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25909" source="XF">sysinfo-debugger-information-disclosure(25909)</ref>
      <ref url="http://secunia.com/advisories/19690" source="SECUNIA">19690</ref>
      <ref url="http://milw0rm.com/exploits/1677" source="MILW0RM">1677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coder-world" name="sysinfo">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1833" published="2006-04-19" name="CVE-2006-1833" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24577" source="OSVDB">24577</ref>
      <ref url="http://securitytracker.com/id?1015907" source="SECTRACK">1015907</ref>
      <ref url="http://secunia.com/advisories/19585" source="SECUNIA" adv="1">19585</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-009.txt.asc" source="NETBSD">NetBSD-SA2006-009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25786" source="XF">netbsd-intel-rng-security-bypass(25786)</ref>
      <ref url="http://www.securityfocus.com/bid/17496" source="BID">17496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1834" published="2006-04-19" name="CVE-2006-1834" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check.  NOTE: a sign extension problem makes the attack easier with shorter strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17513" source="BID" patch="1">17513</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1354" source="VUPEN">ADV-2006-1354</ref>
      <ref url="http://www.sec-consult.com/259.html" source="MISC">http://www.sec-consult.com/259.html</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/854/" source="CONFIRM">http://www.opera.com/docs/changelogs/windows/854/</ref>
      <ref url="http://securitytracker.com/id?1015912" source="SECTRACK">1015912</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114493114031891&amp;w=2" source="FULLDISC">20060413 SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25829" source="XF">opera-wcsncpy-css-bo(25829)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430876/100/0/threaded" source="BUGTRAQ">20060413 SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200606-01.xml" source="GENTOO">GLSA-200606-01</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera">
        <vers num="8.50" />
        <vers num="8.52" />
        <vers prev="1" num="8.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1835" published="2006-04-19" name="CVE-2006-1835" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1376" source="VUPEN">ADV-2006-1376</ref>
      <ref url="http://www.securityfocus.com/bid/17562" source="BID">17562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431122/100/0/threaded" source="BUGTRAQ">20060416 Calendarix "yearcal.php" XSS Attacking</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25874" source="XF">calendarix-yearcal-xss(25874)</ref>
      <ref url="http://securitytracker.com/id?1015954" source="SECTRACK">1015954</ref>
      <ref url="http://securityreason.com/securityalert/727" source="SREASON">727</ref>
      <ref url="http://secunia.com/advisories/19710" source="SECUNIA">19710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vincent_hor" name="calendarix">
        <vers num="0.6.2005-08-30" />
      </prod>
      <prod vendor="vincent_hor" name="calendarix_advanced">
        <vers num="1.5.2005-05-01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1836" published="2006-04-19" name="CVE-2006-1836" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.04.17b.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.04.17b.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1386" source="VUPEN">ADV-2006-1386</ref>
      <ref url="http://www.securityfocus.com/bid/17571" source="BID">17571</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431318/100/0/threaded" source="BUGTRAQ">20060418 [Symantec Security Advisory] LiveUpdate for Macintosh Local Privilege Escalation</ref>
      <ref url="http://securitytracker.com/id?1015953" source="SECTRACK">1015953</ref>
      <ref url="http://secunia.com/advisories/19682" source="SECUNIA" adv="1">19682</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25839" source="XF">liveupdate-exepath-env-privilege-escalation(25839)</ref>
      <ref url="http://securityreason.com/securityalert/100" source="SREASON">100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="liveupdate">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":macintosh" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":macintosh" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":macintosh" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":macintosh" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":macintosh" />
        <vers num="10.0.0" edition="" />
        <vers num="10.0.0" edition=":macintosh" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":macintosh" />
        <vers num="10.9.1" edition="" />
        <vers num="10.9.1" edition=":macintosh" />
        <vers num="9.0.0" edition="" />
        <vers num="9.0.0" edition=":macintosh" />
        <vers num="9.0.1" edition="" />
        <vers num="9.0.1" edition=":macintosh" />
        <vers num="9.0.2" edition="" />
        <vers num="9.0.2" edition=":macintosh" />
        <vers num="9.0.3" edition="" />
        <vers num="9.0.3" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":macintosh" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_utilities">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":macintosh" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1837" published="2006-04-19" name="CVE-2006-1837" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1374" source="VUPEN">ADV-2006-1374</ref>
      <ref url="http://www.securityfocus.com/bid/17572" source="BID">17572</ref>
      <ref url="http://secunia.com/advisories/19677" source="SECUNIA" adv="1">19677</ref>
      <ref url="http://milw0rm.com/exploits/1682" source="MILW0RM">1682</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25897" source="XF">fujunews-archiv2-sql-injection(25897)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clanscripte.net" name="fuju_news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1838" published="2006-04-19" name="CVE-2006-1838" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1374" source="VUPEN">ADV-2006-1374</ref>
      <ref url="http://www.securityfocus.com/bid/17572" source="BID">17572</ref>
      <ref url="http://secunia.com/advisories/19677" source="SECUNIA" adv="1">19677</ref>
      <ref url="http://milw0rm.com/exploits/1682" source="MILW0RM">1682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clanscripte.net" name="fuju_news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1839" published="2006-04-19" name="CVE-2006-1839" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1382" source="VUPEN">ADV-2006-1382</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431067/100/0/threaded" source="BUGTRAQ">20060415 PHP Album &lt;= 0.3.2.3 remote commnads execution</ref>
      <ref url="http://secunia.com/advisories/19661" source="SECUNIA" adv="1">19661</ref>
      <ref url="http://retrogod.altervista.org/phpalbum_0323_incl_xpl.html" source="MISC">http://retrogod.altervista.org/phpalbum_0323_incl_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25846" source="XF">phpalbum-language-file-include(25846)</ref>
      <ref url="http://www.securityfocus.com/bid/17526" source="BID">17526</ref>
      <ref url="http://www.osvdb.org/24741" source="OSVDB">24741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_album" name="php_album">
        <vers num="0.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1840" published="2006-04-19" name="CVE-2006-1840" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=410001&amp;group_id=24031" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=410001&amp;group_id=24031</ref>
      <ref url="http://secunia.com/advisories/19674" source="SECUNIA" patch="1" adv="1">19674</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25863" source="XF">empireserver-unspecified(25863)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1380" source="VUPEN" adv="1">ADV-2006-1380</ref>
      <ref url="http://www.securityfocus.com/bid/17585" source="BID">17585</ref>
      <ref url="http://www.osvdb.org/24700" source="OSVDB">24700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="empire_server" name="empire_server">
        <vers num="4.2.10" />
        <vers num="4.2.11" />
        <vers num="4.2.12" />
        <vers num="4.2.13" />
        <vers num="4.2.14" />
        <vers num="4.2.15" />
        <vers num="4.2.16" />
        <vers num="4.2.17" />
        <vers num="4.2.18" />
        <vers num="4.2.19" />
        <vers num="4.2.20" />
        <vers num="4.2.21" />
        <vers num="4.2.22" />
        <vers num="4.2.23" />
        <vers prev="1" num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1841" published="2006-04-19" name="CVE-2006-1841" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1375" source="VUPEN">ADV-2006-1375</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431120/100/0/threaded" source="BUGTRAQ">20060416 Xss In bMachine 2&amp;#1643;7</ref>
      <ref url="http://secunia.com/advisories/19711" source="SECUNIA" adv="1">19711</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25914" source="XF">boastmachine-search-xss(25914)</ref>
      <ref url="http://www.securityfocus.com/bid/17550" source="BID">17550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kailash_nadh" name="boastmachine">
        <vers num="2.5" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1842" published="2006-04-19" name="CVE-2006-1842" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1385" source="VUPEN">ADV-2006-1385</ref>
      <ref url="http://www.securityfocus.com/bid/17548" source="BID">17548</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431130/100/0/threaded" source="BUGTRAQ">20060417 ShoutBOOK &lt;= 1.1 XSS</ref>
      <ref url="http://securitytracker.com/id?1015958" source="SECTRACK">1015958</ref>
      <ref url="http://secunia.com/advisories/19704" source="SECUNIA" adv="1">19704</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25862" source="XF">shoutbook-global-xss(25862)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cynical_games" name="shoutbook">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1843" published="2006-04-19" name="CVE-2006-1843" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1385" source="VUPEN">ADV-2006-1385</ref>
      <ref url="http://secunia.com/advisories/19704" source="SECUNIA" adv="1">19704</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25862" source="XF">shoutbook-global-xss(25862)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cynical_games" name="shoutbook">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1844" published="2006-04-19" name="CVE-2006-1844" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23922" source="OSVDB" patch="1">23922</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356939" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356939</ref>
      <ref url="http://secunia.com/advisories/19170" source="SECUNIA" adv="1">19170</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="base-config">
        <vers num="2.53.10" />
      </prod>
      <prod vendor="debian" name="shadow-utils">
        <vers num="4.0.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-1845" reject="1" published="2006-04-19" name="CVE-2006-1845" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0537.  Reason: This candidate is a duplicate of CVE-2006-0537.  Notes: All CVE users should reference CVE-2006-0537 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1846" published="2006-04-19" name="CVE-2006-1846" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML and web script via the ublock parameter, which is saved in the user's personal menu.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, it is unclear whether this issue is a vulnerability, since it is related to the user's personal menu, which presumably is not modifiable by others.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0687" source="VUPEN">ADV-2006-0687</ref>
      <ref url="http://www.securityfocus.com/bid/16774" source="BID">16774</ref>
      <ref url="http://www.osvdb.org/23431" source="OSVDB">23431</ref>
      <ref url="http://secunia.com/advisories/18972" source="SECUNIA" adv="1">18972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1847" published="2006-04-19" name="CVE-2006-1847" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to execute arbitrary SQL commands via the user_id parameter in the Your_Home functionality.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44730" source="XF">phpnuke-yourhome-sql-injection(44730)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0687" source="VUPEN">ADV-2006-0687</ref>
      <ref url="http://www.securityfocus.com/bid/16774" source="BID">16774</ref>
      <ref url="http://www.osvdb.org/23432" source="OSVDB">23432</ref>
      <ref url="http://secunia.com/advisories/18972" source="SECUNIA" adv="1">18972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1848" published="2006-04-19" name="CVE-2006-1848" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, and (3) date parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1396" source="VUPEN">ADV-2006-1396</ref>
      <ref url="http://www.securityfocus.com/bid/17581" source="BID">17581</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431242/100/0/threaded" source="BUGTRAQ">20060417 Linpha 1.1.0 - XSS Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/19679" source="SECUNIA" adv="1">19679</ref>
      <ref url="http://d4igoro.blogspot.com/2006/04/linpha-xss-vulnerabilities.html" source="MISC">http://d4igoro.blogspot.com/2006/04/linpha-xss-vulnerabilities.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25916" source="XF">linpha-statsview-xss(25916)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linpha" name="linpha">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1849" published="2006-04-19" name="CVE-2006-1849" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1412" source="VUPEN">ADV-2006-1412</ref>
      <ref url="http://secunia.com/advisories/19707" source="SECUNIA" adv="1">19707</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25853" source="XF">xflow-index-sql-injection(25853)</ref>
      <ref url="http://www.securityfocus.com/bid/17614" source="BID">17614</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skymarx_solutions" name="xflow">
        <vers prev="1" num="5.46.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1850" published="2006-04-19" name="CVE-2006-1850" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level, (2) position, (3) id, and (4) action parameters to members_only/index.cgi, and the (5) page parameter to customer_area/index.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1412" source="VUPEN">ADV-2006-1412</ref>
      <ref url="http://secunia.com/advisories/19707" source="SECUNIA" adv="1">19707</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25854" source="XF">xflow-index-xss(25854)</ref>
      <ref url="http://www.securityfocus.com/bid/17614" source="BID">17614</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skymarx_solutions" name="xflow">
        <vers prev="1" num="5.46.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1851" published="2006-04-19" name="CVE-2006-1851" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">xFlow 5.46.11 and earlier allows remote attackers to determine the installation path of the application via the (1) action parameter to members_only/index.cgi and (2) page parameter customer_area/index.cgi, probably due to invalid values.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25855" source="XF">xflow-index-path-disclosure(25855)</ref>
      <ref url="http://www.securityfocus.com/bid/17614" source="BID">17614</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skymarx_solutions" name="xflow">
        <vers prev="1" num="5.46.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1852" published="2006-04-19" name="CVE-2006-1852" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25898" source="XF">articlepublisher-category-sql-injection(25898)</ref>
      <ref url="http://www.osvdb.org/24730" source="OSVDB">24730</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/article-publisher-pro-sql-inj.html" source="MISC">http://pridels0.blogspot.com/2006/04/article-publisher-pro-sql-inj.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsfrenzy" name="article_publisher_pro">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1853" published="2006-04-19" name="CVE-2006-1853" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1415" source="VUPEN">ADV-2006-1415</ref>
      <ref url="http://www.securityfocus.com/bid/17596" source="BID">17596</ref>
      <ref url="http://secunia.com/advisories/19641" source="SECUNIA">19641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25926" source="XF">modernbill-user-sql-injection(25926)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moderngigabyte" name="modernbill">
        <vers prev="1" num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1854" published="2006-04-19" name="CVE-2006-1854" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field.  NOTE: the vendor has disputed this vulnerability, saying that "it does not exist currently in the Bluepay 2.0 product," and older versions might not have been affected either.  As of 20060512, CVE has not formally investigated this dispute.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://pridels0.blogspot.com/2006/04/bluepay-manager-v20-script-insertion.html" source="MISC">http://pridels0.blogspot.com/2006/04/bluepay-manager-v20-script-insertion.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluepay" name="bluepay_manager">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1855" published="2006-05-18" name="CVE-2006-1855" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=127302" source="MISC">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=127302</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11235" source="OVAL">oval:org.mitre.oval:def:11235</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/bid/18099" source="BID">18099</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1184" source="DEBIAN">DSA-1184</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/22093" source="SECUNIA">22093</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA">21179</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1856" published="2006-05-19" name="CVE-2006-1856" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191524" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191524</ref>
      <ref url="http://www.ussg.iu.edu/hypermail/linux/kernel/0604.3/0777.html" source="MLIST">[linux-kernel] 20060426 [PATCH] LSM: add missing hook to do_compat_readv_writev()</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9927" source="OVAL">oval:org.mitre.oval:def:9927</ref>
      <ref url="http://lists.jammed.com/linux-security-module/2005/09/0019.html" source="MLIST">[linux-security-module] 20050928 readv/writev syscalls are not checked by lsm</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/bid/18105" source="BID">18105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.osvdb.org/25747" source="OSVDB">25747</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1184" source="DEBIAN">DSA-1184</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/22093" source="SECUNIA">22093</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA">21045</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.16" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1857" published="2006-05-22" name="CVE-2006-1857" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/26584" source="XF">linux-sctp-hback-dos(26584)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1893" source="VUPEN">ADV-2006-1893</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/bid/18085" source="BID">18085</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.osvdb.org/25695" source="OSVDB">25695</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html" source="SUSE">SUSE-SA:2006:047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21498" source="SECUNIA">21498</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA">21179</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA">21045</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20185" source="SECUNIA">20185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10622" source="OVAL">oval:org.mitre.oval:def:10622</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1858" published="2006-05-22" name="CVE-2006-1858" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/26585" source="XF">linux-sctp-parameter-dos(26585)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1893" source="VUPEN">ADV-2006-1893</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.securityfocus.com/bid/18085" source="BID">18085</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0617.html" source="REDHAT">RHSA-2006:0617</ref>
      <ref url="http://www.osvdb.org/25696" source="OSVDB">25696</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html" source="SUSE">SUSE-SA:2006:047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm</ref>
      <ref url="http://secunia.com/advisories/22174" source="SECUNIA">22174</ref>
      <ref url="http://secunia.com/advisories/21605" source="SECUNIA">21605</ref>
      <ref url="http://secunia.com/advisories/21498" source="SECUNIA">21498</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA">21179</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA">21045</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20185" source="SECUNIA">20185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9510" source="OVAL">oval:org.mitre.oval:def:9510</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1859" published="2006-05-11" name="CVE-2006-1859" modified="2011-03-07" discovered="2006-05-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Memory leak in __setlease in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (memory consumption) via unspecified actions related to an "uninitialised return value," aka "slab leak."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/20083" source="SECUNIA" patch="1" adv="1">20083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1767" source="VUPEN">ADV-2006-1767</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1f0e637c94a9b041833947c79110d6c02fff8618" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1f0e637c94a9b041833947c79110d6c02fff8618</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=blobdiff;h=aa7f66091823dde953e15895dc427615701c39c7;hp=e75ac392a313f3fad823bf2e46a03f29701e3e34;hb=1f0e637c94a9b041833947c79110d6c02fff8618;f=fs/locks.c" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=blobdiff;h=aa7f66091823dde953e15895dc427615701c39c7;hp=e75ac392a313f3fad823bf2e46a03f29701e3e34;hb=1f0e637c94a9b041833947c79110d6c02fff8618;f=fs/locks.c</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26438" source="XF">linux-locks-setlease-dos(26438)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0028" source="TRUSTIX">2006-0028</ref>
      <ref url="http://www.securityfocus.com/bid/18033" source="BID">18033</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA">21179</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA">21045</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1860" published="2006-05-11" name="CVE-2006-1860" modified="2011-03-07" discovered="2006-05-11" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17943" source="BID" patch="1">17943</ref>
      <ref url="http://secunia.com/advisories/20083" source="SECUNIA" patch="1">20083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1767" source="VUPEN">ADV-2006-1767</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.16" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.16</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1f0e637c94a9b041833947c79110d6c02fff8618" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1f0e637c94a9b041833947c79110d6c02fff8618</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=blobdiff;h=aa7f66091823dde953e15895dc427615701c39c7;hp=e75ac392a313f3fad823bf2e46a03f29701e3e34;hb=1f0e637c94a9b041833947c79110d6c02fff8618;f=fs/locks.c" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=blobdiff;h=aa7f66091823dde953e15895dc427615701c39c7;hp=e75ac392a313f3fad823bf2e46a03f29701e3e34;hb=1f0e637c94a9b041833947c79110d6c02fff8618;f=fs/locks.c</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26437" source="XF">linux-locks-lease-init-dos(26437)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0028" source="TRUSTIX">2006-0028</ref>
      <ref url="http://www.osvdb.org/25425" source="OSVDB">25425</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html" source="SUSE">SUSE-SA:2006:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123" source="MANDRIVA">MDKSA-2006:123</ref>
      <ref url="http://secunia.com/advisories/21179" source="SECUNIA">21179</ref>
      <ref url="http://secunia.com/advisories/21045" source="SECUNIA">21045</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1861" published="2006-05-23" name="CVE-2006-1861" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c.  NOTE: item 4 was originally identified by CVE-2006-2493.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/26553" source="XF" patch="1">freetype-lwfn-overflow(26553)</ref>
      <ref url="http://www.securityfocus.com/bid/18034" source="BID" patch="1">18034</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=416463" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=416463</ref>
      <ref url="http://secunia.com/advisories/20100" source="SECUNIA" patch="1" adv="1">20100</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01401.html" source="FEDORA">FEDORA-2009-5644</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01316.html" source="FEDORA">FEDORA-2009-5558</ref>
      <ref url="https://issues.rpath.com/browse/RPL-429" source="CONFIRM">https://issues.rpath.com/browse/RPL-429</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=502565" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=502565</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593#c8" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593#c8</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=128606" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=128606</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0381" source="VUPEN" adv="1">ADV-2007-0381</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1868" source="VUPEN" adv="1">ADV-2006-1868</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-291-1" source="UBUNTU">USN-291-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436836/100/0/threaded" source="BUGTRAQ">20060612 rPSA-2006-0100-1 freetype</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1062.html" source="REDHAT" adv="1">RHSA-2009:1062</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0329.html" source="REDHAT" adv="1">RHSA-2009:0329</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0500.html" source="REDHAT">RHSA-2006:0500</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:099" source="MANDRIVA">MDKSA-2006:099</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200710-09.xml" source="GENTOO">GLSA-200710-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1095" source="DEBIAN">DSA-1095</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102705-1" source="SUNALERT">102705</ref>
      <ref url="http://securitytracker.com/id?1016522" source="SECTRACK">1016522</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200607-02.xml" source="GENTOO">GLSA-200607-02</ref>
      <ref url="http://secunia.com/advisories/35233" source="SECUNIA" adv="1">35233</ref>
      <ref url="http://secunia.com/advisories/35204" source="SECUNIA" adv="1">35204</ref>
      <ref url="http://secunia.com/advisories/35200" source="SECUNIA" adv="1">35200</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA" adv="1">33937</ref>
      <ref url="http://secunia.com/advisories/27271" source="SECUNIA" adv="1">27271</ref>
      <ref url="http://secunia.com/advisories/27167" source="SECUNIA" adv="1">27167</ref>
      <ref url="http://secunia.com/advisories/27162" source="SECUNIA" adv="1">27162</ref>
      <ref url="http://secunia.com/advisories/23939" source="SECUNIA" adv="1">23939</ref>
      <ref url="http://secunia.com/advisories/21701" source="SECUNIA" adv="1">21701</ref>
      <ref url="http://secunia.com/advisories/21385" source="SECUNIA" adv="1">21385</ref>
      <ref url="http://secunia.com/advisories/21135" source="SECUNIA" adv="1">21135</ref>
      <ref url="http://secunia.com/advisories/21062" source="SECUNIA" adv="1">21062</ref>
      <ref url="http://secunia.com/advisories/21000" source="SECUNIA" adv="1">21000</ref>
      <ref url="http://secunia.com/advisories/20791" source="SECUNIA" adv="1">20791</ref>
      <ref url="http://secunia.com/advisories/20638" source="SECUNIA" adv="1">20638</ref>
      <ref url="http://secunia.com/advisories/20591" source="SECUNIA" adv="1">20591</ref>
      <ref url="http://secunia.com/advisories/20525" source="SECUNIA" adv="1">20525</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9124" source="OVAL">oval:org.mitre.oval:def:9124</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html" source="SUSE">SUSE-SA:2006:037</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html" source="SUSE">SUSE-SR:2007:021</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U" source="SGI">20060701-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freetype" name="freetype">
        <vers num="2.0.9" />
        <vers num="2.1.10" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.8_rc1" />
        <vers num="2.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1862" published="2006-05-24" name="CVE-2006-1862" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0493</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189260" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189260</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189031" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9390" source="OVAL">oval:org.mitre.oval:def:9390</ref>
      <ref url="http://osvdb.org/31663" source="OSVDB">31663</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1863" published="2006-04-25" name="CVE-2006-1863" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189434" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189434</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=296034f7de8bdf111984ce1630ac598a9c94a253" source="CONFIRM" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=296034f7de8bdf111984ce1630ac598a9c94a253</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1542" source="VUPEN">ADV-2006-1542</ref>
      <ref url="http://rhn.redhat.com/errata/RHBA-2007-0304.html" source="REDHAT">RHBA-2007-0304</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10383" source="OVAL">oval:org.mitre.oval:def:10383</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26141" source="XF">kernel-cifs-directory-traversal(26141)</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/bid/17742" source="BID">17742</ref>
      <ref url="http://www.osvdb.org/25068" source="OSVDB">25068</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:151" source="MANDRIVA">MDKSA-2006:151</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.11" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://secunia.com/advisories/21614" source="SECUNIA">21614</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19868" source="SECUNIA">19868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1864" published="2006-04-26" name="CVE-2006-1864" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189435" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189435</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN">ADV-2006-4502</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11327" source="OVAL">oval:org.mitre.oval:def:11327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26137" source="XF">kernel-smbfs-directory-traversal(26137)</ref>
      <ref url="http://www.vmware.com/download/esx/esx-254-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-254-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-213-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-213-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-202-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-202-200610-patch.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0026" source="TRUSTIX">2006-0026</ref>
      <ref url="http://www.securityfocus.com/bid/17735" source="BID">17735</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0710.html" source="REDHAT">RHSA-2006:0710</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0580.html" source="REDHAT">RHSA-2006:0580</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0579.html" source="REDHAT">RHSA-2006:0579</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0493.html" source="REDHAT">RHSA-2006:0493</ref>
      <ref url="http://www.osvdb.org/25067" source="OSVDB">25067</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:151" source="MANDRIVA">MDKSA-2006:151</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150" source="MANDRIVA">MDKSA-2006:150</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-254.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-254.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm</ref>
      <ref url="http://secunia.com/advisories/23064" source="SECUNIA">23064</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA">22875</ref>
      <ref url="http://secunia.com/advisories/22497" source="SECUNIA">22497</ref>
      <ref url="http://secunia.com/advisories/21745" source="SECUNIA">21745</ref>
      <ref url="http://secunia.com/advisories/21614" source="SECUNIA">21614</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/21035" source="SECUNIA">21035</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/20237" source="SECUNIA">20237</ref>
      <ref url="http://secunia.com/advisories/19869" source="SECUNIA">19869</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16_rc7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1865" published="2006-04-21" name="CVE-2006-1865" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26104" source="XF">beagle-indexing-command-execution(26104)</ref>
      <ref url="http://www.securityfocus.com/bid/17611" source="BID">17611</ref>
      <ref url="http://www.osvdb.org/24938" source="OSVDB">24938</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA" adv="1">19897</ref>
      <ref url="http://secunia.com/advisories/19781" source="SECUNIA" adv="1">19781</ref>
      <ref url="http://secunia.com/advisories/19778" source="SECUNIA" adv="1">19778</ref>
      <ref url="http://scary.beasts.org/security/CESA-2006-002.html" source="MISC">http://scary.beasts.org/security/CESA-2006-002.html</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2006-April/013163.html" source="FEDORA">FEDORA-2006-440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beagle-project" name="beagle">
        <vers num="0.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1866" published="2006-04-20" name="CVE-2006-1866" modified="2011-09-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:C/A:C)" CVSS_score="9.7" CVSS_impact_subscore="9.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.7">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10.  NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html" source="CERT">TA06-109A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/139049" source="CERT-VN">VU#139049</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26054" source="XF">oracle-sdocatalog-sql-injection(26054)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26050" source="XF">oracle-dbmsreputil-sql-injection(26050)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1867" published="2006-04-20" name="CVE-2006-1867" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.6 has unknown impact and attack vectors in the Advanced Replication component, aka Vuln# DB02.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26068" source="XF">oracle-database-multiple-unspecified(26068)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1868" published="2006-04-20" name="CVE-2006-1868" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/797465" source="CERT-VN" patch="1">VU#797465</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html" source="CERT">TA06-109A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26049" source="XF">oracle-dbmssnapshotutl-bo(26049)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431588/100/0/threaded" source="BUGTRAQ">20060420 [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html</ref>
      <ref url="http://www.argeniss.com/research/ARGENISS-ADV-040603.txt" source="MISC" adv="1">http://www.argeniss.com/research/ARGENISS-ADV-040603.txt</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1869" published="2006-04-20" name="CVE-2006-1869" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4 and 9.0.1.5 has unknown impact and attack vectors in the Dictionary component, aka Vuln# DB04.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html" source="CERT">TA06-109A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/241481" source="CERT-VN">VU#241481</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26052" source="XF">oracle-dictionary-constraint-modification(26052)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1870" published="2006-04-20" name="CVE-2006-1870" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors in the Export component, aka Vuln# DB05.  NOTE: details are unavailable from Oracle, but as of 20060427, they have not publicly commented on whether DB05 is the same issue as CVE-2006-2081.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/452681" source="CERT-VN" adv="1">VU#452681</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP" adv="1">HPSBMA02113</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.2" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1871" published="2006-04-20" name="CVE-2006-1871" modified="2011-03-07" discovered="2005-11-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26047" source="XF">oracle-dbmslogmnrsession-sql-injection(26047)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431345/30/5490/threaded" source="BUGTRAQ">20060418 SQL Injection in package SYS.DBMS_LOGMNR_SESSION</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_logmnr_session.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_logmnr_session.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045280.html" source="FULLDISC">20060418 SQL Injection in package SYS.DBMS_LOGMNR_SESSION</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1872" published="2006-04-20" name="CVE-2006-1872" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patches :
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26068" source="XF">oracle-database-multiple-unspecified(26068)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1873" published="2006-04-20" name="CVE-2006-1873" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7, 10.1.0.4, and 10.2.0.1 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB08.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patches :
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/26068" source="XF">oracle-database-multiple-unspecified(26068)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK">1015961</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="10.2.0.1" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1874" published="2006-04-20" name="CVE-2006-1874" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB09.  NOTE: Oracle has not disputed reliable claims that this issue is SQL injection in MDSYS.PRVT_IDX using the (1) EXECUTE_INSERT, (2) EXECUTE_DELETE, (3) EXECUTE_UPDATE, (4) EXECUTE UPDATE, and (5) CRT_DUMMY functions.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patches.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/26053" source="XF">oracle-prvtidx-sql-injection(26053)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK">1015961</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1875" published="2006-04-20" name="CVE-2006-1875" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11.  NOTE: Oracle has not disputed reliable researcher claims that this issue is SQL injection in MDSYS.SDO_LRS_TRIG_INS.</descript>
      <descript source="nvd">The most severe of these vulnerabilities could possibly expose affected computers to complete compromise.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26055" source="XF">oracle-sdolrstrigins-sql-injection(26055)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1876" published="2006-04-20" name="CVE-2006-1876" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12.  NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the (1) GEN_RID_RANGE_BY_AREA and (2) GEN_RID_RANGE functions in the MDSYS.SDO_PRIDX package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/240249" source="CERT-VN">VU#240249</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26051" source="XF">oracle-sdopridx-sql-injection(26051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1877" published="2006-04-20" name="CVE-2006-1877" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.7 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB13.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26068" source="XF">oracle-database-multiple-unspecified(26068)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID">17590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://www.osvdb.org/24861" source="OSVDB">24861</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1878" published="2006-04-20" name="CVE-2006-1878" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1394" source="VUPEN">ADV-2006-1394</ref>
      <ref url="http://www.securityfocus.com/bid/17542" source="BID">17542</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431073/100/0/threaded" source="BUGTRAQ">20060415 phpFaber TopSites Script Cross-Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25804" source="XF">phpfabertopsites-index-xss(25804)</ref>
      <ref url="http://securitytracker.com/id?1015945" source="SECTRACK">1015945</ref>
      <ref url="http://securityreason.com/securityalert/760" source="SREASON">760</ref>
      <ref url="http://securityreason.com/securityalert/719" source="SREASON">719</ref>
      <ref url="http://secunia.com/advisories/19652" source="SECUNIA">19652</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpfaber" name="topsites">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1879" published="2006-04-20" name="CVE-2006-1879" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Email Server component in Oracle Collaboration Suite 9.0.4.2, 10.1.1, 10.1.2.0, and 10.1.2.1 have unknown impact and attack vectors, aka Vuln# (1) OCS01, (2) OCS02, (3) OCS03, and (4) OCS04.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html" source="CERT">TA06-109A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/879041" source="CERT-VN">VU#879041</ref>
      <ref url="http://www.kb.cert.org/vuls/id/549146" source="CERT-VN">VU#549146</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26057" source="XF">oracle-collab-unauth-access(26057)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.1" />
        <vers num="10.1.2.0" />
        <vers num="10.1.2.1" />
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1880" published="2006-04-20" name="CVE-2006-1880" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, as identified by Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS09 in the (b) Oracle Diagnostics Interfaces component; (3) APPS10 in the (c) Oracle General Ledger component; (4) APPS12 and (5) APPS13 in the (d) Oracle Receivables component.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/940729" source="CERT-VN">VU#940729</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26058" source="XF">oracle-ebusiness-multiple-unspecifed(26058)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1881" published="2006-04-20" name="CVE-2006-1881" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Financials for Asia/Pacific component in Oracle E-Business Suite and Applications 11.5.9 has unknown impact and attack vectors.  component, aka Vuln# APPS02.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26058" source="XF">oracle-ebusiness-multiple-unspecifed(26058)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1882" published="2006-04-20" name="CVE-2006-1882" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unknown impact and attack vectors, as identified by Vuln# (1) APPS03 in (a) iProcurement; (2) APPS04 in (b) Oracle Application Object Library; (3) APPS06, (4) APPS07, and (5) APPS08 in (c) Oracle Applications Technology Stack; and (6) APPS11 in (d) Oracle Order Capture.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/824833" source="CERT-VN">VU#824833</ref>
      <ref url="http://www.kb.cert.org/vuls/id/619194" source="CERT-VN">VU#619194</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26058" source="XF">oracle-ebusiness-multiple-unspecifed(26058)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1883" published="2006-04-20" name="CVE-2006-1883" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite and Applications 11.5.10CU1 has unknown impact and attack vectors, aka Vuln# APPS05.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26058" source="XF">oracle-ebusiness-multiple-unspecifed(26058)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1884" published="2006-04-20" name="CVE-2006-1884" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this issue through the release of product updates: 
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html 

</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26058" source="XF">oracle-ebusiness-multiple-unspecifed(26058)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jdedwards" name="enterpriseone_tools">
        <vers num="8.95" />
        <vers num="8.95.j1" />
      </prod>
      <prod vendor="oneworld" name="oneworld_tools">
        <vers num="8.95" />
        <vers num="8.95.j1" />
      </prod>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2" />
        <vers num="10.1.2.0.0" />
        <vers num="10.1.2.0.1" />
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.1.0" />
        <vers num="10.1.3.0.0" />
        <vers num="9.0.4.1" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite_10g_release_1">
        <vers num="10.1.1" />
        <vers num="10.1.2.0" />
        <vers num="10.1.2.1" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.1" />
        <vers num="10.2.0.2" />
        <vers num="10.2.0.4" />
        <vers num="10.2.0.4.2" />
        <vers num="10.2.0.5" />
        <vers num="8.0.6.3" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.6" />
        <vers num="9.2.0.7" />
      </prod>
      <prod vendor="oracle" name="developer_suite">
        <vers num="6i" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.0" />
        <vers num="11.5.1" />
        <vers num="11.5.10" />
        <vers num="11.5.10.1" />
        <vers num="11.5.10.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.3" />
        <vers num="10.1.0.4" />
        <vers num="10.2.0.1" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_tools">
        <vers num="8.46" edition="ga" />
        <vers num="8.46.12" />
        <vers num="8.47" edition="ga" />
        <vers num="8.47.04" />
      </prod>
      <prod vendor="oracle" name="pharmaceutical">
        <vers num="4.5.0" />
        <vers num="4.5.1" />
        <vers num="4.5.2" />
      </prod>
      <prod vendor="oracle" name="workflow">
        <vers num="11.5.1" />
        <vers num="11.5.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1885" published="2006-04-20" name="CVE-2006-1885" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manager 9.0.1.5 and 9.2.0.7 have unknown impact and attack vectors, aka Vuln# (1) EM01 and (2) EM02.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/443265" source="CERT-VN">VU#443265</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26056" source="XF">oracle-reporting-framework-access(26056)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1886" published="2006-04-20" name="CVE-2006-1886" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka Vuln# PSE01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html" source="CERT">TA06-109A</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26059" source="XF">oracle-peopletools-unspecified(26059)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">SSRT061148</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.46.12" />
        <vers num="8.47.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1887" published="2006-04-20" name="CVE-2006-1887" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Security Server 8.95.J1 has unknown impact and attack vectors, aka Vuln# JDE01.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html" source="CERT">TA06-109A</ref>
      <ref url="http://www.securityfocus.com/bid/17590" source="BID" patch="1">17590</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" patch="1" adv="1">19712</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN">ADV-2006-1397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26069" source="XF">oracle-jdedwards-enterpriseone-unspecified(26069)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA">19859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.95.j1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1888" published="2006-04-20" name="CVE-2006-1888" modified="2011-08-10" discovered="2006-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script.  NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17567" source="BID" patch="1">17567</ref>
      <ref url="http://secunia.com/advisories/19705" source="SECUNIA" patch="1" adv="1">19705</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25892" source="XF">phpgraphy-index-xss(25892)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1379" source="VUPEN" adv="1">ADV-2006-1379</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431268/100/0/threaded" source="BUGTRAQ">20060418 Re: - PHPGraphy &lt;= 0.9.11 </ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431128/100/0/threaded" source="BUGTRAQ" adv="1">20060417 - PHPGraphy &lt;= 0.9.11 </ref>
      <ref url="http://securitytracker.com/id?1015971" source="SECTRACK">1015971</ref>
      <ref url="http://securityreason.com/securityalert/733" source="SREASON">733</ref>
      <ref url="http://retrogod.altervista.org/phpgraphy_0911_adv.html" source="MISC">http://retrogod.altervista.org/phpgraphy_0911_adv.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgraphy" name="phpgraphy">
        <vers num="0.9.10" />
        <vers prev="1" num="0.9.11" />
        <vers num="0.9.9a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1889" published="2006-04-20" name="CVE-2006-1889" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Search for" item (keyword parameter).</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1413" source="VUPEN">ADV-2006-1413</ref>
      <ref url="http://www.securityfocus.com/bid/17549" source="BID">17549</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431072/100/0/threaded" source="BUGTRAQ">20060415 Boardsolution &lt;= 1.12 XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25805" source="XF">boardsolution-index-xss(25805)</ref>
      <ref url="http://securitytracker.com/id?1015948" source="SECTRACK">1015948</ref>
      <ref url="http://securityreason.com/securityalert/766" source="SREASON">766</ref>
      <ref url="http://securityreason.com/securityalert/718" source="SREASON">718</ref>
      <ref url="http://secunia.com/advisories/19654" source="SECUNIA">19654</ref>
    </refs>
    <vuln_soft>
      <prod vendor="script-solution.de" name="boardsolution">
        <vers prev="1" num="1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1890" published="2006-04-20" name="CVE-2006-1890" modified="2011-09-08" discovered="2006-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php.  NOTE: vector 2 was later reported to affect 1.4 as well.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/28347" source="XF">myevent-myevent-file-include(28347)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25882" source="XF">myevent-event-initialize-file-include(25882)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1384" source="VUPEN" adv="1">ADV-2006-1384</ref>
      <ref url="http://www.securityfocus.com/bid/17575" source="BID">17575</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431125/100/0/threaded" source="BUGTRAQ" adv="1">20060416 MyEvent Remote File Execution And XSS Attacking</ref>
      <ref url="http://www.osvdb.org/24723" source="OSVDB">24723</ref>
      <ref url="http://www.osvdb.org/24722" source="OSVDB">24722</ref>
      <ref url="http://securitytracker.com/id?1016616" source="SECTRACK">1016616</ref>
      <ref url="http://securityreason.com/securityalert/767" source="SREASON">767</ref>
      <ref url="http://securityreason.com/securityalert/726" source="SREASON">726</ref>
      <ref url="http://secunia.com/advisories/19680" source="SECUNIA">19680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="myevent">
        <vers num="1.2" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1891" published="2006-04-20" name="CVE-2006-1891" modified="2011-03-07" discovered="2006-04-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard 0.1 allows remote attackers to inject arbitrary web script or HTML via a user's profile, possibly using the FormVal_profile parameter.  NOTE: it is not clear whether this is a distributable product or a site-specific vulnerability.  If it is site-specific, then it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25838" source="XF">betaboard-editprofile-xss(25838)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1377" source="VUPEN">ADV-2006-1377</ref>
      <ref url="http://www.securityfocus.com/bid/17556" source="BID">17556</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431116/100/0/threaded" source="BUGTRAQ" adv="1">20060416 BetaBoard Cross Site Scripting vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015955" source="SECTRACK">1015955</ref>
      <ref url="http://secunia.com/advisories/19700" source="SECUNIA" adv="1">19700</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045194.html" source="FULLDISC">20060416 BetaBoard Cross Site Scripting vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/765" source="SREASON">765</ref>
      <ref url="http://securityreason.com/securityalert/724" source="SREASON">724</ref>
    </refs>
    <vuln_soft>
      <prod vendor="betaboard" name="betaboard">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1892" published="2006-04-20" name="CVE-2006-1892" modified="2011-03-07" discovered="2006-04-14" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">avast! 4 Linux Home Edition 1.0.5 allows local users to modify permissions of arbitrary files via a symlink attack on the /tmp/_avast4_ temporary directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1387" source="VUPEN">ADV-2006-1387</ref>
      <ref url="http://www.securityfocus.com/bid/17535" source="BID">17535</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431019/100/0/threaded" source="BUGTRAQ" adv="1">20060414 Avast Linux Home Edition (vulnerability on a temporary folder creation)</ref>
      <ref url="http://securityreason.com/securityalert/764" source="SREASON">764</ref>
      <ref url="http://securityreason.com/securityalert/712" source="SREASON">712</ref>
      <ref url="http://secunia.com/advisories/19683" source="SECUNIA">19683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers num="1.0.5" edition="" />
        <vers num="1.0.5" edition=":home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1893" published="2006-04-20" name="CVE-2006-1893" modified="2008-09-05" discovered="2006-04-13" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17522" source="BID">17522</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431030/100/0/threaded" source="BUGTRAQ" adv="1">20060413 Xss In ar-blog v 5.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25834" source="XF">arblog-print-xss(25834)</ref>
      <ref url="http://securityreason.com/securityalert/763" source="SREASON">763</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ar-blog" name="ar-blog">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1894" published="2006-04-20" name="CVE-2006-1894" modified="2008-09-05" discovered="2006-04-13" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfuscator reverses the transformation.  NOTE: it is not clear whether this is a site-specific issue; however, the claimed codebase relationship with PunBB might be relevant.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430886/100/0/threaded" source="BUGTRAQ" adv="1">20060413 RevoBoard [email] tag XSS</ref>
      <ref url="http://securityreason.com/securityalert/768" source="SREASON">768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="revoboard" name="revoboard">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1895" published="2006-04-20" name="CVE-2006-1895" modified="2008-09-05" discovered="2006-04-14" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17573" source="BID">17573</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431017/100/0/threaded" source="BUGTRAQ" adv="1">20060414 phpBB template file code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25888" source="XF">phpbb-template-code-execution(25888)</ref>
      <ref url="http://securityreason.com/securityalert/769" source="SREASON">769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1896" published="2006-04-20" name="CVE-2006-1896" modified="2008-09-05" discovered="2006-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality.  NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1066" source="DEBIAN" patch="1">DSA-1066</ref>
      <ref url="http://secunia.com/advisories/20197" source="SECUNIA" patch="1" adv="1">20197</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25889" source="XF">phpbb-admin-code-execution(25889)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431387/100/0/threaded" source="BUGTRAQ" adv="1">20060418 Re: phpBB Admin command execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431015/100/0/threaded" source="BUGTRAQ" adv="1">20060414 phpBB Admin command execution</ref>
      <ref url="http://securityreason.com/securityalert/762" source="SREASON">762</ref>
      <ref url="http://securityreason.com/securityalert/715" source="SREASON">715</ref>
      <ref url="http://secunia.com/advisories/20093" source="SECUNIA" adv="1">20093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1897" published="2006-04-20" name="CVE-2006-1897" modified="2008-09-05" discovered="2006-04-13" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24621" source="OSVDB" patch="1">24621</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430880/100/0/threaded" source="BUGTRAQ" adv="1">20060413 TalentSoft Web+Shop Path Disclosure</ref>
      <ref url="http://secunia.com/advisories/19662" source="SECUNIA" adv="1">19662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25802" source="XF">webplusshop-webplus-path-disclosure(25802)</ref>
      <ref url="http://securityreason.com/securityalert/761" source="SREASON">761</ref>
      <ref url="http://securityreason.com/securityalert/703" source="SREASON">703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="talentsoft" name="web+_shop">
        <vers num="5.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1898" published="2006-04-20" name="CVE-2006-1898" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name.  NOTE: the "Access to hash password" issue is already covered by CVE-2006-0103.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded" source="BUGTRAQ">20060417 Tiny PHP forum - vulns</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25856" source="XF">tinyphpforum-profile-error-xss(25856)</ref>
      <ref url="http://www.securityfocus.com/bid/17553" source="BID">17553</ref>
      <ref url="http://securityreason.com/securityalert/773" source="SREASON">773</ref>
      <ref url="http://securityreason.com/securityalert/728" source="SREASON">728</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1899" published="2006-04-20" name="CVE-2006-1899" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) website parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1406" source="VUPEN">ADV-2006-1406</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431131/100/0/threaded" source="BUGTRAQ">20060417 Neuron Blog &lt;= 1.1 XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25913" source="XF">neuronblog-addcomment-xss(25913)</ref>
      <ref url="http://www.securityfocus.com/bid/17552" source="BID">17552</ref>
      <ref url="http://securitytracker.com/id?1015960" source="SECTRACK">1015960</ref>
      <ref url="http://secunia.com/advisories/19703" source="SECUNIA">19703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev" name="neuron_blog">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1900" published="2006-04-20" name="CVE-2006-1900" modified="2011-03-07" discovered="2005-12-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25791" source="XF" patch="1">amaya-various-attribute-bo(25791)</ref>
      <ref url="http://www.osvdb.org/24624" source="OSVDB" patch="1">24624</ref>
      <ref url="http://www.osvdb.org/24623" source="OSVDB" patch="1">24623</ref>
      <ref url="http://secunia.com/advisories/19670" source="SECUNIA" patch="1" adv="1">19670</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1351" source="VUPEN">ADV-2006-1351</ref>
      <ref url="http://www.securityfocus.com/bid/17507" source="BID">17507</ref>
      <ref url="http://morph3us.org/advisories/20060412-amaya-94.txt" source="MISC" adv="1">http://morph3us.org/advisories/20060412-amaya-94.txt</ref>
      <ref url="http://morph3us.org/advisories/20060412-amaya-94-2.txt" source="MISC" adv="1">http://morph3us.org/advisories/20060412-amaya-94-2.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430879/100/0/threaded" source="BUGTRAQ">20060412 [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4 #2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430877/100/0/threaded" source="BUGTRAQ">20060412 [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3c" name="amaya">
        <vers num="9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1901" published="2006-04-20" name="CVE-2006-1901" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Camino 1.0 and earlier allow remote attackers to cause a denial of service (null dereference and application crash or hang) via HTML with certain improperly nested elements.  NOTE: this might be the same issue as CVE-2006-1724.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431004/100/0/threaded" source="BUGTRAQ">20060413 Camino Browser HTML Parsing Null Pointer Dereference Denial of Service Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/772" source="SREASON">772</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="camino">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" edition="alpha1" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.9" edition="alpha2" />
        <vers num="1.0" edition="apha1" />
        <vers num="1.0" edition="beta1" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1902" published="2006-04-20" name="CVE-2006-1902" modified="2011-02-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">fold_binary in fold-const.c in GNU Compiler Collection (gcc) 4.1 improperly handles pointer overflow when folding a certain expr comparison to a corresponding offset comparison in cases other than EQ_EXPR and NE_EXPR, which might introduce buffer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.NOTE: the vendor states that the essence of the issue is "not correctly interpreting an offset to a pointer as a signed value."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431245/100/0/threaded" source="BUGTRAQ">20060418 RE: gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431184/100/0/threaded" source="BUGTRAQ">20060417 gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref>
      <ref url="http://www.securityfocus.com/archive/1/431319/100/0/threaded" source="BUGTRAQ">20060418 Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref>
      <ref url="http://www.securityfocus.com/archive/1/431297/100/0/threaded" source="BUGTRAQ">20060418 Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref>
      <ref url="http://gcc.gnu.org/viewcvs/branches/gcc-4_1-branch/gcc/fold-const.c?r1=110549&amp;r2=112698&amp;pathrev=112698&amp;diff_format=h" source="CONFIRM">http://gcc.gnu.org/viewcvs/branches/gcc-4_1-branch/gcc/fold-const.c?r1=110549&amp;r2=112698&amp;pathrev=112698&amp;diff_format=h</ref>
      <ref url="http://gcc.gnu.org/ml/gcc-bugs/2006-04/msg01298.html" source="MLIST">[gcc-bugs] 20060417 [Bug middle-end/27180] New: pointer arithmetic overflow handling broken</ref>
      <ref url="http://gcc.gnu.org/ml/gcc-bugs/2006-04/msg01297.html" source="MLIST">[gcc-bugs] 20060417 [Bug c/27180] New: pointer arithmetic overflow handling broken</ref>
      <ref url="http://gcc.gnu.org/bugzilla/show_bug.cgi?id=26763" source="CONFIRM">http://gcc.gnu.org/bugzilla/show_bug.cgi?id=26763</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356896" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356896</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gcc">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1903" published="2006-04-20" name="CVE-2006-1903" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila allow remote attackers to inject arbitrary web script or HTML (1) via the referer parameter in sendMail, and via attributes of (2) the A element and certain other HTML elements in web pages edited with the editInBrowser module.  NOTE: the msgReader$1 mode attack vector is already covered by CVE-2006-1769.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431058/100/0/threaded" source="BUGTRAQ">20060414 manila.userland cross site scriptable</ref>
      <ref url="http://www.securityfocus.com/bid/17565" source="BID">17565</ref>
      <ref url="http://www.securityfocus.com/bid/17563" source="BID">17563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="userland" name="manila">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1904" published="2006-04-20" name="CVE-2006-1904" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1395" source="VUPEN">ADV-2006-1395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431135/100/0/threaded" source="BUGTRAQ">20060417 AnimeGenesis &lt;= XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="animegenesis" name="gallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1905" published="2006-04-20" name="CVE-2006-1905" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1432" source="VUPEN">ADV-2006-1432</ref>
      <ref url="http://www.securityfocus.com/bid/17579" source="BID">17579</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431251/100/0/threaded" source="BUGTRAQ">20060418 Remote Xine Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25851" source="XF">xine-playlist-format-string(25851)</ref>
      <ref url="http://www.osvdb.org/24747" source="OSVDB">24747</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_05.html" source="SUSE">SUSE-SA:2006:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:085" source="MANDRIVA">MDKSA-2006:085</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-15.xml" source="GENTOO">GLSA-200604-15</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_id=15429845" source="CONFIRM">http://sourceforge.net/mailarchive/message.php?msg_id=15429845</ref>
      <ref url="http://securitytracker.com/id?1015959" source="SECTRACK">1015959</ref>
      <ref url="http://secunia.com/advisories/20066" source="SECUNIA">20066</ref>
      <ref url="http://secunia.com/advisories/19854" source="SECUNIA">19854</ref>
      <ref url="http://secunia.com/advisories/19671" source="SECUNIA">19671</ref>
      <ref url="http://open-security.org/advisories/16" source="MISC">http://open-security.org/advisories/16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.9.13" />
        <vers num="0.9.18" />
        <vers num="0.9.8" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1_alpha" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc0a" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
        <vers num="1_rc6" />
        <vers num="1_rc6a" />
        <vers num="1_rc7" />
        <vers num="1_rc8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1906" published="2006-04-20" name="CVE-2006-1906" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431308/100/0/threaded" source="BUGTRAQ">20060418 phpLister v. 0.4.1 XSS Attacking</ref>
      <ref url="http://advisory.patriotichackers.com/index.php?itemid=3" source="MISC">http://advisory.patriotichackers.com/index.php?itemid=3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25910" source="XF">phplister-index-xss(25910)</ref>
      <ref url="http://www.securityfocus.com/bid/17591" source="BID">17591</ref>
      <ref url="http://securityreason.com/securityalert/770" source="SREASON">770</ref>
      <ref url="http://securityreason.com/securityalert/735" source="SREASON">735</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jjgan852" name="phplister">
        <vers num="0.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1907" published="2006-04-20" name="CVE-2006-1907" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1384" source="VUPEN">ADV-2006-1384</ref>
      <ref url="http://secunia.com/advisories/19680" source="SECUNIA" adv="1">19680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25886" source="XF">myevent-addevent-del-sql-injection(25886)</ref>
      <ref url="http://www.osvdb.org/24721" source="OSVDB">24721</ref>
      <ref url="http://www.osvdb.org/24720" source="OSVDB">24720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="myevent">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1908" published="2006-04-20" name="CVE-2006-1908" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1384" source="VUPEN">ADV-2006-1384</ref>
      <ref url="http://secunia.com/advisories/19680" source="SECUNIA" adv="1">19680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25885" source="XF">myevent-addevent-xss(25885)</ref>
      <ref url="http://www.osvdb.org/24719" source="OSVDB">24719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="myevent">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1909" published="2006-04-20" name="CVE-2006-1909" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1392" source="VUPEN">ADV-2006-1392</ref>
      <ref url="http://www.securityfocus.com/bid/17570" source="BID">17570</ref>
      <ref url="http://www.securityfocus.com/archive/1/431118/30/0/threaded" source="BUGTRAQ">20060416 Re: [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack</ref>
      <ref url="http://www.securityfocus.com/archive/1/431062" source="BUGTRAQ">20060415 [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack</ref>
      <ref url="http://secunia.com/advisories/19665" source="SECUNIA">19665</ref>
      <ref url="http://myimei.com/security/2006-04-14/copperminephotogallery144-plugininclusionsystemindexphp-remotefileinclusion-attack.html" source="MISC">http://myimei.com/security/2006-04-14/copperminephotogallery144-plugininclusionsystemindexphp-remotefileinclusion-attack.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25866" source="XF">coppermine-index-file-include(25866)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1910" published="2006-04-20" name="CVE-2006-1910" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17566" source="BID">17566</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0282.html" source="FULLDISC">20040614 Serendipity Blog vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="1.0_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1911" published="2006-04-20" name="CVE-2006-1911" modified="2011-03-07" discovered="2006-04-14" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1 allows remote attackers to inject arbitrary web script or HTML via the attachment content disposition in an HTML attachment.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
MyBB, MyBB, 1.1.1</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19668" source="SECUNIA" patch="1" adv="1">19668</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=8232" source="CONFIRM" patch="1">http://community.mybboard.net/showthread.php?tid=8232</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1381" source="VUPEN">ADV-2006-1381</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25864" source="XF">mybb-html-attachment-xss(25864)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1912" published="2006-04-20" name="CVE-2006-1912" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to MyBB 1.1.1</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25865" source="XF">mybb-global-init-data-manipulation(25865)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1381" source="VUPEN">ADV-2006-1381</ref>
      <ref url="http://www.osvdb.org/24711" source="OSVDB">24711</ref>
      <ref url="http://www.osvdb.org/24710" source="OSVDB">24710</ref>
      <ref url="http://secunia.com/advisories/19668" source="SECUNIA" adv="1">19668</ref>
      <ref url="http://myimei.com/security/2006-04-14/mybb110globalphpparameterextracting.html" source="MISC">http://myimei.com/security/2006-04-14/mybb110globalphpparameterextracting.html</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=8232" source="CONFIRM">http://community.mybboard.net/showthread.php?tid=8232</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431061/30/5580/threaded" source="BUGTRAQ">20060415 [KAPDA]MyBB1.1.0~global.php~ParameterExtracting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1913" published="2006-04-20" name="CVE-2006-1913" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1800" source="VUPEN">ADV-2006-1800</ref>
      <ref url="http://www.securityfocus.com/bid/17560" source="BID">17560</ref>
      <ref url="http://secunia.com/advisories/16337" source="SECUNIA">16337</ref>
      <ref url="http://lostmon.blogspot.com/2005/08/jax-php-scripts-multiple.html" source="MISC">http://lostmon.blogspot.com/2005/08/jax-php-scripts-multiple.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26448" source="XF">jaxguestbook-admin-xss(26448)</ref>
      <ref url="http://www.osvdb.org/24991" source="OSVDB">24991</ref>
      <ref url="http://secunia.com/advisories/20110" source="SECUNIA">20110</ref>
      <ref url="http://secunia.com/advisories/19843" source="SECUNIA">19843</ref>
      <ref url="http://kiki91.altervista.org/exploit/jax.txt" source="MISC">http://kiki91.altervista.org/exploit/jax.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jax_scripts" name="jax_guestbook">
        <vers prev="1" num="3.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1914" published="2006-04-20" name="CVE-2006-1914" modified="2008-09-05" discovered="2006-04-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php.  NOTE: this information leak might be resultant from a global variable overwrite issue.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/431117" source="BUGTRAQ">20060416 DbbS&lt;=2.0-alpha Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25922" source="XF">dbbs-multiple-path-disclosure(25922)</ref>
      <ref url="http://securityreason.com/securityalert/771" source="SREASON">771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbbs" name="dbbs">
        <vers prev="1" num="2.0-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1915" published="2006-04-20" name="CVE-2006-1915" modified="2008-09-05" discovered="2006-04-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/431117" source="BUGTRAQ" adv="1">20060416 DbbS&lt;=2.0-alpha Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/771" source="SREASON">771</ref>
      <ref url="http://securityreason.com/securityalert/661" source="SREASON">661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbbs" name="dbbs">
        <vers prev="1" num="2.0-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1916" published="2006-04-20" name="CVE-2006-1916" modified="2008-09-05" discovered="2006-04-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17559" source="BID">17559</ref>
      <ref url="http://www.securityfocus.com/archive/1/431117" source="BUGTRAQ" adv="1">20060416 DbbS&lt;=2.0-alpha Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25923" source="XF">dbbs-profile-xss(25923)</ref>
      <ref url="http://securityreason.com/securityalert/771" source="SREASON">771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbbs" name="dbbs">
        <vers num="2.0" />
        <vers prev="1" num="2.0-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1917" published="2006-04-20" name="CVE-2006-1917" modified="2011-03-07" discovered="2006-04-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1405" source="VUPEN">ADV-2006-1405</ref>
      <ref url="http://www.securityfocus.com/bid/17558" source="BID">17558</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/Blackorpheus_poc" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/Blackorpheus_poc</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25902" source="XF">blackorpheus-member-sql-injection(25902)</ref>
      <ref url="http://secunia.com/advisories/19678" source="SECUNIA">19678</ref>
      <ref url="http://milw0rm.com/exploits/1683" source="MILW0RM">1683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackorpheus" name="clanmemberskript">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1918" published="2006-04-20" name="CVE-2006-1918" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menuid parameter to (1) index.php or (2) forum.php, or the (3) reporeid_print parameter to print.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015939" source="SECTRACK">1015939</ref>
      <ref url="http://www.securityfocus.com/bid/17530" source="BID">17530</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431009/100/0/threaded" source="BUGTRAQ">20060414 Vulnerabilities in Papoo</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1919" published="2006-04-20" name="CVE-2006-1919" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1417" source="VUPEN">ADV-2006-1417</ref>
      <ref url="http://secunia.com/advisories/19726" source="SECUNIA" adv="1">19726</ref>
      <ref url="http://milw0rm.com/exploits/1694" source="MILW0RM">1694</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25937" source="XF">ip-index-file-include(25937)</ref>
      <ref url="http://www.securityfocus.com/bid/17620" source="BID">17620</ref>
      <ref url="http://www.osvdb.org/24743" source="OSVDB">24743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomas_voecking" name="internet_photoshow">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1920" published="2006-04-20" name="CVE-2006-1920" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PMTool 1.2.2 allows remote attackers to execute arbitrary SQL commands via the order parameter in the include files (1) user.inc.php, (2) customer.inc.php, and (3) project.inc.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1416" source="VUPEN">ADV-2006-1416</ref>
      <ref url="http://secunia.com/advisories/19685" source="SECUNIA" adv="1">19685</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25877" source="XF">pmtool-order-sql-injection(25877)</ref>
      <ref url="http://www.securityfocus.com/bid/17599" source="BID">17599</ref>
      <ref url="http://www.osvdb.org/24782" source="OSVDB">24782</ref>
      <ref url="http://www.osvdb.org/24781" source="OSVDB">24781</ref>
      <ref url="http://www.osvdb.org/24780" source="OSVDB">24780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmtool" name="pmtool">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1921" published="2006-04-20" name="CVE-2006-1921" modified="2011-03-07" discovered="2006-04-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1420" source="VUPEN">ADV-2006-1420</ref>
      <ref url="http://secunia.com/advisories/19694" source="SECUNIA" adv="1">19694</ref>
      <ref url="http://milw0rm.com/exploits/1695" source="MILW0RM">1695</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25941" source="XF">phpnettools-nettools-command-execution(25941)</ref>
      <ref url="http://www.securityfocus.com/bid/17601" source="BID">17601</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-June/000839.html" source="VIM">20060609 [VIM] Update Regarding CVE-2006-1921 (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_net_tools" name="php_net_tools">
        <vers num="2.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1922" published="2006-04-20" name="CVE-2006-1922" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1418" source="VUPEN">ADV-2006-1418</ref>
      <ref url="http://secunia.com/advisories/19730" source="SECUNIA" adv="1">19730</ref>
      <ref url="http://www.securityfocus.com/bid/17618" source="BID">17618</ref>
      <ref url="http://www.osvdb.org/24751" source="OSVDB">24751</ref>
      <ref url="http://www.osvdb.org/24748" source="OSVDB">24748</ref>
      <ref url="http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip" source="MISC">http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/totalcalendar-remote-code-execution.html" source="MISC">http://pridels0.blogspot.com/2006/04/totalcalendar-remote-code-execution.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sweetphp" name="totalcalendar">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1923" published="2006-04-20" name="CVE-2006-1923" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) RSS/RSS.php and (2) possibly other vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19719" source="SECUNIA" patch="1">19719</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1424" source="VUPEN">ADV-2006-1424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26269" source="XF">linpha-rss-xss(26269)</ref>
      <ref url="http://www.securityfocus.com/bid/17619" source="BID">17619</ref>
      <ref url="http://www.osvdb.org/24816" source="OSVDB">24816</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000709.html" source="VIM">20060420 LinPHA provenance/acknowledgement</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linpha" name="linpha">
        <vers num="1.0" />
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1924" published="2006-04-20" name="CVE-2006-1924" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19719" source="SECUNIA" patch="1" adv="1">19719</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1424" source="VUPEN">ADV-2006-1424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26268" source="XF">linpha-functionsdbapi-sql-injection(26268)</ref>
      <ref url="http://www.securityfocus.com/bid/17619" source="BID">17619</ref>
      <ref url="http://www.osvdb.org/24817" source="OSVDB">24817</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000709.html" source="VIM">20060420 LinPHA provenance/acknowledgement</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linpha" name="linpha">
        <vers num="1.0" />
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1925" published="2006-04-20" name="CVE-2006-1925" modified="2008-09-05" discovered="2006-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action.  NOTE: this can also produce resultant XSS when the target file does not exist.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25935" source="XF">cutenews-index-source-xss(25935)</ref>
      <ref url="http://www.securityfocus.com/bid/17592" source="BID">17592</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431528/100/0/threaded" source="BUGTRAQ">20060420 Re: CuteNews 1.4.1 &lt;= Cross Site Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/431340/30/0/threaded" source="BUGTRAQ">20060418 CuteNews 1.4.1 &lt;= Cross Site Scripting</ref>
      <ref url="http://securityreason.com/securityalert/775" source="SREASON">775</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1926" published="2006-04-20" name="CVE-2006-1926" modified="2008-09-05" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17606" source="BID">17606</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431354/100/0/threaded" source="BUGTRAQ">20060419 ThWboard &lt;= 3 Beta 2.84 SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25891" source="XF">thwboard-showtopic-sql-injection(25891)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436919/100/0/threaded" source="BUGTRAQ">20060613 Re: BUGTRAQ:20060611 ThWboard 3.0 &lt;= SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436813/100/0/threaded" source="BUGTRAQ">20060611 ThWboard 3.0 &lt;= SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thwboard" name="thwboard">
        <vers num="2.81_beta" />
        <vers num="2.82_beta" />
        <vers num="2.83_beta" />
        <vers num="2.84_beta_3" />
        <vers num="2.8_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1927" published="2006-04-20" name="CVE-2006-1927" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash) via certain MPLS packets, as identified by Cisco bug ID CSCsc77475.</descript>
      <descript source="nvd">Only systems that are running Cisco IOS XR and configured for MPLS are affected by this vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1433" source="VUPEN">ADV-2006-1433</ref>
      <ref url="http://www.securityfocus.com/bid/17607" source="BID">17607</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-xr.shtml" source="CISCO">20060419 Cisco IOS XR MPLS Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25881" source="XF">cisco-iosxr-mpls-dos(25881)</ref>
      <ref url="http://securitytracker.com/id?1015964" source="SECTRACK">1015964</ref>
      <ref url="http://secunia.com/advisories/19740" source="SECUNIA">19740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_xr">
        <vers num="3.0.1" />
        <vers num="3.1.0" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" edition="" />
        <vers num="3.2.3" edition=":prp" />
        <vers num="3.2.3" edition=":crs-1" />
        <vers num="3.2.4" />
        <vers num="3.2.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1928" published="2006-04-20" name="CVE-2006-1928" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2) CSCsd55531.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1433" source="VUPEN">ADV-2006-1433</ref>
      <ref url="http://www.securityfocus.com/bid/17607" source="BID">17607</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-xr.shtml" source="CISCO">20060419 Cisco IOS XR MPLS Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25881" source="XF">cisco-iosxr-mpls-dos(25881)</ref>
      <ref url="http://www.osvdb.org/24811" source="OSVDB">24811</ref>
      <ref url="http://securitytracker.com/id?1015964" source="SECTRACK">1015964</ref>
      <ref url="http://secunia.com/advisories/19740" source="SECUNIA">19740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_xr">
        <vers num="3.0.1" />
        <vers num="3.1.0" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" edition="" />
        <vers num="3.2.3" edition=":prp" />
        <vers num="3.2.3" edition=":crs-1" />
        <vers num="3.2.4" />
        <vers num="3.2.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1929" published="2006-04-20" name="CVE-2006-1929" modified="2011-03-07" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1431" source="VUPEN">ADV-2006-1431</ref>
      <ref url="http://secunia.com/advisories/19684" source="SECUNIA" adv="1">19684</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25963" source="XF">Irater-common-file-include(25963)</ref>
      <ref url="http://www.securityfocus.com/bid/17623" source="BID">17623</ref>
      <ref url="http://www.osvdb.org/24777" source="OSVDB">24777</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/i-rater-platinum-remote-file-inclusion.html" source="MISC">http://pridels0.blogspot.com/2006/04/i-rater-platinum-remote-file-inclusion.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-rater" name="i-rater_platinum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1930" published="2006-04-20" name="CVE-2006-1930" modified="2008-11-03" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in userscript.php in Green Minute 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) huserid, (2) pituus, or (3) date parameters. NOTE: this issue has been disputed by the vendor, saying "those parameters mentioned ARE checked (preg_match) before they are used in SQL-query...  If someone decided to add SQL-injection stuff to certain parameter, they would see an error text, but only because _nothing_ was passed inside that parameter (to MySQL-database)."  As allowed by the vendor, CVE investigated this report on 20060525 and found that the demo site demonstrated a non-sensitive SQL error when given standard SQL injection manipulations.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25942" source="XF">greenminute-userscript-sql-injection(25942)</ref>
      <ref url="http://www.osvdb.org/25207" source="OSVDB">25207</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/green-minute-sql-inj-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/green-minute-sql-inj-vuln.html</ref>
      <ref url="http://osvdb.org/ref/25/25207-dispute.txt" source="MISC">http://osvdb.org/ref/25/25207-dispute.txt</ref>
      <ref url="http://hoito.org/en/products/" source="MISC">http://hoito.org/en/products/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hoito" name="green_minute">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1931" published="2006-04-20" name="CVE-2006-1931" modified="2010-08-21" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189540" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189540</ref>
      <ref url="http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-dev/27787" source="MISC" patch="1">http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-dev/27787</ref>
      <ref url="ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-webrick-dos-1.patch" source="MISC" patch="1">ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-webrick-dos-1.patch</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11100" source="OVAL">oval:org.mitre.oval:def:11100</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26102" source="XF">ruby-socket-dos(26102)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-273-1" source="UBUNTU">USN-273-1</ref>
      <ref url="http://www.securityfocus.com/bid/17645" source="BID">17645</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0427.html" source="REDHAT">RHSA-2006:0427</ref>
      <ref url="http://www.osvdb.org/24972" source="OSVDB">24972</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-06-02.html" source="SUSE">SUSE-SR:2006:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:079" source="MANDRIVA">MDKSA-2006:079</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-11.xml" source="GENTOO">GLSA-200605-11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1157" source="DEBIAN">DSA-1157</ref>
      <ref url="http://securitytracker.com/id?1015978" source="SECTRACK">1015978</ref>
      <ref url="http://secunia.com/advisories/21657" source="SECUNIA">21657</ref>
      <ref url="http://secunia.com/advisories/20457" source="SECUNIA">20457</ref>
      <ref url="http://secunia.com/advisories/20064" source="SECUNIA">20064</ref>
      <ref url="http://secunia.com/advisories/20024" source="SECUNIA">20024</ref>
      <ref url="http://secunia.com/advisories/19804" source="SECUNIA">19804</ref>
      <ref url="http://secunia.com/advisories/19772" source="SECUNIA">19772</ref>
      <ref url="http://secunia.com/advisories/16904" source="SECUNIA">16904</ref>
      <ref url="ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-xmlrpc-dos-1.patch" source="MISC">ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-xmlrpc-dos-1.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yukihiro_matsumoto" name="ruby">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.8" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1932" published="2006-04-25" name="CVE-2006-1932" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9823" source="OVAL">oval:org.mitre.oval:def:9823</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26012" source="XF">ethereal-oid-printing-offbyone(26012)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.14" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1933" published="2006-04-25" name="CVE-2006-1933" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (large or infinite loops) viarafted packets to the (1) UMA and (2) BER dissectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10841" source="OVAL">oval:org.mitre.oval:def:10841</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26024" source="XF">ethereal-ber-loop-dos(26024)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26008" source="XF">ethereal-uma-dissector-dos(26008)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1934" published="2006-04-25" name="CVE-2006-1934" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) ALCAP dissector, (2) Network Instruments file code, or (3) NetXray/Windows Sniffer file code.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10445" source="OVAL">oval:org.mitre.oval:def:10445</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26027" source="XF">ethereal-netxwin-sniffer-bo(26027)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26026" source="XF">ethereal-net-instr-bo(26026)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26014" source="XF">ethereal-alcap-dissector-bo(26014)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1935" published="2006-04-25" name="CVE-2006-1935" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Ethereal 0.9.15 up to 0.10.14 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the COPS dissector.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10811" source="OVAL">oval:org.mitre.oval:def:10811</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26013" source="XF">ethereal-cops-dissector-bo(26013)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1936" published="2006-04-25" name="CVE-2006-1936" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10341" source="OVAL">oval:org.mitre.oval:def:10341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26029" source="XF">ethereal-telnet-dissector-bo(26029)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1937" published="2006-04-25" name="CVE-2006-1937" modified="2011-09-06" discovered="2006-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26031" source="XF">ethereal-h248-dos(26031)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26019" source="XF">ethereal-aim-dos(26019)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26018" source="XF">ethereal-general-dissector-dos(26018)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26015" source="XF">ethereal-statistics-counter-dos(26015)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26011" source="XF">ethereal-h245-dos(26011)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26010" source="XF">ethereal-srvloc-dos(26010)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26009" source="XF">ethereal-x509if-dissector-dos(26009)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26007" source="XF">ethereal-h248-dissector-dos(26007)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN" adv="1">ADV-2006-1501</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA" adv="1">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA" adv="1">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA" adv="1">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA" adv="1">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA" adv="1">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA" adv="1">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA" adv="1">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA" adv="1">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA" adv="1">19769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10323" source="OVAL">oval:org.mitre.oval:def:10323</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1938" published="2006-04-25" name="CVE-2006-1938" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9850" source="OVAL">oval:org.mitre.oval:def:9850</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26023" source="XF">ethereal-smbpipe-dos(26023)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26016" source="XF">ethereal-sniffer-capture-dos(26016)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.8" />
        <vers num="0.8.10" />
        <vers num="0.8.11" />
        <vers num="0.8.12" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.16" />
        <vers num="0.8.17" />
        <vers num="0.8.17a" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.8.20" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="0.9_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1939" published="2006-04-25" name="CVE-2006-1939" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11030" source="OVAL">oval:org.mitre.oval:def:11030</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26033" source="XF">ethereal-per-diss-dos(26033)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26032" source="XF">ethereal-dcerpcnt-dissector-dos(26032)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26030" source="XF">ethereal-asn1based-dissector-dos(26030)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26028" source="XF">ethereal-gsmsms-dissector-dos(26028)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26022" source="XF">ethereal-asn1-dissector-dos(26022)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26021" source="XF">ethereal-dcerpc-dissector-dos(26021)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26020" source="XF">ethereal-rpc-dos(26020)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26017" source="XF">ethereal-display-filter-dos(26017)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="0.9_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1940" published="2006-04-25" name="CVE-2006-1940" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00023.html" source="CONFIRM" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00023.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1501" source="VUPEN">ADV-2006-1501</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9781" source="OVAL">oval:org.mitre.oval:def:9781</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26025" source="XF">ethereal-sndcp-dissector-dos(26025)</ref>
      <ref url="http://www.securityfocus.com/bid/17682" source="BID">17682</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0420.html" source="REDHAT">RHSA-2006:0420</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html" source="FEDORA">FEDORA-2006-461</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html" source="FEDORA">FEDORA-2006-456</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077" source="MANDRIVA">MDKSA-2006:077</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml" source="GENTOO">GLSA-200604-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1049" source="DEBIAN">DSA-1049</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm</ref>
      <ref url="http://securitytracker.com/id?1015985" source="SECTRACK">1015985</ref>
      <ref url="http://secunia.com/advisories/20944" source="SECUNIA">20944</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19962" source="SECUNIA">19962</ref>
      <ref url="http://secunia.com/advisories/19958" source="SECUNIA">19958</ref>
      <ref url="http://secunia.com/advisories/19839" source="SECUNIA">19839</ref>
      <ref url="http://secunia.com/advisories/19828" source="SECUNIA">19828</ref>
      <ref url="http://secunia.com/advisories/19805" source="SECUNIA">19805</ref>
      <ref url="http://secunia.com/advisories/19769" source="SECUNIA">19769</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1941" published="2006-04-20" name="CVE-2006-1941" modified="2011-03-07" discovered="2006-04-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431157/100/0/threaded" source="BUGTRAQ" patch="1">20060417 Neon Responder (Dos,Exploit)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1442" source="VUPEN">ADV-2006-1442</ref>
      <ref url="http://www.securityfocus.com/bid/17569" source="BID">17569</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25904" source="XF">neonresponder-clocksynchronization-dos(25904)</ref>
      <ref url="http://securitytracker.com/id?1015950" source="SECTRACK">1015950</ref>
      <ref url="http://securityreason.com/securityalert/776" source="SREASON">776</ref>
      <ref url="http://securityreason.com/securityalert/731" source="SREASON">731</ref>
      <ref url="http://secunia.com/advisories/19702" source="SECUNIA">19702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neon_software" name="neon_responder">
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1942" published="2006-04-20" name="CVE-2006-1942" modified="2011-03-07" discovered="2006-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gavinsharp.com/tmp/ImageVuln.html" source="MISC" patch="1">http://www.gavinsharp.com/tmp/ImageVuln.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=334341" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=334341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25925" source="XF">firefox-viewimage-security-bypass(25925)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN" adv="1">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN" adv="1">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2106" source="VUPEN" adv="1">ADV-2006-2106</ref>
      <ref url="http://www.securityfocus.com/bid/18228" source="BID">18228</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">SSRT061181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435795/100/0/threaded" source="BUGTRAQ">20060602 rPSA-2006-0091-1 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433539/30/5070/threaded" source="BUGTRAQ">20060507 Re: Firefox 1.5.0.3 code execution exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433138/100/0/threaded" source="BUGTRAQ">20060505 Firefox 1.5.0.3 code execution exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431267/100/0/threaded" source="BUGTRAQ">20060418 Another flaw in Firefox 1.5.0.2: to open files from remote</ref>
      <ref url="http://www.osvdb.org/24713" source="OSVDB">24713</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_35_mozilla.html" source="SUSE">SUSE-SA:2006:035</ref>
      <ref url="http://www.networksecurity.fi/advisories/netscape-view-image.html" source="MISC" adv="1">http://www.networksecurity.fi/advisories/netscape-view-image.html</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-39.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-39.html</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1134" source="DEBIAN">DSA-1134</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1120" source="DEBIAN">DSA-1120</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1118" source="DEBIAN">DSA-1118</ref>
      <ref url="http://securitytracker.com/id?1016202" source="SECTRACK">1016202</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA" adv="1">22066</ref>
      <ref url="http://secunia.com/advisories/21324" source="SECUNIA" adv="1">21324</ref>
      <ref url="http://secunia.com/advisories/21183" source="SECUNIA" adv="1">21183</ref>
      <ref url="http://secunia.com/advisories/21176" source="SECUNIA" adv="1">21176</ref>
      <ref url="http://secunia.com/advisories/20376" source="SECUNIA" adv="1">20376</ref>
      <ref url="http://secunia.com/advisories/20063" source="SECUNIA" adv="1">20063</ref>
      <ref url="http://secunia.com/advisories/19988" source="SECUNIA" adv="1">19988</ref>
      <ref url="http://secunia.com/advisories/19698" source="SECUNIA" adv="1">19698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="k-meleon_project" name="k-meleon">
        <vers num="0.9.13" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.2" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.2" />
        <vers num="8.0.40" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1943" published="2006-04-20" name="CVE-2006-1943" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1409" source="VUPEN">ADV-2006-1409</ref>
      <ref url="http://www.securityfocus.com/bid/17605" source="BID">17605</ref>
      <ref url="http://secunia.com/advisories/19701" source="SECUNIA" adv="1">19701</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25929" source="XF">intellilink-multiple-xss(25929)</ref>
      <ref url="http://www.osvdb.org/24733" source="OSVDB">24733</ref>
      <ref url="http://www.osvdb.org/24732" source="OSVDB">24732</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/intellilink-pro-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/intellilink-pro-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smarter_scripts" name="intellilink_pro">
        <vers num="5.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1944" published="2006-04-20" name="CVE-2006-1944" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1407" source="VUPEN">ADV-2006-1407</ref>
      <ref url="http://www.securityfocus.com/bid/17602" source="BID">17602</ref>
      <ref url="http://secunia.com/advisories/19667" source="SECUNIA" adv="1">19667</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25931" source="XF">communimail-multiple-xss(25931)</ref>
      <ref url="http://www.osvdb.org/24736" source="OSVDB">24736</ref>
      <ref url="http://www.osvdb.org/24735" source="OSVDB">24735</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/communimail-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/communimail-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sibsoft" name="communimail">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1945" published="2006-04-20" name="CVE-2006-1945" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter.  NOTE: this might be the same core issue as CVE-2005-2732.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17621" source="BID">17621</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200606-06.xml" source="GENTOO">GLSA-200606-06</ref>
      <ref url="http://secunia.com/advisories/20496" source="SECUNIA">20496</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/awstats-65-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/awstats-65-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awstats" name="awstats">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers prev="1" num="6.5_1.857" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1946" published="2006-04-20" name="CVE-2006-1946" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter in pblscg.cgi, and (3) the listno parameter in pblsmb.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1408" source="VUPEN">ADV-2006-1408</ref>
      <ref url="http://www.securityfocus.com/bid/17598" source="BID">17598</ref>
      <ref url="http://www.osvdb.org/24718" source="OSVDB">24718</ref>
      <ref url="http://www.osvdb.org/24717" source="OSVDB">24717</ref>
      <ref url="http://www.osvdb.org/24716" source="OSVDB">24716</ref>
      <ref url="http://secunia.com/advisories/19655" source="SECUNIA" adv="1">19655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25928" source="XF">visale-multiple-xss(25928)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/visale-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/visale-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visale" name="visale">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1947" published="2006-04-20" name="CVE-2006-1947" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1423" source="VUPEN">ADV-2006-1423</ref>
      <ref url="http://www.securityfocus.com/bid/17617" source="BID">17617</ref>
      <ref url="http://secunia.com/advisories/19720" source="SECUNIA" adv="1">19720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25918" source="XF">plexum-multiple-sql-injection(25918)</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/plexum-x5-sql-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/plexum-x5-sql-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicplex" name="plexum">
        <vers prev="1" num="x5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1948" published="2006-04-20" name="CVE-2006-1948" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21232945" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21232945</ref>
      <ref url="http://securitytracker.com/id?1015914" source="SECTRACK">1015914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.0" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1949" published="2006-04-20" name="CVE-2006-1949" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in plexcart.pl in NicPlex PlexCart X3 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25917" source="XF">plexcartx3-catid-sql-injection(25917)</ref>
      <ref url="http://secunia.com/advisories/18033" source="SECUNIA">18033</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/plexcart-x3-sql-inj.html" source="MISC">http://pridels0.blogspot.com/2006/04/plexcart-x3-sql-inj.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicplex" name="plexcart">
        <vers prev="1" num="x3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1950" published="2006-04-20" name="CVE-2006-1950" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1410" source="VUPEN">ADV-2006-1410</ref>
      <ref url="http://www.securityfocus.com/bid/17613" source="BID">17613</ref>
      <ref url="http://secunia.com/advisories/19718" source="SECUNIA" adv="1">19718</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25919" source="XF">bannerfarm-banners-xss(25919)</ref>
      <ref url="http://www.osvdb.org/24728" source="OSVDB">24728</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/bannerfarm-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/bannerfarm-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perlcoders_group" name="bannerfarm">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1951" published="2006-04-24" name="CVE-2006-1951" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17648" source="BID" patch="1">17648</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431729/100/0/threaded" source="BUGTRAQ" patch="1">20060421 Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0019.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0019.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1561" source="VUPEN">ADV-2006-1561</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25969" source="XF">tftp-dotdotdotdot-directory-traversal(25969)</ref>
      <ref url="http://securityreason.com/securityalert/778" source="SREASON">778</ref>
      <ref url="http://secunia.com/advisories/19848" source="SECUNIA">19848</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0009.html" source="VULNWATCH">20060421 Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solarwinds" name="tftp_server">
        <vers num="5.0.55_standard" />
        <vers num="5.0.60standard" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1952" published="2006-04-24" name="CVE-2006-1952" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request.</descript>
    </desc>
    <sols>
      <sol source="nvd">According to the vendor, WinAgents TFTP server version 3.2 fixes this directory traversal vulnerability.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1562" source="VUPEN">ADV-2006-1562</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0020.html" source="MISC" adv="1">http://www.rapid7.com/advisories/R7-0020.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25971" source="XF">tftp-dotdotdot-directory-traversal(25971)</ref>
      <ref url="http://www.winagents.com/en/news/410.php" source="CONFIRM">http://www.winagents.com/en/news/410.php</ref>
      <ref url="http://www.securityfocus.com/bid/17718" source="BID">17718</ref>
      <ref url="http://secunia.com/advisories/19844" source="SECUNIA">19844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winagents" name="tftp_server">
        <vers prev="1" num="3.1" edition="" />
        <vers prev="1" num="3.1" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1953" published="2006-05-17" name="CVE-2006-1953" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encoded drive letter) in a URL.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Caucho Technology, Resin, 3.0.19

The following product releases are not vulnerable: 
Caucho Technology, Resin, 3.0.16 
Caucho Technology, Resin, 2.1.12 
Caucho Technology, Resin, 2.1.2 
Caucho Technology, Resin, 2.1.1
Caucho Technology, Resin, 2.0</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18005" source="BID" patch="1">18005</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434150/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060516 Caucho Resin Windows Directory Traversal Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1831" source="VUPEN">ADV-2006-1831</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26478" source="XF">resin-webserver-directory-traversal(26478)</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0024.html" source="MISC">http://www.rapid7.com/advisories/R7-0024.html</ref>
      <ref url="http://www.osvdb.org/25570" source="OSVDB">25570</ref>
      <ref url="http://securitytracker.com/id?1016109" source="SECTRACK">1016109</ref>
      <ref url="http://securityreason.com/securityalert/904" source="SREASON">904</ref>
      <ref url="http://secunia.com/advisories/20125" source="SECUNIA">20125</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0026.html" source="VULNWATCH">20060516 Caucho Resin Windows Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="3.0.17" edition="" />
        <vers num="3.0.17" edition=":windows" />
        <vers num="3.0.18" edition="" />
        <vers num="3.0.18" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1954" published="2006-04-21" name="CVE-2006-1954" modified="2011-03-07" discovered="2006-04-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1425" source="VUPEN">ADV-2006-1425</ref>
      <ref url="http://www.securityfocus.com/bid/17588" source="BID">17588</ref>
      <ref url="http://www.g-0.org/code/rz2-adv.html" source="MISC">http://www.g-0.org/code/rz2-adv.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25911" source="XF">rechnungszentrale-authent-sql-injection(25911)</ref>
      <ref url="http://www.osvdb.org/24752" source="OSVDB">24752</ref>
      <ref url="http://secunia.com/advisories/19728" source="SECUNIA">19728</ref>
      <ref url="http://milw0rm.com/exploits/1699" source="MILW0RM">1699</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0384.html" source="BUGTRAQ">20060419 RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfec.de" name="rechnungszentrale">
        <vers num="v2_1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1955" published="2006-04-21" name="CVE-2006-1955" modified="2011-03-07" discovered="2006-04-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1425" source="VUPEN">ADV-2006-1425</ref>
      <ref url="http://www.securityfocus.com/bid/17589" source="BID">17589</ref>
      <ref url="http://www.g-0.org/code/rz2-adv.html" source="MISC">http://www.g-0.org/code/rz2-adv.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25912" source="XF">rechnungszentrale-authent-file-inclusion(25912)</ref>
      <ref url="http://www.osvdb.org/24753" source="OSVDB">24753</ref>
      <ref url="http://secunia.com/advisories/19728" source="SECUNIA">19728</ref>
      <ref url="http://milw0rm.com/exploits/1699" source="MILW0RM">1699</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0384.html" source="BUGTRAQ">20060419 RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfec.de" name="rechnungszentrale">
        <vers num="v2_1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1956" published="2006-04-21" name="CVE-2006-1956" modified="2008-09-05" discovered="2006-04-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431317/100/0/threaded" source="BUGTRAQ">20060418 [KAPDA::#41] - Mambo/Joomla rss component vulnerability</ref>
      <ref url="http://www.kapda.ir/advisory-313.html" source="MISC">http://www.kapda.ir/advisory-313.html</ref>
      <ref url="http://irannetjob.com/content/view/209/28/" source="MISC">http://irannetjob.com/content/view/209/28/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.7" />
      </prod>
      <prod vendor="mambo" name="mambo">
        <vers num="4.5.3h" edition="h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1957" published="2006-04-21" name="CVE-2006-1957" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with different values of the feed parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431317/100/0/threaded" source="BUGTRAQ">20060418 [KAPDA::#41] - Mambo/Joomla rss component vulnerability</ref>
      <ref url="http://www.kapda.ir/advisory-313.html" source="MISC" adv="1">http://www.kapda.ir/advisory-313.html</ref>
      <ref url="http://irannetjob.com/content/view/209/28/" source="MISC">http://irannetjob.com/content/view/209/28/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26131" source="XF">mambo-joomla-rss-dos(26131)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0380.html" source="BUGTRAQ">20060419 Re: [KAPDA::#41] - Mambo/Joomla rss component vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1958" published="2006-04-21" name="CVE-2006-1958" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1447" source="VUPEN">ADV-2006-1447</ref>
      <ref url="http://www.securityfocus.com/bid/17615" source="BID">17615</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431400/100/0/threaded" source="BUGTRAQ">20060419 WWWThread RC 3 MultBugs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25936" source="XF">wwwthreads-multiple-sql-injection(25936)</ref>
      <ref url="http://securityreason.com/securityalert/739" source="SREASON">739</ref>
      <ref url="http://secunia.com/advisories/19732" source="SECUNIA">19732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wired_community_software" name="wwwthreads">
        <vers num="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1959" published="2006-04-21" name="CVE-2006-1959" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1430" source="VUPEN">ADV-2006-1430</ref>
      <ref url="http://www.securityfocus.com/bid/17597" source="BID">17597</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431351/100/0/threaded" source="BUGTRAQ">20060419 [MajorSecurity]ActualAnalyzer - Remote File Include Vulnerability</ref>
      <ref url="http://secunia.com/advisories/19743" source="SECUNIA">19743</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25893" source="XF">actualanalyzer-direct-file-include(25893)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434562/100/0/threaded" source="BUGTRAQ">20060520 ActualAnalyzer Server &lt;=8.23 - Remote File Include Vulnerability</ref>
      <ref url="http://www.osvdb.org/24778" source="OSVDB">24778</ref>
      <ref url="http://securitytracker.com/id?1015967" source="SECTRACK">1015967</ref>
      <ref url="http://securityreason.com/securityalert/742" source="SREASON">742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="actualscripts" name="actualanalyzer">
        <vers num="2.72" edition="" />
        <vers num="2.72" edition=":lite" />
        <vers num="7.63" edition="gold" />
        <vers prev="1" num="8.23" edition="" />
        <vers prev="1" num="8.23" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1960" published="2006-04-21" name="CVE-2006-1960" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-wlse.shtml" source="CISCO" patch="1">20060419 Multiple Vulnerabilities in the WLSE Appliance</ref>
      <ref url="http://securitytracker.com/id?1015965" source="SECTRACK" patch="1">1015965</ref>
      <ref url="http://secunia.com/advisories/19736" source="SECUNIA" patch="1" adv="1">19736</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1434" source="VUPEN">ADV-2006-1434</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25883" source="XF">cisco-wlse-user-xss(25883)</ref>
      <ref url="http://www.securityfocus.com/bid/17604" source="BID">17604</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431371/30/5490/threaded" source="BUGTRAQ">20060419 Multiple vulnerabilities in Linux based Cisco products</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431367/30/5490/threaded" source="BUGTRAQ">20060419 Re: Multiple vulnerabilities in Linux based Cisco products</ref>
      <ref url="http://www.osvdb.org/24812" source="OSVDB">24812</ref>
      <ref url="http://www.assurance.com.au/advisories/200604-cisco.txt" source="MISC">http://www.assurance.com.au/advisories/200604-cisco.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_solution_engine">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":express" />
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":express" />
        <vers num="2.10" edition="" />
        <vers num="2.10" edition=":express" />
        <vers num="2.11" edition="" />
        <vers num="2.11" edition=":express" />
        <vers num="2.12" edition="" />
        <vers num="2.12" edition=":express" />
        <vers num="2.13" edition="" />
        <vers num="2.13" edition=":express" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":express" />
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":express" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":express" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":express" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":express" />
        <vers num="2.7" edition="" />
        <vers num="2.7" edition=":express" />
        <vers num="2.8" edition="" />
        <vers num="2.8" edition=":express" />
        <vers num="2.9" edition="" />
        <vers num="2.9" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1961" published="2006-04-21" name="CVE-2006-1961" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE).  NOTE: other issues might be addressed by the Cisco advisory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sr-20060419-priv.shtml" source="CISCO" patch="1">20060419 Response to Privilege Escalation on Multiple Cisco Products</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-wlse.shtml" source="CISCO" patch="1">20060419 Multiple Vulnerabilities in the WLSE Appliance</ref>
      <ref url="http://securitytracker.com/id?1015965" source="SECTRACK" patch="1">1015965</ref>
      <ref url="http://secunia.com/advisories/19736" source="SECUNIA" patch="1" adv="1">19736</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25884" source="XF">cisco-wlse-shell-privilege-escalation(25884)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1435" source="VUPEN">ADV-2006-1435</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1434" source="VUPEN">ADV-2006-1434</ref>
      <ref url="http://www.securityfocus.com/bid/17609" source="BID">17609</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431371/30/5490/threaded" source="BUGTRAQ">20060419 Multiple vulnerabilities in Linux based Cisco products</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431367/30/5490/threaded" source="BUGTRAQ">20060419 Re: Multiple vulnerabilities in Linux based Cisco products</ref>
      <ref url="http://www.osvdb.org/24813" source="OSVDB">24813</ref>
      <ref url="http://www.assurance.com.au/advisories/200604-cisco.txt" source="MISC">http://www.assurance.com.au/advisories/200604-cisco.txt</ref>
      <ref url="http://secunia.com/advisories/19741" source="SECUNIA">19741</ref>
      <ref url="http://secunia.com/advisories/19739" source="SECUNIA">19739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ciscoworks_2000_service_management_solution">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="user_registration_tool">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_solution_engine">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":express" />
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":express" />
        <vers num="2.10" edition="" />
        <vers num="2.10" edition=":express" />
        <vers num="2.11" edition="" />
        <vers num="2.11" edition=":express" />
        <vers num="2.12" edition="" />
        <vers num="2.12" edition=":express" />
        <vers num="2.13" edition="" />
        <vers num="2.13" edition=":express" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":express" />
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":express" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":express" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":express" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":express" />
        <vers num="2.7" edition="" />
        <vers num="2.7" edition=":express" />
        <vers num="2.8" edition="" />
        <vers num="2.8" edition=":express" />
        <vers num="2.9" edition="" />
        <vers num="2.9" edition=":express" />
      </prod>
      <prod vendor="cisco" name="hosting_solution_engine">
        <vers num="1.7" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
      <prod vendor="cisco" name="ethernet_subscriber_solution_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1962" published="2006-04-21" name="CVE-2006-1962" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25961" source="XF">pcpin-chat-main-sql-injection(25961)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1441" source="VUPEN" adv="1">ADV-2006-1441</ref>
      <ref url="http://www.securityfocus.com/bid/17632" source="BID">17632</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436029/100/0/threaded" source="BUGTRAQ">20060604 Re: PCPIN Chat &lt;= 5.0.4 </ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431390/100/0/threaded" source="BUGTRAQ">20060419 PCPIN Chat &lt;= 5.0.4 </ref>
      <ref url="http://securitytracker.com/id?1015968" source="SECTRACK">1015968</ref>
      <ref url="http://secunia.com/advisories/19708" source="SECUNIA" adv="1">19708</ref>
      <ref url="http://retrogod.altervista.org/pcpin_504_xpl.html" source="MISC">http://retrogod.altervista.org/pcpin_504_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcpin" name="pcpin_chat">
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers num="3.1.7r" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="4.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1963" published="2006-04-21" name="CVE-2006-1963" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and earlier allows remote authenticated users to include and execute arbitrary PHP code via a ".." (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually contains PHP code.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1441" source="VUPEN">ADV-2006-1441</ref>
      <ref url="http://www.securityfocus.com/bid/17632" source="BID">17632</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431390/100/0/threaded" source="BUGTRAQ">20060419 PCPIN Chat &lt;= 5.0.4 "login/language" remote cmmnds xctn</ref>
      <ref url="http://secunia.com/advisories/19708" source="SECUNIA" adv="1">19708</ref>
      <ref url="http://retrogod.altervista.org/pcpin_504_xpl.html" source="MISC">http://retrogod.altervista.org/pcpin_504_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25962" source="XF">pcpin-chat-main-file-include(25962)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436029/100/0/threaded" source="BUGTRAQ">20060604 Re: PCPIN Chat &lt;= 5.0.4 "login/language" remote cmmnds xctn</ref>
      <ref url="http://securitytracker.com/id?1015968" source="SECTRACK">1015968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcpin" name="pcpin_chat">
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers num="3.1.7r" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="4.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1964" published="2006-04-21" name="CVE-2006-1964" modified="2011-03-07" discovered="2006-04-19" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Haberler.asp in ASPSitem 1.83 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17616" source="BID" patch="1">17616</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431469/100/0/threaded" source="BUGTRAQ" patch="1">20060419 ASPSitem &lt;= 1.83 Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.nukedx.com/?getxpl=23" source="MISC" patch="1">http://www.nukedx.com/?getxpl=23</ref>
      <ref url="http://secunia.com/advisories/19693" source="SECUNIA" patch="1" adv="1">19693</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1439" source="VUPEN">ADV-2006-1439</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25932" source="XF">aspsitem-haberler-sql-injection(25932)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspsitem" name="aspsitem">
        <vers num="1.83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1965" published="2006-04-21" name="CVE-2006-1965" modified="2011-03-07" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1436" source="VUPEN">ADV-2006-1436</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25957" source="XF">netclubspro-multiple-xss(25957)</ref>
      <ref url="http://www.securityfocus.com/bid/17622" source="BID">17622</ref>
      <ref url="http://www.osvdb.org/24757" source="OSVDB">24757</ref>
      <ref url="http://www.osvdb.org/24756" source="OSVDB">24756</ref>
      <ref url="http://www.osvdb.org/24755" source="OSVDB">24755</ref>
      <ref url="http://www.osvdb.org/24754" source="OSVDB">24754</ref>
      <ref url="http://secunia.com/advisories/19651" source="SECUNIA">19651</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/net-clubs-pro-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/net-clubs-pro-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aasi_media" name="net_clubs_pro">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1966" published="2006-04-21" name="CVE-2006-1966" modified="2008-09-05" discovered="2006-04-16" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets.  NOTE: this issue has been disputed in followup posts that suggest that a protection feature is triggering a RST.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431404/100/0/threaded" source="BUGTRAQ">20060416 Fortinet28 box does not resist has small synflood!</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0472.html" source="FULLDISC">20060418 Re: Fortinet28 box does not resist has small synflood!</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0449.html" source="FULLDISC">20060418 Re: Fortinet28 box does not resist has small synflood!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fortinet" name="fortinet28">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1967" published="2006-04-21" name="CVE-2006-1967" modified="2011-03-07" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25940" source="XF">portalpack-multiple-xss(25940)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1440" source="VUPEN">ADV-2006-1440</ref>
      <ref url="http://www.securityfocus.com/bid/17628" source="BID">17628</ref>
      <ref url="http://www.osvdb.org/24761" source="OSVDB">24761</ref>
      <ref url="http://secunia.com/advisories/19695" source="SECUNIA" adv="1">19695</ref>
      <ref url="http://securityreason.com/securityalert/503" source="SREASON">503</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kcscripts" name="kcscripts_calendar">
        <vers num="6.1" />
      </prod>
      <prod vendor="kcscripts" name="portal_pack">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1968" published="2006-04-21" name="CVE-2006-1968" modified="2011-03-07" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25940" source="XF">portalpack-multiple-xss(25940)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1440" source="VUPEN">ADV-2006-1440</ref>
      <ref url="http://www.securityfocus.com/bid/17628" source="BID">17628</ref>
      <ref url="http://www.osvdb.org/24762" source="OSVDB">24762</ref>
      <ref url="http://secunia.com/advisories/19695" source="SECUNIA" adv="1">19695</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kcscripts" name="kcscripts_news_publisher">
        <vers num="6.0" />
      </prod>
      <prod vendor="kcscripts" name="portal_pack">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1969" published="2006-04-21" name="CVE-2006-1969" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1440" source="VUPEN">ADV-2006-1440</ref>
      <ref url="http://secunia.com/advisories/19695" source="SECUNIA" adv="1">19695</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25940" source="XF">portalpack-multiple-xss(25940)</ref>
      <ref url="http://www.securityfocus.com/bid/17628" source="BID">17628</ref>
      <ref url="http://www.osvdb.org/24763" source="OSVDB">24763</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kcscripts" name="portal_pack">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1970" published="2006-04-21" name="CVE-2006-1970" modified="2011-03-07" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1440" source="VUPEN">ADV-2006-1440</ref>
      <ref url="http://secunia.com/advisories/19695" source="SECUNIA" adv="1">19695</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25940" source="XF">portalpack-multiple-xss(25940)</ref>
      <ref url="http://www.securityfocus.com/bid/17628" source="BID">17628</ref>
      <ref url="http://www.osvdb.org/24764" source="OSVDB">24764</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kcscripts" name="portal_pack">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1971" published="2006-04-21" name="CVE-2006-1971" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1438" source="VUPEN">ADV-2006-1438</ref>
      <ref url="http://www.securityfocus.com/bid/17612" source="BID">17612</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431386/100/0/threaded" source="BUGTRAQ">20060419 ContentBoxx Login.php Cross-Site Scripting</ref>
      <ref url="http://secunia.com/advisories/19733" source="SECUNIA" adv="1">19733</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25952" source="XF">contentboxx-login-xss(25952)</ref>
      <ref url="http://www.osvdb.org/24768" source="OSVDB">24768</ref>
      <ref url="http://securityreason.com/securityalert/779" source="SREASON">779</ref>
      <ref url="http://securityreason.com/securityalert/740" source="SREASON">740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="krankikom" name="contentboxx">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1972" published="2006-04-21" name="CVE-2006-1972" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1437" source="VUPEN">ADV-2006-1437</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431430/100/0/threaded" source="BUGTRAQ">20060419 EasyGallery Cross-Site Scripting</ref>
      <ref url="http://advisory.patriotichackers.com/index.php?itemid=5" source="MISC">http://advisory.patriotichackers.com/index.php?itemid=5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25943" source="XF">easygallery-script-xss(25943)</ref>
      <ref url="http://www.securityfocus.com/bid/17624" source="BID">17624</ref>
      <ref url="http://securityreason.com/securityalert/746" source="SREASON">746</ref>
      <ref url="http://secunia.com/advisories/19713" source="SECUNIA">19713</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wingnut" name="easygallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1973" published="2006-04-21" name="CVE-2006-1973" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/621566" source="CERT-VN" adv="1">VU#621566</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1443" source="VUPEN">ADV-2006-1443</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MIMG-6GMMW4" source="MISC">http://www.kb.cert.org/vuls/id/MIMG-6GMMW4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25915" source="XF">linksys-rt31p2-sip-dos(25915)</ref>
      <ref url="http://www.securityfocus.com/bid/17631" source="BID">17631</ref>
      <ref url="http://www.osvdb.org/24810" source="OSVDB">24810</ref>
      <ref url="http://secunia.com/advisories/19722" source="SECUNIA">19722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="rt31p2">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1974" published="2006-04-21" name="CVE-2006-1974" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16443/exploit" source="MISC">http://www.securityfocus.com/bid/16443/exploit</ref>
      <ref url="http://www.securityfocus.com/bid/16443" source="BID">16443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0_final" />
        <vers num="1.0_pr2" />
        <vers num="1.0_preview_release_2" />
        <vers num="1.0_rc2" />
        <vers num="1.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1975" published="2006-04-21" name="CVE-2006-1975" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23962" source="OSVDB">23962</ref>
      <ref url="http://osvdb.org/ref/23/23962-gastebuch.txt" source="MISC">http://osvdb.org/ref/23/23962-gastebuch.txt</ref>
      <ref url="http://secunia.com/advisories/19810" source="SECUNIA">19810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stadtaus.com" name="php-gastebuch">
        <vers num="1.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1976" published="2006-04-21" name="CVE-2006-1976" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23958" source="OSVDB" patch="1">23958</ref>
      <ref url="http://osvdb.org/ref/23/23958-prb.txt" source="MISC">http://osvdb.org/ref/23/23958-prb.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geekforgod.net" name="prayer_request_board">
        <vers num="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1977" published="2006-04-21" name="CVE-2006-1977" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FlexBB 0.5.7 BETA and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) message parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1393" source="VUPEN">ADV-2006-1393</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431071/100/0/threaded" source="BUGTRAQ">20060415 FlexBB &lt;= 0.5.7 BETA XSS</ref>
      <ref url="http://securitytracker.com/id?1015946" source="SECTRACK">1015946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25868" source="XF">flexbb-newthread-xss(25868)</ref>
      <ref url="http://securityreason.com/securityalert/777" source="SREASON">777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexbb" name="flexbb">
        <vers prev="1" num="0.5.7_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1978" published="2006-04-21" name="CVE-2006-1978" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431156/100/0/threaded" source="BUGTRAQ">20060417 FlexBB 0.5.5 Bypass Exploit</ref>
      <ref url="http://securitytracker.com/id?1015949" source="SECTRACK">1015949</ref>
      <ref url="http://www.securityfocus.com/bid/17568" source="BID">17568</ref>
      <ref url="http://milw0rm.com/exploits/1686" source="MILW0RM">1686</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1979" published="2006-04-21" name="CVE-2006-1979" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17630" source="BID">17630</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431507/100/0/threaded" source="BUGTRAQ">20060420 [eVuln] MWGuest XSS Vulnerability</ref>
      <ref url="http://evuln.com/vulns/122/summary.html" source="MISC">http://evuln.com/vulns/122/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25674" source="XF">mwguest-mwguest-xss(25674)</ref>
      <ref url="http://securityreason.com/securityalert/747" source="SREASON">747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manic_web" name="mwguest">
        <vers num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1980" published="2006-04-21" name="CVE-2006-1980" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25947" source="XF">w2bonlinebanking-sid-xss(25947)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1445" source="VUPEN">ADV-2006-1445</ref>
      <ref url="http://www.securityfocus.com/bid/17626" source="BID">17626</ref>
      <ref url="http://www.osvdb.org/24759" source="OSVDB">24759</ref>
      <ref url="http://secunia.com/advisories/19717" source="SECUNIA" adv="1">19717</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/w2b-online-banking-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/w2b-online-banking-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w2b" name="online_banking">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1981" published="2006-04-21" name="CVE-2006-1981" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1398" source="VUPEN">ADV-2006-1398</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303658" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303658</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26167" source="XF">macosx-java-inputmethods-info-disclosure(26167)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1982" published="2006-04-21" name="CVE-2006-1982" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://www.security-protocols.com/sp-x24-advisory.php" source="MISC" patch="1" adv="1">http://www.security-protocols.com/sp-x24-advisory.php</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303411" source="MISC" patch="1">http://docs.info.apple.com/article.html?artnum=303411</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN" adv="1">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233</ref>
      <ref url="http://www.osvdb.org/31837" source="OSVDB">31837</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA" adv="1">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1983" published="2006-04-21" name="CVE-2006-1983" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit.  NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://securitytracker.com/id?1016067" source="SECTRACK" patch="1">1016067</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25951" source="XF">macosx-predictorvsetfield-bo(25951)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25949" source="XF">macosx-cfallocatorallocate-bo(25949)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN" adv="1">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/sp-x30-advisory.php" source="MISC" adv="1">http://www.security-protocols.com/sp-x30-advisory.php</ref>
      <ref url="http://www.security-protocols.com/sp-x28-advisory.php" source="MISC" adv="1">http://www.security-protocols.com/sp-x28-advisory.php</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233</ref>
      <ref url="http://www.osvdb.org/24822" source="OSVDB">24822</ref>
      <ref url="http://www.osvdb.org/24821" source="OSVDB">24821</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA" adv="1">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1984" published="2006-04-21" name="CVE-2006-1984" modified="2011-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25950" source="XF">macosx-tiffsetfield-bo(25950)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN" adv="1">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/sp-x29-advisory.php" source="MISC" adv="1">http://www.security-protocols.com/sp-x29-advisory.php</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA" adv="1">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers prev="1" num="10.4.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers prev="1" num="10.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1985" published="2006-04-21" name="CVE-2006-1985" modified="2011-10-18" discovered="2006-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT" patch="1" adv="1">TA06-132A</ref>
      <ref url="http://www.security-protocols.com/sp-x25-advisory.php" source="MISC" patch="1" adv="1">http://www.security-protocols.com/sp-x25-advisory.php</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA" patch="1" adv="1">20077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE" patch="1">APPLE-SA-2006-05-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25945" source="XF">macosx-archivehelper-bo(25945)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN" adv="1">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN" adv="1">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233</ref>
      <ref url="http://www.osvdb.org/24819" source="OSVDB">24819</ref>
      <ref url="http://securitytracker.com/id?1016082" source="SECTRACK">1016082</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA" adv="1">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1986" published="2006-04-21" name="CVE-2006-1986" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/sp-x26-advisory.php" source="MISC" adv="1">http://www.security-protocols.com/sp-x26-advisory.php</ref>
      <ref url="http://security-protocols.com/poc/sp-x26-1.html" source="MISC">http://security-protocols.com/poc/sp-x26-1.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25946" source="XF">macosx-safari-dos(25946)</ref>
      <ref url="http://www.osvdb.org/24823" source="OSVDB">24823</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1987" published="2006-04-21" name="CVE-2006-1987" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value.  NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/sp-x26-advisory.php" source="MISC" adv="1">http://www.security-protocols.com/sp-x26-advisory.php</ref>
      <ref url="http://security-protocols.com/poc/sp-x26-4.html" source="MISC">http://security-protocols.com/poc/sp-x26-4.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25946" source="XF">macosx-safari-dos(25946)</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1988" published="2006-04-21" name="CVE-2006-1988" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1452" source="VUPEN">ADV-2006-1452</ref>
      <ref url="http://www.securityfocus.com/bid/17634" source="BID">17634</ref>
      <ref url="http://www.security-protocols.com/sp-x26-advisory.php" source="MISC" adv="1">http://www.security-protocols.com/sp-x26-advisory.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25946" source="XF">macosx-safari-dos(25946)</ref>
      <ref url="http://www.osvdb.org/24823" source="OSVDB">24823</ref>
      <ref url="http://security-protocols.com/poc/sp-x26-2.html" source="MISC">http://security-protocols.com/poc/sp-x26-2.html</ref>
      <ref url="http://secunia.com/advisories/19686" source="SECUNIA">19686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1989" published="2006-05-01" name="CVE-2006-1989" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Clam Anti-Virus, ClamAV, 0.88.2</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/599220" source="CERT-VN">VU#599220</ref>
      <ref url="http://www.securityfocus.com/bid/17754" source="BID" patch="1">17754</ref>
      <ref url="http://secunia.com/advisories/19880" source="SECUNIA" patch="1" adv="1">19880</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2566" source="VUPEN">ADV-2006-2566</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1586" source="VUPEN">ADV-2006-1586</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.osvdb.org/25120" source="OSVDB">25120</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_05.html" source="SUSE">SUSE-SA:2006:025</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-03.xml" source="GENTOO">GLSA-200605-03</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1050" source="DEBIAN">DSA-1050</ref>
      <ref url="http://www.clamav.net/security/0.88.2.html" source="CONFIRM" adv="1">http://www.clamav.net/security/0.88.2.html</ref>
      <ref url="http://secunia.com/advisories/20159" source="SECUNIA">20159</ref>
      <ref url="http://secunia.com/advisories/20117" source="SECUNIA">20117</ref>
      <ref url="http://secunia.com/advisories/19964" source="SECUNIA">19964</ref>
      <ref url="http://secunia.com/advisories/19963" source="SECUNIA">19963</ref>
      <ref url="http://secunia.com/advisories/19912" source="SECUNIA">19912</ref>
      <ref url="http://secunia.com/advisories/19874" source="SECUNIA">19874</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html" source="SUSE">SUSE-SR:2006:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html" source="APPLE">APPLE-SA-2006-06-27</ref>
      <ref url="http://kolab.org/security/kolab-vendor-notice-09.txt" source="CONFIRM">http://kolab.org/security/kolab-vendor-notice-09.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26182" source="XF">clamav-freshclam-http-bo(26182)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:080" source="MANDRIVA">MDKSA-2006:080</ref>
      <ref url="http://securitytracker.com/id?1016392" source="SECTRACK">1016392</ref>
      <ref url="http://secunia.com/advisories/20877" source="SECUNIA">20877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.88" />
        <vers num="0.88.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1990" published="2006-04-24" name="CVE-2006-1990" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html" source="CERT">TA06-333A</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4750" source="VUPEN">ADV-2006-4750</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1500" source="VUPEN">ADV-2006-1500</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:091" source="MANDRIVA">MDKSA-2006:091</ref>
      <ref url="http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02" source="MISC">http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9696" source="OVAL">oval:org.mitre.oval:def:9696</ref>
      <ref url="https://issues.rpath.com/browse/RPL-683" source="CONFIRM">https://issues.rpath.com/browse/RPL-683</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26001" source="XF">php-wordwrap-string-bo(26001)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-320-1" source="UBUNTU">USN-320-1</ref>
      <ref url="http://www.turbolinux.com/security/2006/TLSA-2006-38.txt" source="TURBO">TLSA-2006-38</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447866/100/0/threaded" source="BUGTRAQ">20061005 rPSA-2006-0182-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0568.html" source="REDHAT">RHSA-2006:0568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0501.html" source="REDHAT">RHSA-2006:0501</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_31_php.html" source="SUSE">SUSE-SA:2006:031</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122" source="MANDRIVA">MDKSA-2006:122</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:091" source="MANDRAKE">MDKSA-2006:091</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm</ref>
      <ref url="http://securitytracker.com/id?1015979" source="SECTRACK">1015979</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200605-08.xml" source="GENTOO">GLSA-200605-08</ref>
      <ref url="http://secunia.com/advisories/23155" source="SECUNIA">23155</ref>
      <ref url="http://secunia.com/advisories/22225" source="SECUNIA">22225</ref>
      <ref url="http://secunia.com/advisories/21723" source="SECUNIA">21723</ref>
      <ref url="http://secunia.com/advisories/21564" source="SECUNIA">21564</ref>
      <ref url="http://secunia.com/advisories/21252" source="SECUNIA">21252</ref>
      <ref url="http://secunia.com/advisories/21135" source="SECUNIA">21135</ref>
      <ref url="http://secunia.com/advisories/21125" source="SECUNIA">21125</ref>
      <ref url="http://secunia.com/advisories/21050" source="SECUNIA">21050</ref>
      <ref url="http://secunia.com/advisories/21031" source="SECUNIA">21031</ref>
      <ref url="http://secunia.com/advisories/20676" source="SECUNIA">20676</ref>
      <ref url="http://secunia.com/advisories/20269" source="SECUNIA">20269</ref>
      <ref url="http://secunia.com/advisories/20222" source="SECUNIA">20222</ref>
      <ref url="http://secunia.com/advisories/20052" source="SECUNIA">20052</ref>
      <ref url="http://secunia.com/advisories/19803" source="SECUNIA">19803</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0549.html" source="REDHAT">RHSA-2006:0549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html" source="APPLE">APPLE-SA-2006-11-28</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=304829" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=304829</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U" source="SGI">20060701-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.2" />
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1991" published="2006-04-24" name="CVE-2006-1991" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/20269" source="SECUNIA" patch="1" adv="1">20269</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26003" source="XF">php-substrcompare-length-dos(26003)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1500" source="VUPEN" adv="1">ADV-2006-1500</ref>
      <ref url="http://www.ubuntu.com/usn/usn-320-1" source="UBUNTU">USN-320-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_31_php.html" source="SUSE">SUSE-SA:2006:031</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:091" source="MANDRAKE">MDKSA-2006:091</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:091" source="MANDRIVA">MDKSA-2006:091</ref>
      <ref url="http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02" source="MISC">http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02</ref>
      <ref url="http://securitytracker.com/id?1015979" source="SECTRACK">1015979</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200605-08.xml" source="GENTOO">GLSA-200605-08</ref>
      <ref url="http://secunia.com/advisories/21125" source="SECUNIA" adv="1">21125</ref>
      <ref url="http://secunia.com/advisories/20676" source="SECUNIA" adv="1">20676</ref>
      <ref url="http://secunia.com/advisories/20052" source="SECUNIA" adv="1">20052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1992" published="2006-04-24" name="CVE-2006-1992" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences.  NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx" source="MS" patch="1">MS06-021</ref>
      <ref url="http://securitytracker.com/id?1016291" source="SECTRACK" patch="1">1016291</ref>
      <ref url="http://secunia.com/advisories/19762" source="SECUNIA" patch="1" adv="1">19762</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25978" source="XF">ie-object-memory-corruption(25978)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1507" source="VUPEN" adv="1">ADV-2006-1507</ref>
      <ref url="http://www.securityfocus.com/bid/17658" source="BID">17658</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431796/100/0/threaded" source="BUGTRAQ">20060422 MSIE (mshtml.dll) OBJECT tag vulnerability</ref>
      <ref url="http://www.osvdb.org/27475" source="OSVDB">27475</ref>
      <ref url="http://securitytracker.com/id?1016001" source="SECTRACK">1016001</ref>
      <ref url="http://securityreason.com/securityalert/781" source="SREASON">781</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045422.html" source="FULLDISC">20060423 MSIE (mshtml.dll) OBJECT tag vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0616.html" source="FULLDISC">20060422 Re: MSIE (mshtml.dll) OBJECT tag vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1993" published="2006-04-25" name="CVE-2006-1993" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object.  NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/866300" source="CERT-VN" adv="1">VU#866300</ref>
      <ref url="http://www.securityfocus.com/bid/17671" source="BID" patch="1">17671</ref>
      <ref url="http://secunia.com/advisories/19802" source="SECUNIA" patch="1" adv="1">19802</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25994" source="XF">firefox-iframe-contentwindowfocus-bo(25994)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN" adv="1">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3748" source="VUPEN" adv="1">ADV-2006-3748</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1922" source="VUPEN" adv="1">ADV-2006-1922</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1614" source="VUPEN" adv="1">ADV-2006-1614</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded" source="HP">HPSBUX02153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded" source="HP">SSRT061145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431878/100/0/threaded" source="BUGTRAQ">20060424 Firefox Remote Code Execution and DoS 1.5.0.2</ref>
      <ref url="http://www.securident.com/vuln/ff.txt" source="MISC">http://www.securident.com/vuln/ff.txt</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-30.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2006/mfsa2006-30.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-06.xml" source="GENTOO">GLSA-200605-06</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1055" source="DEBIAN">DSA-1055</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1053" source="DEBIAN">DSA-1053</ref>
      <ref url="http://securitytracker.com/id?1015981" source="SECTRACK">1015981</ref>
      <ref url="http://securityreason.com/securityalert/780" source="SREASON">780</ref>
      <ref url="http://secunia.com/advisories/22066" source="SECUNIA" adv="1">22066</ref>
      <ref url="http://secunia.com/advisories/20214" source="SECUNIA" adv="1">20214</ref>
      <ref url="http://secunia.com/advisories/20070" source="SECUNIA" adv="1">20070</ref>
      <ref url="http://secunia.com/advisories/20019" source="SECUNIA" adv="1">20019</ref>
      <ref url="http://secunia.com/advisories/20015" source="SECUNIA" adv="1">20015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1790" source="OVAL" sig="1">oval:org.mitre.oval:def:1790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-1994" published="2006-04-25" name="CVE-2006-1994" modified="2011-03-07" discovered="2006-04-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1482" source="VUPEN">ADV-2006-1482</ref>
      <ref url="http://www.securityfocus.com/bid/17650" source="BID">17650</ref>
      <ref url="http://www.securityfocus.com/archive/1/431758" source="BUGTRAQ">20060421 dForum &lt;= 1.5 Multiple Remote File Inclusion Vulnerabilities.</ref>
      <ref url="http://www.nukedx.com/?viewdoc=27" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=27</ref>
      <ref url="http://secunia.com/advisories/19788" source="SECUNIA" adv="1">19788</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26035" source="XF">dforum-dforumpath-parameter-file-include(26035)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045369.html" source="FULLDISC">20060421 dForum &lt;= 1.5 Multiple Remote File Inclusion Vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dforum" name="dforum">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1995" published="2006-04-25" name="CVE-2006-1995" modified="2011-03-07" discovered="2006-04-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1490" source="VUPEN">ADV-2006-1490</ref>
      <ref url="http://www.securityfocus.com/bid/17649" source="BID">17649</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431716/100/0/threaded" source="BUGTRAQ">20060421 Scry Gallery Directory Traversal &amp; Full Path Disclosure Vulnerabilites</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/17649-directory-traversal.exploit" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/17649-directory-traversal.exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25991" source="XF">scry-gallery-index-directory-traversal(25991)</ref>
      <ref url="http://www.securityfocus.com/bid/17668" source="BID">17668</ref>
      <ref url="http://www.osvdb.org/24889" source="OSVDB">24889</ref>
      <ref url="http://securityreason.com/securityalert/784" source="SREASON">784</ref>
      <ref url="http://secunia.com/advisories/19777" source="SECUNIA">19777</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000716.html" source="VIM">20060425 Interesting Scry stuff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scry_gallery" name="scry_gallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1996" published="2006-04-25" name="CVE-2006-1996" modified="2011-03-07" discovered="2006-04-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1490" source="VUPEN">ADV-2006-1490</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431716/100/0/threaded" source="BUGTRAQ">20060421 Scry Gallery Directory Traversal &amp; Full Path Disclosure Vulnerabilites</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25990" source="XF">scry-gallery-index-path-disclosure(25990)</ref>
      <ref url="http://www.securityfocus.com/bid/17668" source="BID">17668</ref>
      <ref url="http://www.osvdb.org/24890" source="OSVDB">24890</ref>
      <ref url="http://securityreason.com/securityalert/784" source="SREASON">784</ref>
      <ref url="http://secunia.com/advisories/19777" source="SECUNIA">19777</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000716.html" source="VIM">20060425 Interesting Scry stuff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scry_gallery" name="scry_gallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1997" published="2006-04-25" name="CVE-2006-1997" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.sybase.com/detail?id=1040213" source="CONFIRM" patch="1">http://www.sybase.com/detail?id=1040213</ref>
      <ref url="http://secunia.com/advisories/19784" source="SECUNIA" patch="1" adv="1">19784</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25989" source="XF">pylon-groupware-unauth-access(25989)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1477" source="VUPEN" adv="1">ADV-2006-1477</ref>
      <ref url="http://www.securityfocus.com/bid/17677" source="BID">17677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="pylon_anywhere">
        <vers num="5.5.4" />
        <vers num="6.2.1" />
        <vers num="6.3.2" />
        <vers num="6.4.2" />
        <vers num="6.4.8" />
        <vers num="6.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-1998" published="2006-04-25" name="CVE-2006-1998" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">OpenTTD 0.4.7 and earlier allows local users to cause a denial of service (application exit) via a large invalid error number, which triggers an error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/openttdx-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/openttdx-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1480" source="VUPEN">ADV-2006-1480</ref>
      <ref url="http://secunia.com/advisories/19768" source="SECUNIA" adv="1">19768</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26000" source="XF">openttd-command-packet-dos(26000)</ref>
      <ref url="http://www.securityfocus.com/bid/17661" source="BID">17661</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431871/100/0/threaded" source="BUGTRAQ">20060423 Denial of service bugs in OpenTTD 0.4.7</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200609-03.xml" source="GENTOO">GLSA-200609-03</ref>
      <ref url="http://secunia.com/advisories/21799" source="SECUNIA">21799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openttd" name="openttd">
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.2.1" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.4.0" />
        <vers num="0.4.0.1" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-1999" published="2006-04-25" name="CVE-2006-1999" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/openttdx-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/openttdx-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1480" source="VUPEN">ADV-2006-1480</ref>
      <ref url="http://secunia.com/advisories/19768" source="SECUNIA" adv="1">19768</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26004" source="XF">openttd-udp-packet-dos(26004)</ref>
      <ref url="http://www.securityfocus.com/bid/17661" source="BID">17661</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431871/100/0/threaded" source="BUGTRAQ">20060423 Denial of service bugs in OpenTTD 0.4.7</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200609-03.xml" source="GENTOO">GLSA-200609-03</ref>
      <ref url="http://secunia.com/advisories/21799" source="SECUNIA">21799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openttd" name="openttd">
        <vers num="0.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2000" published="2006-04-25" name="CVE-2006-2000" modified="2011-03-07" discovered="2006-04-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1484" source="VUPEN">ADV-2006-1484</ref>
      <ref url="http://secunia.com/advisories/19793" source="SECUNIA" adv="1">19793</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25968" source="XF">logmethods-lmsa2z-xss(25968)</ref>
      <ref url="http://www.securityfocus.com/bid/17675" source="BID">17675</ref>
      <ref url="http://www.osvdb.org/24876" source="OSVDB">24876</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/logmethods-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/logmethods-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logmethods" name="logmethods">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2001" published="2006-04-25" name="CVE-2006-2001" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: this is a different vulnerability than the directory traversal vector.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1490" source="VUPEN">ADV-2006-1490</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431853/100/0/threaded" source="BUGTRAQ">20060424 Scry Gallery XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26101" source="XF">scry-gallery-index-xss(26101)</ref>
      <ref url="http://www.securityfocus.com/bid/17668" source="BID">17668</ref>
      <ref url="http://www.osvdb.org/24891" source="OSVDB">24891</ref>
      <ref url="http://securityreason.com/securityalert/783" source="SREASON">783</ref>
      <ref url="http://secunia.com/advisories/19777" source="SECUNIA">19777</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-April/000716.html" source="VIM">20060425 Interesting Scry stuff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scry_gallery" name="scry_gallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2002" published="2006-04-25" name="CVE-2006-2002" modified="2011-03-07" discovered="2006-04-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter.</descript>
      <descript source="nvd">Successful exploitation requires that "register_globals" is enabled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1483" source="VUPEN">ADV-2006-1483</ref>
      <ref url="http://www.securityfocus.com/bid/17657" source="BID">17657</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431902/100/0/threaded" source="BUGTRAQ">20060422 Advisory: My Gaming Ladder Combo System &lt;= 7.0 Remote File Inclusion Vulnerability.</ref>
      <ref url="http://www.nukedx.com/?viewdoc=28" source="MISC">http://www.nukedx.com/?viewdoc=28</ref>
      <ref url="http://secunia.com/advisories/19773" source="SECUNIA" adv="1">19773</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25992" source="XF">mygamingladder-stats-file-inclusion(25992)</ref>
      <ref url="http://www.osvdb.org/24892" source="OSVDB">24892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mygamingladder" name="mygamingladder">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2003" published="2006-04-25" name="CVE-2006-2003" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1446" source="VUPEN">ADV-2006-1446</ref>
      <ref url="http://www.osvdb.org/24784" source="OSVDB">24784</ref>
      <ref url="http://secunia.com/advisories/19742" source="SECUNIA" adv="1">19742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="community_architect" name="community_architect_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2004" published="2006-04-25" name="CVE-2006-2004" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1489" source="VUPEN">ADV-2006-1489</ref>
      <ref url="http://www.securityfocus.com/bid/17654" source="BID">17654</ref>
      <ref url="http://secunia.com/advisories/19783" source="SECUNIA" adv="1">19783</ref>
      <ref url="http://colander.altervista.org/advisory/riblog.txt" source="MISC">http://colander.altervista.org/advisory/riblog.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26132" source="XF">riblog-login-sql-injection(26132)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431868/100/0/threaded" source="BUGTRAQ">20060423 RIblog Remote SQL Injection Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_romedahl" name="ri_blog">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2005" published="2006-04-25" name="CVE-2006-2005" modified="2008-09-05" discovered="2006-04-23" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement.  NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17660" source="BID">17660</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431873/100/0/threaded" source="BUGTRAQ" adv="1">20060423 Advisory: Clansys &lt;= 1.1 PHP Code Insertion Vulnerability.</ref>
      <ref url="http://www.nukedx.com/?getxpl=29" source="MISC">http://www.nukedx.com/?getxpl=29</ref>
      <ref url="http://securitytracker.com/id?1015988" source="SECTRACK">1015988</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25976" source="XF">clansys-index-file-include(25976)</ref>
      <ref url="http://www.osvdb.org/25083" source="OSVDB">25083</ref>
      <ref url="http://securityreason.com/securityalert/782" source="SREASON">782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clansys" name="clansys">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2006" published="2006-04-25" name="CVE-2006-2006" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in IZArc Archiver 3.5 beta 3 allow remote attackers to write arbitrary files via a ..\ (dot dot backslash) in a (1) .rar, (2) .tar, (3) .zip, (4) .jar, or (5) .gz archive.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1488" source="VUPEN">ADV-2006-1488</ref>
      <ref url="http://www.securityfocus.com/bid/17664" source="BID">17664</ref>
      <ref url="http://secunia.com/advisories/19791" source="SECUNIA" adv="1">19791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26039" source="XF">izarc-extract-directory-traversal(26039)</ref>
      <ref url="http://www.osvdb.org/24895" source="OSVDB">24895</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ivan_zahariev" name="izarc">
        <vers num="3.5_beta_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2007" published="2006-04-25" name="CVE-2006-2007" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Winny 2.0 b7.1 and earlier allows remote attackers to execute arbitrary code via long strings to certain commands sent to the file transfer port.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/167033" source="CERT-VN">VU#167033</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1486" source="VUPEN">ADV-2006-1486</ref>
      <ref url="http://www.securityfocus.com/bid/17666" source="BID">17666</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20060421.html" source="MISC" adv="1">http://www.eeye.com/html/research/advisories/AD20060421.html</ref>
      <ref url="http://secunia.com/advisories/19795" source="SECUNIA" adv="1">19795</ref>
      <ref url="http://jvn.jp/jp/JVN%2374294680/index.html" source="JVN">JVN#74294680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25986" source="XF">winny-file-transfer-bo(25986)</ref>
      <ref url="http://www.osvdb.org/24883" source="OSVDB">24883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winny" name="winny">
        <vers num="2.0b5.7" />
        <vers num="2.0b7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2008" published="2006-04-25" name="CVE-2006-2008" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1481" source="VUPEN">ADV-2006-1481</ref>
      <ref url="http://secunia.com/advisories/19749" source="SECUNIA" adv="1">19749</ref>
      <ref url="http://milw0rm.com/exploits/1711" source="MILW0RM">1711</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26063" source="XF">moviereview-moviecls-file-include(26063)</ref>
      <ref url="http://www.securityfocus.com/bid/17679" source="BID">17679</ref>
      <ref url="http://www.osvdb.org/24887" source="OSVDB">24887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="built2go" name="movie_review">
        <vers num="1a" />
        <vers num="2a" />
        <vers num="2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2009" published="2006-04-25" name="CVE-2006-2009" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in agenda.php3 in phpMyAgenda 3.0 Final and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootagenda parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1509" source="VUPEN">ADV-2006-1509</ref>
      <ref url="http://www.securityfocus.com/bid/17670" source="BID">17670</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431862/100/0/threaded" source="BUGTRAQ">20060424 [MajorSecurity] phpMyAgenda 3.0 Final - Remote File Include Vulnerability</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/phpMyAgenda_fi.txt" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/phpMyAgenda_fi.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26062" source="XF">phpmyagenda-rootagenda-file-include(26062)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433995/100/0/threaded" source="BUGTRAQ">20060515 tyree[at]users.sourceforge.net</ref>
      <ref url="http://www.osvdb.org/24943" source="OSVDB">24943</ref>
      <ref url="http://securitytracker.com/id?1015984" source="SECTRACK">1015984</ref>
      <ref url="http://securityreason.com/securityalert/787" source="SREASON">787</ref>
      <ref url="http://secunia.com/advisories/19748" source="SECUNIA">19748</ref>
      <ref url="http://osvdb.org/ref/29/2914x-phpmyagenda.txt" source="MISC">http://osvdb.org/ref/29/2914x-phpmyagenda.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyagenda" name="phpmyagenda">
        <vers num="3.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2010" published="2006-04-25" name="CVE-2006-2010" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in check_login.asp in Bloggage allow remote attackers to execute arbitrary SQL commands via the (1) acc_name and (2) password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1448" source="VUPEN">ADV-2006-1448</ref>
      <ref url="http://secunia.com/advisories/19751" source="SECUNIA" adv="1">19751</ref>
      <ref url="http://colander.altervista.org/advisory/bloggage.txt" source="MISC">http://colander.altervista.org/advisory/bloggage.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25955" source="XF">bloggage-checklogin-sql-injection(25955)</ref>
      <ref url="http://www.securityfocus.com/bid/17639" source="BID">17639</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431673/100/0/threaded" source="BUGTRAQ">20060421 bloggage Remote SQL Injection</ref>
      <ref url="http://www.osvdb.org/24797" source="OSVDB">24797</ref>
      <ref url="http://securityreason.com/securityalert/751" source="SREASON">751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paras_chopra" name="bloggage">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2011" published="2006-04-25" name="CVE-2006-2011" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1449" source="VUPEN">ADV-2006-1449</ref>
      <ref url="http://www.securityfocus.com/bid/17625" source="BID">17625</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431599/100/0/threaded" source="BUGTRAQ">20060420 4images &lt;= 1.7 XSS</ref>
      <ref url="http://secunia.com/advisories/19745" source="SECUNIA" adv="1">19745</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25987" source="XF">4images-member-xss(25987)</ref>
      <ref url="http://www.osvdb.org/24796" source="OSVDB">24796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4homepages" name="4images">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2012" published="2006-04-25" name="CVE-2006-2012" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1479" source="VUPEN">ADV-2006-1479</ref>
      <ref url="http://secunia.com/advisories/19767" source="SECUNIA" adv="1">19767</ref>
      <ref url="http://aluigi.altervista.org/adv/skulltagfs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/skulltagfs-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25988" source="XF">skulltag-version-format-string(25988)</ref>
      <ref url="http://www.securityfocus.com/bid/17659" source="BID">17659</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431872/100/0/threaded" source="BUGTRAQ">20060423 Format string bug in Skulltag 0.96f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skulltag_team" name="skulltag">
        <vers num="0.96d" />
        <vers prev="1" num="0.96f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2013" published="2006-04-25" name="CVE-2006-2013" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in page.php in SL_site 1.0 allows remote attackers to execute arbitrary SQL commands via the id_page parameter. NOTE: this issue could be used to produce resultant XSS from an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1487" source="VUPEN">ADV-2006-1487</ref>
      <ref url="http://securitytracker.com/id?1015972" source="SECTRACK">1015972</ref>
      <ref url="http://secunia.com/advisories/19792" source="SECUNIA" adv="1">19792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26036" source="XF">slsite-page-sql-injection(26036)</ref>
      <ref url="http://www.securityfocus.com/bid/17667" source="BID">17667</ref>
      <ref url="http://www.osvdb.org/24896" source="OSVDB">24896</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-provence" name="sl_site">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2014" published="2006-04-25" name="CVE-2006-2014" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php.  NOTE: this issue could be used to produce resultant XSS from an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1487" source="VUPEN">ADV-2006-1487</ref>
      <ref url="http://securitytracker.com/id?1015972" source="SECTRACK">1015972</ref>
      <ref url="http://secunia.com/advisories/19792" source="SECUNIA" adv="1">19792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26037" source="XF">slsite-gallerie-directory-traversal(26037)</ref>
      <ref url="http://www.securityfocus.com/bid/17672" source="BID">17672</ref>
      <ref url="http://www.securityfocus.com/bid/17667" source="BID">17667</ref>
      <ref url="http://www.osvdb.org/24897" source="OSVDB">24897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-provence" name="sl_site">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2015" published="2006-04-25" name="CVE-2006-2015" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php.  NOTE: other XSS vectors, as reported in the original disclosure, are resultant from other primary vulnerabilities that have separate CVE names.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1487" source="VUPEN">ADV-2006-1487</ref>
      <ref url="http://securitytracker.com/id?1015972" source="SECTRACK">1015972</ref>
      <ref url="http://secunia.com/advisories/19792" source="SECUNIA" adv="1">19792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26038" source="XF">slsite-recherche-xss(26038)</ref>
      <ref url="http://www.securityfocus.com/bid/17667" source="BID">17667</ref>
      <ref url="http://www.osvdb.org/24898" source="OSVDB">24898</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-provence" name="sl_site">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2016" published="2006-04-25" name="CVE-2006-2016" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e) delete_form.php; (2) scope parameter in (f) search.php; and (3) Container DN, (4) Machine Name, and (5) UID Number fields in (g) template_engine.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1450" source="VUPEN">ADV-2006-1450</ref>
      <ref url="http://www.securityfocus.com/bid/17643" source="BID">17643</ref>
      <ref url="http://www.osvdb.org/24794" source="OSVDB">24794</ref>
      <ref url="http://www.osvdb.org/24793" source="OSVDB">24793</ref>
      <ref url="http://www.osvdb.org/24792" source="OSVDB">24792</ref>
      <ref url="http://www.osvdb.org/24790" source="OSVDB">24790</ref>
      <ref url="http://www.osvdb.org/24789" source="OSVDB">24789</ref>
      <ref url="http://www.osvdb.org/24788" source="OSVDB">24788</ref>
      <ref url="http://secunia.com/advisories/19747" source="SECUNIA" adv="1">19747</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25959" source="XF">phpldapadmin-templateengine-xss(25959)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25958" source="XF">phpldapadmin-scope-dn-xss(25958)</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1057" source="DEBIAN">DSA-1057</ref>
      <ref url="http://secunia.com/advisories/20124" source="SECUNIA">20124</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpldapadmin" name="phpldapadmin">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.4a" />
        <vers num="0.9.4b" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.6c" />
        <vers num="0.9.7" />
        <vers num="0.9.7.1" />
        <vers num="0.9.7.2" />
        <vers num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2017" published="2006-04-25" name="CVE-2006-2017" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
version 2.30</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17662" source="BID" patch="1">17662</ref>
      <ref url="http://secunia.com/advisories/19760" source="SECUNIA" patch="1" adv="1">19760</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1494" source="VUPEN">ADV-2006-1494</ref>
      <ref url="http://thekelleys.org.uk/dnsmasq/CHANGELOG" source="CONFIRM">http://thekelleys.org.uk/dnsmasq/CHANGELOG</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26005" source="XF">dnsmasq-dhcp-dos(26005)</ref>
      <ref url="http://www.osvdb.org/24884" source="OSVDB">24884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnsmasq" name="dnsmasq">
        <vers num="2.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2018" published="2006-04-25" name="CVE-2006-2018" modified="2008-09-05" discovered="2006-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter.  NOTE: the affected version has been disputed by the vendor.  It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been disputed by the vendor.  The affected version has been disputed by the vendor via e-mail to CVE.  It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/431901" source="BUGTRAQ">20060423 vbulletin&lt;--3.0.x SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431951/30/5370/threaded" source="BUGTRAQ">20060424 Re: vbulletin&lt;--3.0.x SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.0_beta_2" />
        <vers num="3.0.0_can4" />
        <vers num="3.0.0_rc4" />
        <vers num="3.0.1" />
        <vers num="3.0.12" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2019" published="2006-04-25" name="CVE-2006-2019" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1508" source="VUPEN">ADV-2006-1508</ref>
      <ref url="http://www.securityfocus.com/bid/17674" source="BID">17674</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431944/100/0/threaded" source="BUGTRAQ">20060424 Re: Apple Mac OS X Safari 2.0.3 Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431874/100/0/threaded" source="BUGTRAQ">20060424 Apple Mac OS X Safari 2.0.3 Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015982" source="SECTRACK">1015982</ref>
      <ref url="http://secunia.com/advisories/19763" source="SECUNIA" adv="1">19763</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045472.html" source="FULLDISC">20060424 Apple Mac OS X Safari 2.0.3 Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25998" source="XF">macosx-safari-table-dos(25998)</ref>
      <ref url="http://milw0rm.com/exploits/1715" source="MILW0RM">1715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.3.1" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2020" published="2006-04-25" name="CVE-2006-2020" modified="2011-03-07" discovered="2006-04-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
Littlejohn Consulting, Asterisk Recording Interface, 0.10.00 and higher</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/24805" source="OSVDB" patch="1">24805</ref>
      <ref url="http://secunia.com/advisories/19744" source="SECUNIA" patch="1" adv="1">19744</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1457" source="VUPEN">ADV-2006-1457</ref>
      <ref url="http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2006.1" source="MISC">http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2006.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431655/100/0/threaded" source="BUGTRAQ">20060421 [SecuriWeb 2006.1] directory traversal in Asterisk@Home and ARI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25993" source="XF">asterisk-mail-disclose-information(25993)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asteriskathome" name="asteriskathome">
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2021" published="2006-04-25" name="CVE-2006-2021" modified="2011-03-07" discovered="2006-04-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in recordings/misc/audio.php in the Asterisk Recording Interface (ARI) web interface in Asterisk@Home before 2.8 allows remote attackers to read arbitrary MP3, WAV, and GSM files via a full pathname in the recording parameter.  NOTE: this issue can also be used to determine existence of files.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Asterisk@Home, Asterisk@Home, 2.8
</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17641" source="BID" patch="1">17641</ref>
      <ref url="http://secunia.com/advisories/19744" source="SECUNIA" patch="1" adv="1">19744</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1457" source="VUPEN">ADV-2006-1457</ref>
      <ref url="http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2006.1" source="MISC">http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2006.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431655/100/0/threaded" source="BUGTRAQ">20060421 [SecuriWeb 2006.1] directory traversal in Asterisk@Home and ARI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25996" source="XF">asterisk-audio-directory-traversal(25996)</ref>
      <ref url="http://www.osvdb.org/24806" source="OSVDB">24806</ref>
      <ref url="http://securityreason.com/securityalert/750" source="SREASON">750</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asteriskathome" name="asteriskathome">
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2022" published="2006-04-25" name="CVE-2006-2022" modified="2011-03-07" discovered="2006-04-23" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1491" source="VUPEN">ADV-2006-1491</ref>
      <ref url="http://www.securityfocus.com/bid/17678" source="BID">17678</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431870/100/0/threaded" source="BUGTRAQ" adv="1">20060423 Buffer-overflow and crash in Fenice OMS 1.10</ref>
      <ref url="http://secunia.com/advisories/19770" source="SECUNIA" adv="1">19770</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26078" source="XF">fenice-parseurl-bo(26078)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436256/100/0/threaded" source="BUGTRAQ">20060607 Re: Buffer-overflow and crash in Fenice OMS 1.10</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432002/100/0/threaded" source="BUGTRAQ">20060425 Fenice - Open Media Streaming Server remote BOF exploit</ref>
      <ref url="http://securityreason.com/securityalert/794" source="SREASON">794</ref>
      <ref url="http://aluigi.altervista.org/adv/fenicex-adv.txt" source="MISC">http://aluigi.altervista.org/adv/fenicex-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ls3" name="fenice">
        <vers prev="1" num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2023" published="2006-04-25" name="CVE-2006-2023" modified="2011-03-07" discovered="2006-04-23" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the RTSP_msg_len function in rtsp/RTSP_msg_len.c in Fenice 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a large HTTP Content-Length value, which leads to an invalid memory access.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1491" source="VUPEN">ADV-2006-1491</ref>
      <ref url="http://www.securityfocus.com/bid/17678" source="BID">17678</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431870/100/0/threaded" source="BUGTRAQ" adv="1">20060423 Buffer-overflow and crash in Fenice OMS 1.10</ref>
      <ref url="http://secunia.com/advisories/19770" source="SECUNIA" adv="1">19770</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26080" source="XF">fenice-contentlength-dos(26080)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436256/100/0/threaded" source="BUGTRAQ">20060607 Re: Buffer-overflow and crash in Fenice OMS 1.10</ref>
      <ref url="http://www.osvdb.org/24882" source="OSVDB">24882</ref>
      <ref url="http://securityreason.com/securityalert/794" source="SREASON">794</ref>
      <ref url="http://aluigi.altervista.org/adv/fenicex-adv.txt" source="MISC">http://aluigi.altervista.org/adv/fenicex-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ls3" name="fenice">
        <vers prev="1" num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2024" published="2006-04-25" name="CVE-2006-2024" modified="2011-03-07" discovered="2006-03-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
libTIFF, libTIFF, 3.8.1</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1563" source="VUPEN">ADV-2006-1563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9893" source="OVAL">oval:org.mitre.oval:def:9893</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1102" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=1102</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26133" source="XF">libtiff-tifffetchanyarray-dos(26133)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1" source="UBUNTU">USN-277-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/bid/17730" source="BID">17730</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0425.html" source="REDHAT">RHSA-2006:0425</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082" source="MANDRIVA">MDKSA-2006:082</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml" source="GENTOO">GLSA-200605-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1054" source="DEBIAN">DSA-1054</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1" source="SUNALERT">201332</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1" source="SUNALERT">103099</ref>
      <ref url="http://secunia.com/advisories/20667" source="SECUNIA">20667</ref>
      <ref url="http://secunia.com/advisories/20345" source="SECUNIA">20345</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20023" source="SECUNIA">20023</ref>
      <ref url="http://secunia.com/advisories/20021" source="SECUNIA">20021</ref>
      <ref url="http://secunia.com/advisories/19964" source="SECUNIA">19964</ref>
      <ref url="http://secunia.com/advisories/19949" source="SECUNIA">19949</ref>
      <ref url="http://secunia.com/advisories/19936" source="SECUNIA">19936</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
      <ref url="http://secunia.com/advisories/19851" source="SECUNIA">19851</ref>
      <ref url="http://secunia.com/advisories/19838" source="SECUNIA">19838</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
        <vers prev="1" num="3.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2025" published="2006-04-25" name="CVE-2006-2025" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
libTIFF, libTIFF, 3.8.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1102" source="MISC" patch="1">http://bugzilla.remotesensing.org/show_bug.cgi?id=1102</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1563" source="VUPEN">ADV-2006-1563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10593" source="OVAL">oval:org.mitre.oval:def:10593</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26134" source="XF">libtiff-tifffetchdata-overflow(26134)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1" source="UBUNTU">USN-277-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/bid/17732" source="BID">17732</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0425.html" source="REDHAT">RHSA-2006:0425</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082" source="MANDRIVA">MDKSA-2006:082</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml" source="GENTOO">GLSA-200605-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1054" source="DEBIAN">DSA-1054</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1" source="SUNALERT">201332</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1" source="SUNALERT">103099</ref>
      <ref url="http://secunia.com/advisories/20667" source="SECUNIA">20667</ref>
      <ref url="http://secunia.com/advisories/20345" source="SECUNIA">20345</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/20023" source="SECUNIA">20023</ref>
      <ref url="http://secunia.com/advisories/20021" source="SECUNIA">20021</ref>
      <ref url="http://secunia.com/advisories/19964" source="SECUNIA">19964</ref>
      <ref url="http://secunia.com/advisories/19949" source="SECUNIA">19949</ref>
      <ref url="http://secunia.com/advisories/19936" source="SECUNIA">19936</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA">19897</ref>
      <ref url="http://secunia.com/advisories/19838" source="SECUNIA">19838</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
        <vers prev="1" num="3.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2026" published="2006-04-25" name="CVE-2006-2026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
libTIFF, libTIFF, 3.8.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1102" source="MISC" patch="1">http://bugzilla.remotesensing.org/show_bug.cgi?id=1102</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26135" source="XF">libtiff-tifjpeg-doublefree-memory-corruption(26135)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1563" source="VUPEN">ADV-2006-1563</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1" source="UBUNTU">USN-277-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0024" source="TRUSTIX">2006-0024</ref>
      <ref url="http://www.securityfocus.com/bid/17733" source="BID">17733</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0425.html" source="REDHAT">RHSA-2006:0425</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_28.html" source="SUSE">SUSE-SR:2006:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082" source="MANDRIVA">MDKSA-2006:082</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml" source="GENTOO">GLSA-200605-17</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1054" source="DEBIAN">DSA-1054</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm</ref>
      <ref url="http://secunia.com/advisories/20667" source="SECUNIA" adv="1">20667</ref>
      <ref url="http://secunia.com/advisories/20345" source="SECUNIA" adv="1">20345</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA" adv="1">20210</ref>
      <ref url="http://secunia.com/advisories/20023" source="SECUNIA" adv="1">20023</ref>
      <ref url="http://secunia.com/advisories/20021" source="SECUNIA" adv="1">20021</ref>
      <ref url="http://secunia.com/advisories/19964" source="SECUNIA" adv="1">19964</ref>
      <ref url="http://secunia.com/advisories/19949" source="SECUNIA" adv="1">19949</ref>
      <ref url="http://secunia.com/advisories/19936" source="SECUNIA" adv="1">19936</ref>
      <ref url="http://secunia.com/advisories/19897" source="SECUNIA" adv="1">19897</ref>
      <ref url="http://secunia.com/advisories/19838" source="SECUNIA" adv="1">19838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11389" source="OVAL">oval:org.mitre.oval:def:11389</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1" source="SUNALERT">201332</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1" source="SUNALERT">103099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
        <vers prev="1" num="3.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2027" published="2006-04-25" name="CVE-2006-2027" modified="2008-09-05" discovered="2006-03-26" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long argument, which triggers a buffer overflow when an admin selects the Logging section in the FTP server main window.  NOTE: the original researcher claims that the vendor disputes this issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431920/100/0/threaded" source="BUGTRAQ" adv="1">20060424 Quick 'n Easy FTP Server pro/lite Logging unicode stack overflow</ref>
      <ref url="http://www.securityfocus.com/bid/17681" source="BID">17681</ref>
      <ref url="http://www.osvdb.org/25235" source="OSVDB">25235</ref>
      <ref url="http://securityreason.com/securityalert/788" source="SREASON">788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablo_software_solutions" name="quick_n_easy_ftp_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":lite" />
        <vers num="3.0" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2028" published="2006-04-25" name="CVE-2006-2028" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter.  NOTE: this issue might be resultant from directory traversal.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1493" source="VUPEN">ADV-2006-1493</ref>
      <ref url="http://www.securityfocus.com/bid/17653" source="BID">17653</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431760/100/0/threaded" source="BUGTRAQ">20060421 Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref>
      <ref url="http://www.osvdb.org/24880" source="OSVDB">24880</ref>
      <ref url="http://www.nukedx.com/?getxpl=25" source="MISC">http://www.nukedx.com/?getxpl=25</ref>
      <ref url="http://secunia.com/advisories/19764" source="SECUNIA">19764</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0649.html" source="FULLDISC">20060423 RE: Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25984" source="XF">simplog-imagelist-xss(25984)</ref>
      <ref url="http://securityreason.com/securityalert/799" source="SREASON">799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2029" published="2006-04-25" name="CVE-2006-2029" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1493" source="VUPEN">ADV-2006-1493</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431760/100/0/threaded" source="BUGTRAQ">20060421 Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref>
      <ref url="http://www.osvdb.org/24879" source="OSVDB">24879</ref>
      <ref url="http://www.osvdb.org/24878" source="OSVDB">24878</ref>
      <ref url="http://www.osvdb.org/24877" source="OSVDB">24877</ref>
      <ref url="http://www.nukedx.com/?getxpl=25" source="MISC">http://www.nukedx.com/?getxpl=25</ref>
      <ref url="http://securitytracker.com/id?1015976" source="SECTRACK">1015976</ref>
      <ref url="http://secunia.com/advisories/19764" source="SECUNIA">19764</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0649.html" source="FULLDISC">20060423 RE: Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25982" source="XF">simplog-multiple-sql-injection(25982)</ref>
      <ref url="http://www.simplog.org/archive.php?blogid=1&amp;pid=57" source="CONFIRM">http://www.simplog.org/archive.php?blogid=1&amp;pid=57</ref>
      <ref url="http://securityreason.com/securityalert/799" source="SREASON">799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplog" name="simplog">
        <vers prev="1" num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2030" published="2006-04-25" name="CVE-2006-2030" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Allied Telesyn AT-9724TS switch allows remote attackers to cause a denial of service via a large amount of UDP data to the switch, which leads to unstable operation and possibly failure of the management interface or routing.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431586/100/0/threaded" source="BUGTRAQ">20060419 Allied Telesyn Switch UDP Data Flood Management Denial Of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25938" source="XF">telesyn-udp-dos(25938)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alliedtelesyn" name="at-9724ts">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2031" published="2006-04-25" name="CVE-2006-2031" modified="2008-11-03" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19659" source="SECUNIA">19659</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25954" source="XF">phpmyadmin-index-xss(25954)</ref>
      <ref url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-2" source="CONFIRM">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-2</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/phpmyadmin-xss-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/phpmyadmin-xss-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.8.0.2" />
        <vers num="2.8.0.3" />
        <vers num="2.8.1_dev" />
        <vers num="2.9.0_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2032" published="2006-04-25" name="CVE-2006-2032" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17655" source="BID">17655</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431761/100/0/threaded" source="BUGTRAQ">20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref>
      <ref url="http://www.nukedx.com/?getxpl=24" source="MISC">http://www.nukedx.com/?getxpl=24</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25977" source="XF">corenews-preview-sql-injection(25977)</ref>
      <ref url="http://securityreason.com/securityalert/797" source="SREASON">797</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045372.html" source="FULLDISC">20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corenews" name="corenews">
        <vers prev="1" num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2033" published="2006-04-25" name="CVE-2006-2033" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter.  NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17655" source="BID">17655</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431761/100/0/threaded" source="BUGTRAQ">20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref>
      <ref url="http://www.nukedx.com/?getxpl=24" source="MISC">http://www.nukedx.com/?getxpl=24</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25979" source="XF">corenews-index-file-include(25979)</ref>
      <ref url="http://securityreason.com/securityalert/797" source="SREASON">797</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045372.html" source="FULLDISC">20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corenews" name="corenews">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2034" published="2006-04-25" name="CVE-2006-2034" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17574" source="BID">17574</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431793/100/0/threaded" source="BUGTRAQ">20060421 FlexBB 0.5.5 Exploit [ function/showprofile.php ] Remote SQL Injection</ref>
      <ref url="http://www.osvdb.org/24867" source="OSVDB">24867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexbb" name="flexbb">
        <vers num="0.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2035" published="2006-04-25" name="CVE-2006-2035" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a "/?" sequence to a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431685/100/0/threaded" source="BUGTRAQ">20060421 RE: [BULK] - Websense Filter Bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431600/100/0/threaded" source="BUGTRAQ">20060420 Websense Filter Bypass</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25980" source="XF">websense-uncategorized-filter-bypass(25980)</ref>
      <ref url="http://www.osvdb.org/25211" source="OSVDB">25211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="websense" name="websense">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2036" published="2006-04-25" name="CVE-2006-2036" modified="2008-09-05" discovered="2006-04-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17656" source="BID">17656</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431904/100/0/threaded" source="BUGTRAQ">20060422 ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26266" source="XF">iopus-insecure-passwords(26266)</ref>
      <ref url="http://www.securityfocus.com/archive/1/431989/100/0/threaded" source="BUGTRAQ">20060425 Re: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS</ref>
      <ref url="http://securitytracker.com/id?1015980" source="SECTRACK">1015980</ref>
      <ref url="http://secunia.com/advisories/19771" source="SECUNIA">19771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iopus" name="secure_email_attachments">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2037" published="2006-04-26" name="CVE-2006-2037" modified="2008-09-05" discovered="2006-04-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17627" source="BID">17627</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431509/100/0/threaded" source="BUGTRAQ">20060420 ThWboard 3 Beta 2.84 Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25953" source="XF">thwboard-index-xss(25953)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thwboard" name="thwboard">
        <vers num="3.0_beta_2.84" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2038" published="2006-04-26" name="CVE-2006-2038" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ampleShop 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) RecordID parameter in (a) Customeraddresses_RecordAction.cfm and (b) youraccount.cfm; (2) solus parameter in (c) detail.cfm; and (3) cat parameter in (d) category.cfm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1512" source="VUPEN">ADV-2006-1512</ref>
      <ref url="http://secunia.com/advisories/19806" source="SECUNIA" adv="1">19806</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26064" source="XF">ampleshop-multiple-sql-injection(26064)</ref>
      <ref url="http://www.osvdb.org/24937" source="OSVDB">24937</ref>
      <ref url="http://www.osvdb.org/24936" source="OSVDB">24936</ref>
      <ref url="http://www.osvdb.org/24935" source="OSVDB">24935</ref>
      <ref url="http://www.osvdb.org/24934" source="OSVDB">24934</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/ampleshop-ecommerce-software-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/ampleshop-ecommerce-software-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amplecom" name="ampleshop">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2039" published="2006-04-26" name="CVE-2006-2039" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17676" source="BID" patch="1">17676</ref>
      <ref url="http://secunia.com/advisories/19776" source="SECUNIA" patch="1" adv="1">19776</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1492" source="VUPEN">ADV-2006-1492</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=411859" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=411859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26040" source="XF">helpcenterlive-osticket-sql-injection(26040)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubertec" name="help_center_live">
        <vers num="1.0" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2040" published="2006-04-26" name="CVE-2006-2040" modified="2011-03-07" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1525" source="VUPEN">ADV-2006-1525</ref>
      <ref url="http://www.securityfocus.com/bid/17683" source="BID">17683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431982/100/0/threaded" source="BUGTRAQ">20060425 photokorn 1.53 , 1.542 &lt;&lt; Sql</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26066" source="XF">photokorn-multiple-sql-injection(26066)</ref>
      <ref url="http://www.osvdb.org/24983" source="OSVDB">24983</ref>
      <ref url="http://www.osvdb.org/24982" source="OSVDB">24982</ref>
      <ref url="http://www.osvdb.org/24981" source="OSVDB">24981</ref>
      <ref url="http://securityreason.com/securityalert/789" source="SREASON">789</ref>
      <ref url="http://secunia.com/advisories/19836" source="SECUNIA">19836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photokorn" name="photokorn">
        <vers num="1.53" />
        <vers num="1.542" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2041" published="2006-04-26" name="CVE-2006-2041" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19801" source="SECUNIA" patch="1" adv="1">19801</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1515" source="VUPEN">ADV-2006-1515</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26079" source="XF">phpwebgallery-picture-bypass-security(26079)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebgallery" name="phpwebgallery">
        <vers num="1.0" />
        <vers num="1.4.1" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2042" published="2006-05-09" name="CVE-2006-2042" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects all versions of Adobe, Dreamweaver, 8.0 before 8.0.2
This vulnerability is addressed in the following product releases:
Adobe, Dreamweaver, 8.0.2
Code update for Macromedia, Dreamweaver MX, 2004</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb06-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb06-07.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1753" source="VUPEN">ADV-2006-1753</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26339" source="XF">dreamweaver-server-sql-injection(26339)</ref>
      <ref url="http://www.securityfocus.com/bid/17928" source="BID">17928</ref>
      <ref url="http://www.osvdb.org/25361" source="OSVDB">25361</ref>
      <ref url="http://securitytracker.com/id?1016050" source="SECTRACK">1016050</ref>
      <ref url="http://secunia.com/advisories/20054" source="SECUNIA">20054</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0194.html" source="BUGTRAQ">20060509 Multiple SQL Injection Vulnerabilities in Dreamweaver Generated Code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="dreamweaver">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2043" published="2006-04-26" name="CVE-2006-2043" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1540" source="VUPEN">ADV-2006-1540</ref>
      <ref url="http://www.securityfocus.com/bid/17698" source="BID">17698</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded" source="BUGTRAQ">20060424 Multiple vulnerabilities in IP3 Networks 'NetAccess' NA75 appliance</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26108" source="XF">ip3-na75-backtick-command-injection(26108)</ref>
      <ref url="http://securityreason.com/securityalert/793" source="SREASON">793</ref>
      <ref url="http://secunia.com/advisories/19818" source="SECUNIA">19818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ip3_networks" name="ip3_netaccess_75">
        <vers num="4.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2044" published="2006-04-26" name="CVE-2006-2044" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has a default username of admin and a default password of admin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1540" source="VUPEN">ADV-2006-1540</ref>
      <ref url="http://www.securityfocus.com/bid/17698" source="BID">17698</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded" source="BUGTRAQ">20060424 Multiple vulnerabilities in IP3 Networks 'NetAccess' NA75 appliance</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26112" source="XF">ip3-na75-default-account(26112)</ref>
      <ref url="http://securityreason.com/securityalert/793" source="SREASON">793</ref>
      <ref url="http://secunia.com/advisories/19818" source="SECUNIA">19818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ip3_networks" name="ip3_netaccess_75">
        <vers num="4.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-2045" published="2006-04-26" name="CVE-2006-2045" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The (1) shadow password file in na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has world readable permissions, which allows local users to view encrypted passwords; and the (2) NetAccess database file has world readable and writable permissions, which allows local users to view sensitive information and modify data.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1540" source="VUPEN">ADV-2006-1540</ref>
      <ref url="http://www.securityfocus.com/bid/17698" source="BID">17698</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded" source="BUGTRAQ">20060424 Multiple vulnerabilities in IP3 Networks 'NetAccess' NA75 appliance</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26110" source="XF">ip3-na75-database-file-permission(26110)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26109" source="XF">ip3-na75-shadow-file-permission(26109)</ref>
      <ref url="http://secunia.com/advisories/19818" source="SECUNIA">19818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ip3_networks" name="ip3_netaccess_75">
        <vers num="4.0.34_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2046" published="2006-04-26" name="CVE-2006-2046" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1513" source="VUPEN">ADV-2006-1513</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26060" source="XF">cartweaver-multiple-sql-injection(26060)</ref>
      <ref url="http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes" source="CONFIRM">http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes</ref>
      <ref url="http://www.securityfocus.com/bid/25210" source="BID">25210</ref>
      <ref url="http://www.securityfocus.com/bid/17941" source="BID">17941</ref>
      <ref url="http://www.osvdb.org/24962" source="OSVDB">24962</ref>
      <ref url="http://www.osvdb.org/24961" source="OSVDB">24961</ref>
      <ref url="http://www.milw0rm.com/exploits/4264" source="MILW0RM">4264</ref>
      <ref url="http://secunia.com/advisories/19812" source="SECUNIA">19812</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="application_dynamics" name="cartweaver_coldfusion">
        <vers prev="1" num="2.16.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2047" published="2006-04-26" name="CVE-2006-2047" modified="2011-03-07" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) category, or (4) keywords parameter in (a) Results.cfm; or an invalid (5) ProdID parameter in (b) Details.cfm; which reveal the path in various error messages. NOTE: the behavior for the category, keywords, and ProdID parameters might be resultant from SQL injection.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1513" source="VUPEN">ADV-2006-1513</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26061" source="XF">cartweaver-multiple-path-disclosure(26061)</ref>
      <ref url="http://www.osvdb.org/24964" source="OSVDB">24964</ref>
      <ref url="http://www.osvdb.org/24963" source="OSVDB">24963</ref>
      <ref url="http://secunia.com/advisories/19812" source="SECUNIA">19812</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="application_dynamics" name="cartweaver_coldfusion">
        <vers num="2.16.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2048" published="2006-04-26" name="CVE-2006-2048" modified="2011-03-07" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) port, (2) server, and (3) user parameters.  NOTE: it is possible that the affected version is actually 3.2.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1530" source="VUPEN">ADV-2006-1530</ref>
      <ref url="http://www.subjectzero.net/research/phpwebftpxss.htm" source="MISC">http://www.subjectzero.net/research/phpwebftpxss.htm</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431985/100/0/threaded" source="BUGTRAQ">20060425 PhpWebFtp Cross Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26067" source="XF">phpwebftp-index-xss(26067)</ref>
      <ref url="http://www.securityfocus.com/bid/17688" source="BID">17688</ref>
      <ref url="http://www.osvdb.org/24975" source="OSVDB">24975</ref>
      <ref url="http://securityreason.com/securityalert/786" source="SREASON">786</ref>
      <ref url="http://secunia.com/advisories/19827" source="SECUNIA">19827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebftp" name="phpwebftp">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2049" published="2006-04-26" name="CVE-2006-2049" modified="2011-03-07" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script or HTML via the az parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1532" source="VUPEN">ADV-2006-1532</ref>
      <ref url="http://www.securityfocus.com/bid/17697" source="BID">17697</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432010/100/0/threaded" source="BUGTRAQ">20060425 DCForumLite V 3.0&lt;--XSS/SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26083" source="XF">dcforumlite-dcboard-xss(26083)</ref>
      <ref url="http://www.osvdb.org/24988" source="OSVDB">24988</ref>
      <ref url="http://securityreason.com/securityalert/792" source="SREASON">792</ref>
      <ref url="http://secunia.com/advisories/19815" source="SECUNIA">19815</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcscripts" name="dcforumlite">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2050" published="2006-04-26" name="CVE-2006-2050" modified="2008-09-05" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17697" source="BID">17697</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432010/100/0/threaded" source="BUGTRAQ">20060425 DCForumLite V 3.0&lt;--XSS/SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26084" source="XF">deforumlite-dcboard-sql-injection(26084)</ref>
      <ref url="http://www.osvdb.org/24989" source="OSVDB">24989</ref>
      <ref url="http://securityreason.com/securityalert/792" source="SREASON">792</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcscripts" name="dcforumlite">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2051" published="2006-04-26" name="CVE-2006-2051" modified="2008-09-05" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431983/100/0/threaded" source="BUGTRAQ">20060425 NextAge Shopping Cart Software XSS</ref>
      <ref url="http://www.aria-security.net/advisory/nextage/nextageshoppingcart.txt" source="MISC" adv="1">http://www.aria-security.net/advisory/nextage/nextageshoppingcart.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26065" source="XF">nextageshoppingcart-index-xss(26065)</ref>
      <ref url="http://www.securityfocus.com/bid/17685" source="BID">17685</ref>
      <ref url="http://securityreason.com/securityalert/791" source="SREASON">791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nextage" name="nextage_shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2052" published="2006-04-26" name="CVE-2006-2052" modified="2008-09-05" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17696" source="BID">17696</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432241/100/0/threaded" source="BUGTRAQ">20060427 Re: Instant Photo Gallery &lt;= Multiple XSS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432022/100/0/threaded" source="BUGTRAQ">20060425 Instant Photo Gallery &lt;= Multiple XSS</ref>
      <ref url="http://www.osvdb.org/24984" source="OSVDB">24984</ref>
      <ref url="http://securityreason.com/securityalert/790" source="SREASON">790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verosky_media" name="instant_photo_gallery">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2053" published="2006-04-26" name="CVE-2006-2053" modified="2011-03-07" discovered="2006-04-25" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in QuickEStore 7.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the OrderID parameter in (a) shipping.cfm and (b) checkout.cfm, (2) ItemID parameter in (c) proddetail.cfm, (3) SubCatID parameter in (d) index.cfm, the (4) CategoryID parameter in (e) prodpage.cfm, and (5) ProdID parameter in (f) Details.cfm.  NOTE: these issues can also be exploited for path disclosure.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1514" source="VUPEN">ADV-2006-1514</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26045" source="XF">quickestore-multiple-sql-injection(26045)</ref>
      <ref url="http://www.osvdb.org/24980" source="OSVDB">24980</ref>
      <ref url="http://www.osvdb.org/24979" source="OSVDB">24979</ref>
      <ref url="http://www.osvdb.org/24978" source="OSVDB">24978</ref>
      <ref url="http://www.osvdb.org/24977" source="OSVDB">24977</ref>
      <ref url="http://www.osvdb.org/24976" source="OSVDB">24976</ref>
      <ref url="http://secunia.com/advisories/19817" source="SECUNIA">19817</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/quickestore-79-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/quickestore-79-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quickestore" name="quickestore">
        <vers num="7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2054" published="2006-04-26" name="CVE-2006-2054" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">3Com Baseline Switch 2848-SFP Plus Model #3C16486 with firmware before 1.0.2.0 allows remote attackers to cause a denial of service (unstable operation) via long DHCP packets.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to firmware version 1.0.2.0.
http://www.3com.com/products/en_...e&amp;order=desc&amp;prodcat=all</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1510" source="VUPEN">ADV-2006-1510</ref>
      <ref url="http://www.securityfocus.com/bid/17686" source="BID">17686</ref>
      <ref url="http://support.3com.com/infodeli/tools/switches/baseline/3C16486_V1_0_2_0_readme.pdf" source="CONFIRM">http://support.3com.com/infodeli/tools/switches/baseline/3C16486_V1_0_2_0_readme.pdf</ref>
      <ref url="http://secunia.com/advisories/19756" source="SECUNIA" adv="1">19756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26076" source="XF">3com-baseline-dhcp-dos(26076)</ref>
      <ref url="http://www.osvdb.org/24942" source="OSVDB">24942</ref>
      <ref url="http://securitytracker.com/id?1015997" source="SECTRACK">1015997</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3c16486">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2055" published="2006-04-26" name="CVE-2006-2055" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/26118" source="XF">office-mailto-obtain-information(26118)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1538" source="VUPEN">ADV-2006-1538</ref>
      <ref url="http://www.osvdb.org/25003" source="OSVDB">25003</ref>
      <ref url="http://secunia.com/advisories/19819" source="SECUNIA">19819</ref>
      <ref url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html" source="MISC">http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2056" published="2006-04-26" name="CVE-2006-2056" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1538" source="VUPEN">ADV-2006-1538</ref>
      <ref url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html" source="MISC">http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26118" source="XF">office-mailto-obtain-information(26118)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_xp_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2057" published="2006-04-26" name="CVE-2006-2057" modified="2011-03-07" discovered="2006-04-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1538" source="VUPEN">ADV-2006-1538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432009/100/0/threaded" source="BUGTRAQ">20060424 Multiple browsers Windows mailto protocol Office 2003 file attachment exploit</ref>
      <ref url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html" source="MISC">http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26118" source="XF">office-mailto-obtain-information(26118)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avant_force" name="avant_browser">
        <vers num="10.1_build_17" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" edition="sp1" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2058" published="2006-04-26" name="CVE-2006-2058" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1538" source="VUPEN">ADV-2006-1538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432009/100/0/threaded" source="BUGTRAQ">20060424 Multiple browsers Windows mailto protocol Office 2003 file attachment exploit</ref>
      <ref url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html" source="MISC">http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26118" source="XF">office-mailto-obtain-information(26118)</ref>
      <ref url="http://securityreason.com/securityalert/785" source="SREASON">785</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avant_force" name="avant_browser">
        <vers num="10.1_build_17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2059" published="2006-04-26" name="CVE-2006-2059" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=213374" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=213374</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1534" source="VUPEN">ADV-2006-1534</ref>
      <ref url="http://www.securityfocus.com/bid/17695" source="BID">17695</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431990/100/0/threaded" source="BUGTRAQ">20060425 Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26070" source="XF">invision-search-file-include(26070)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439607/100/0/threaded" source="BUGTRAQ">20060710 Re: RE: Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432451/100/0/threaded" source="BUGTRAQ">20060427 Invision Power Board 2.1.5 POC</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432226/100/0/threaded" source="BUGTRAQ">20060427 Re: Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://www.osvdb.org/25005" source="OSVDB">25005</ref>
      <ref url="http://securityreason.com/securityalert/796" source="SREASON">796</ref>
      <ref url="http://secunia.com/advisories/19830" source="SECUNIA">19830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.1.5_2006-03-08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2060" published="2006-04-26" name="CVE-2006-2060" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to erase the initial static portion of a filename.</descript>
    </desc>
    <sols>
      <sol source="nvd">If you've downloaded IPB 2.1.5 since the time of this post, there is no need to update your installation as the main download has been updated.</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=213374" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=213374</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1534" source="VUPEN">ADV-2006-1534</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431990/100/0/threaded" source="BUGTRAQ">20060425 Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26072" source="XF">invision-admin-file-include(26072)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439607/100/0/threaded" source="BUGTRAQ">20060710 Re: RE: Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432226/100/0/threaded" source="BUGTRAQ">20060427 Re: Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://www.osvdb.org/25008" source="OSVDB">25008</ref>
      <ref url="http://securityreason.com/securityalert/796" source="SREASON">796</ref>
      <ref url="http://secunia.com/advisories/19830" source="SECUNIA">19830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.x" />
        <vers num="2.1.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2061" published="2006-04-26" name="CVE-2006-2061" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has released an update to address this and other versions.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17690" source="BID" patch="1">17690</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1534" source="VUPEN">ADV-2006-1534</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431990/100/0/threaded" source="BUGTRAQ">20060425 Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=213374" source="CONFIRM">http://forums.invisionpower.com/index.php?showtopic=213374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26071" source="XF">invision-index-ck-sql-injection(26071)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432226/100/0/threaded" source="BUGTRAQ">20060427 Re: Invision Vulnerabilities, including remote code execution</ref>
      <ref url="http://securityreason.com/securityalert/796" source="SREASON">796</ref>
      <ref url="http://secunia.com/advisories/19830" source="SECUNIA">19830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0_alpha_3" />
        <vers num="2.0_pdr3" />
        <vers num="2.0_pf1" />
        <vers num="2.0_pf2" />
        <vers num="2.1" />
        <vers num="2.1.5" />
        <vers num="2.1_alpha2" />
      </prod>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.1.5_2006-03-08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2062" published="2006-04-26" name="CVE-2006-2062" modified="2008-11-03" discovered="2006-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version "Full Version", allow remote attackers to execute arbitrary SQL commands via the (1) banner parameter in agent_links.pl; the offset parameter in (2) agent_links.pl, (3) agent_transactions.pl, (4) agent_subaffiliates.pl, and (5) agent_summary.pl; the camp_id parameter in (6) agent_transactions_csv.pl, (7) agent_subaffiliates.pl, and (8) agent_camp_det.pl; the (9) login parameter in agent_commission_statement.pl; the logged parameter in (10) agent_commission_statement.pl and (11) agent_camp_det.pl; the (12) agent_id parameter in agent_commission_statement.pl; and the (13) sub parameter in unspecified files.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/25029" source="OSVDB">25029</ref>
      <ref url="http://www.osvdb.org/25028" source="OSVDB">25028</ref>
      <ref url="http://www.osvdb.org/25027" source="OSVDB">25027</ref>
      <ref url="http://www.osvdb.org/25026" source="OSVDB">25026</ref>
      <ref url="http://www.osvdb.org/25025" source="OSVDB">25025</ref>
      <ref url="http://www.osvdb.org/25024" source="OSVDB">25024</ref>
      <ref url="http://www.osvdb.org/25023" source="OSVDB">25023</ref>
      <ref url="http://secunia.com/advisories/19867" source="SECUNIA" adv="1">19867</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/leadhound-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/leadhound-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leadhound_network" name="leadhound_full">
        <vers num="2.1" />
        <vers num="2.1_network_version" />
      </prod>
      <prod vendor="leadhound_network" name="leadhound_lite">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2063" published="2006-04-26" name="CVE-2006-2063" modified="2008-11-03" discovered="2006-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version "Full Version", allow remote attackers to inject arbitrary web script or HTML via the login parameter in (1) agent_affil.pl, (2) agent_help.pl, (3) agent_faq.pl, (4) agent_help_insert.pl, (5) sign_out.pl, (6) members.pl, (7) modify_agent_1.pl, (8) modify_agent_2.pl, (9) modify_agent.pl, (10) agent_links.pl, (11) agent_stats_pending_leads.pl, (12) agent_logoff.pl, (13) agent_rev_det.pl, (14) agent_subaffiliates.pl, (15) agent_stats_pending_leads.pl, (16) agent_transactions.pl, (17) agent_payment_history.pl, (18) agent_summary.pl, (19) agent_camp_all.pl, (20) agent_camp_new.pl, (21) agent_camp_notsub.pl, (22) agent_campaign.pl, (23) agent_camp_expired.pl, (24) agent_stats_det.pl, (25) agent_stats.pl, (26) agent_camp_det.pl, (27) agent_camp_sub.pl, (28) agent_affil_list.pl, and (29) agent_affil_code.pl; the logged parameter in (30) agent_faq.pl, (31) agent_help_insert.pl, (32) members.pl, (33) modify_agent_1.pl, (34) modify_agent_2.pl, (35) modify_agent.pl, (36) agent_links.pl, (37) agent_subaffiliates.pl, (38) agent_stats_pending_leads.pl, (39) agent_transactions.pl, (40) agent_summary.pl, (41) agent_camp_all.pl, (42) agent_camp_new.pl, (43) agent_camp_notsub.pl, (44) agent_campaign.pl, (45) agent_camp_expired.pl, (46) agent_stats.pl, (47) agent_camp_det.pl, (48) agent_camp_sub.pl, (49) agent_affil_list.pl, and (50) agent_affil_code.pl; the camp_id parameter in (51) agent_links.pl, (52) agent_subaffiliates.pl, and (53) agent_camp_det.pl; the (54) banner parameter in agent_links.pl; the offset parameter in (55) agent_links.pl, (56) agent_subaffiliates.pl, (57) agent_transactions.pl, and (58) agent_summary.pl; the date parameter in (59) agent_subaffiliates.pl, (60) agent_transactions.pl, and (61) agent_summary.pl; the dates parameter in (62) agent_rev_det.pl and (63) agent_stats_det.pl; the (64) page parameter in agent_camp_det.pl; the (65) agent_id parameter in agent_commission_statement.pl; and the (66) lost password field in lost_pwd.pl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/25060" source="OSVDB">25060</ref>
      <ref url="http://www.osvdb.org/25059" source="OSVDB">25059</ref>
      <ref url="http://www.osvdb.org/25058" source="OSVDB">25058</ref>
      <ref url="http://www.osvdb.org/25057" source="OSVDB">25057</ref>
      <ref url="http://www.osvdb.org/25056" source="OSVDB">25056</ref>
      <ref url="http://www.osvdb.org/25055" source="OSVDB">25055</ref>
      <ref url="http://www.osvdb.org/25054" source="OSVDB">25054</ref>
      <ref url="http://www.osvdb.org/25053" source="OSVDB">25053</ref>
      <ref url="http://www.osvdb.org/25052" source="OSVDB">25052</ref>
      <ref url="http://www.osvdb.org/25051" source="OSVDB">25051</ref>
      <ref url="http://www.osvdb.org/25050" source="OSVDB">25050</ref>
      <ref url="http://www.osvdb.org/25049" source="OSVDB">25049</ref>
      <ref url="http://www.osvdb.org/25048" source="OSVDB">25048</ref>
      <ref url="http://www.osvdb.org/25047" source="OSVDB">25047</ref>
      <ref url="http://www.osvdb.org/25046" source="OSVDB">25046</ref>
      <ref url="http://www.osvdb.org/25045" source="OSVDB">25045</ref>
      <ref url="http://www.osvdb.org/25044" source="OSVDB">25044</ref>
      <ref url="http://www.osvdb.org/25043" source="OSVDB">25043</ref>
      <ref url="http://www.osvdb.org/25042" source="OSVDB">25042</ref>
      <ref url="http://www.osvdb.org/25041" source="OSVDB">25041</ref>
      <ref url="http://www.osvdb.org/25039" source="OSVDB">25039</ref>
      <ref url="http://www.osvdb.org/25038" source="OSVDB">25038</ref>
      <ref url="http://www.osvdb.org/25037" source="OSVDB">25037</ref>
      <ref url="http://www.osvdb.org/25036" source="OSVDB">25036</ref>
      <ref url="http://www.osvdb.org/25035" source="OSVDB">25035</ref>
      <ref url="http://www.osvdb.org/25034" source="OSVDB">25034</ref>
      <ref url="http://www.osvdb.org/25033" source="OSVDB">25033</ref>
      <ref url="http://www.osvdb.org/25032" source="OSVDB">25032</ref>
      <ref url="http://www.osvdb.org/25031" source="OSVDB">25031</ref>
      <ref url="http://www.osvdb.org/25030" source="OSVDB">25030</ref>
      <ref url="http://secunia.com/advisories/19867" source="SECUNIA" adv="1">19867</ref>
      <ref url="http://pridels0.blogspot.com/2006/04/leadhound-multiple-vuln.html" source="MISC">http://pridels0.blogspot.com/2006/04/leadhound-multiple-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leadhound_network" name="leadhound_full">
        <vers num="2.1" />
        <vers num="2.1_network_version" />
      </prod>
      <prod vendor="leadhound_network" name="leadhound_lite">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2064" published="2006-04-27" name="CVE-2006-2064" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain privileges or cause a denial of service (application failure) via unknown attack vectors that involve the getpwnam family of non-reentrant functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17687" source="BID" patch="1">17687</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102316-1" source="SUNALERT" patch="1">102316</ref>
      <ref url="http://securitytracker.com/id?1015987" source="SECTRACK" patch="1">1015987</ref>
      <ref url="http://secunia.com/advisories/19789" source="SECUNIA" patch="1" adv="1">19789</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1504" source="VUPEN">ADV-2006-1504</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26075" source="XF">solaris-libpkcs11-privilege-escalation(26075)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="10.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2065" published="2006-04-27" name="CVE-2006-2065" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie.  NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19761" source="SECUNIA" patch="1" adv="1">19761</ref>
      <ref url="http://securitytracker.com/id?1015970" source="SECTRACK">1015970</ref>
      <ref url="http://retrogod.altervista.org/phpsurveyor_0995_xpl.html" source="MISC">http://retrogod.altervista.org/phpsurveyor_0995_xpl.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25970" source="XF">phpsurveyor-surveyid-shell-execution(25970)</ref>
      <ref url="http://www.securityfocus.com/bid/17633" source="BID">17633</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431508/100/0/threaded" source="BUGTRAQ">20060420 PHPSurveyor &lt;= 0.995 'save.php/surveyid' remote cmmnds xctn</ref>
      <ref url="http://www.osvdb.org/24787" source="OSVDB">24787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsurveyor" name="phpsurveyor">
        <vers num="0.96_beta" />
        <vers num="0.97_beta" />
        <vers num="0.98_beta" />
        <vers num="0.98_stable" />
        <vers num="0.99" />
        <vers num="0.991" />
        <vers num="0.992" />
        <vers num="0.993" />
        <vers num="0.995" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2066" published="2006-04-27" name="CVE-2006-2066" modified="2011-09-13" discovered="2006-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1485" source="VUPEN" adv="1">ADV-2006-1485</ref>
      <ref url="http://www.securityfocus.com/bid/20232" source="BID">20232</ref>
      <ref url="http://www.securityfocus.com/bid/17651" source="BID">17651</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447303/100/0/threaded" source="BUGTRAQ">20060928 Re: xxs in MKPortal M1.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447195/100/0/threaded" source="BUGTRAQ">20060927 MkPortal Cross Site Scripting (All versions) xSS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431759/100/0/threaded" source="BUGTRAQ" adv="1">20060421 vBulletin &lt;= 3.5.4 with MKPortal 1.1 Remote SQL Injection Vulnerability.</ref>
      <ref url="http://www.osvdb.org/24901" source="OSVDB">24901</ref>
      <ref url="http://www.nukedx.com/?viewdoc=26" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=26</ref>
      <ref url="http://securitytracker.com/id?1015977" source="SECTRACK">1015977</ref>
      <ref url="http://securityreason.com/securityalert/801" source="SREASON">801</ref>
      <ref url="http://secunia.com/advisories/19786" source="SECUNIA" adv="1">19786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num="1.1_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-2067" published="2006-04-27" name="CVE-2006-2067" modified="2008-09-05" discovered="2006-04-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the userid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431759/100/0/threaded" source="BUGTRAQ" adv="1">20060421 vBulletin &lt;= 3.5.4 with MKPortal 1.1 Remote SQL Injection Vulnerability.</ref>
      <ref url="http://www.nukedx.com/?viewdoc=26" source="MISC" adv="1">http://www.nukedx.com/?viewdoc=26</ref>
      <ref url="http://securitytracker.com/id?1015977" source="SECTRACK">1015977</ref>
      <ref url="http://www.securityfocus.com/bid/17651" source="BID">17651</ref>
      <ref url="http://securityreason.com/securityalert/801" source="SREASON">801</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2068" published="2006-04-27" name="CVE-2006-2068" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-007_e/index-e.html" source="CONFIRM" patch="1">http://www.hitachi-support.com/security_e/vuls_e/HS06-007_e/index-e.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1524" source="VUPEN">ADV-2006-1524</ref>
      <ref url="http://secunia.com/advisories/19841" source="SECUNIA" adv="1">19841</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26087" source="XF">hitachi-jp1-request-dos(26087)</ref>
      <ref url="http://www.securityfocus.com/bid/17706" source="BID">17706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="jp1-cm2-network_node_manager">
        <vers prev="1" num="05_20" edition="" />
        <vers prev="1" num="05_20" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="jp1-cm2-network_node_manager_250">
        <vers num="05_20" />
        <vers num="06_00" />
      </prod>
      <prod vendor="hitachi" name="jpi_automatic_job_management_system_2">
        <vers num="" edition=":agent" />
      </prod>
      <prod vendor="hitachi" name="jpi_performance_management">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="jpi_pfm_snmp_system_observer">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="jpi_security_integrated_manager">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="jpi_server_conductor_blade_server_manager">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="jpi_server_conductor_server_manager">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="jpi_server_system_observer_-_report_feature">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-2069" published="2006-04-27" name="CVE-2006-2069" modified="2011-06-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <ex
