<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2010-02-09" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry reject="1" name="CVE-2006-0018" seq="2006-0018" type="CVE" published="2005-11-29" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0064" seq="2006-0064" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0016" adv="1">ADV-2006-0016</ref>
            <ref source="MILW0RM" url="http://milw0rm.com/exploits/1398">1398</ref>
        </refs>
        <vuln_soft>
            <prod vendor="devellion" name="cubecart">
                <vers num="3.0.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0065" seq="2006-0065" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded" adv="1">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0003" adv="1">ADV-2006-0003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18273" adv="1">18273</ref>
            <ref source="MISC" url="http://evuln.com/vulns/1/summary.html" adv="1">http://evuln.com/vulns/1/summary.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16107">16107</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22140">22140</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/315">315</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vego" name="vego_web_forum">
                <vers num="1.26" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0066" seq="2006-0066" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16111">16111</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded" adv="1">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22149">22149</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0006" adv="1">ADV-2006-0006</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18265" adv="1">18265</ref>
            <ref source="MISC" url="http://evuln.com/vulns/9/summary.html" adv="1">http://evuln.com/vulns/9/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpjournaler" name="phpjournaler">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0067" seq="2006-0067" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0004" adv="1">ADV-2006-0004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18272" adv="1">18272</ref>
            <ref source="MISC" url="http://evuln.com/vulns/2/summary.html" adv="1">http://evuln.com/vulns/2/summary.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16108">16108</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22139">22139</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vego" name="vego_links_builder">
                <vers num="2.00" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0068" seq="2006-0068" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-20">
        <desc>
            <descript source="cve">SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0008" adv="1">ADV-2006-0008</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18264" adv="1">18264</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16125">16125</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22147">22147</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22146">22146</ref>
            <ref source="MISC" url="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html">http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="primo_place" name="primo_cart">
                <vers num="1.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0069" seq="2006-0069" severity="Medium" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/19087">19087</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16112">16112</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded" adv="1">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18270">18270</ref>
            <ref source="MISC" url="http://evuln.com/vulns/4/summary.html" adv="1">http://evuln.com/vulns/4/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="chipmunk_scripts" name="chipmunk_guestbook">
                <vers num="1.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0070" seq="2006-0070" severity="Medium" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded">20060103 Re: Drupal all versiyon xss cehennem.org</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/420671/100/0/threaded" adv="1">20060102 Drupal all versiyon xss cehennem.org</ref>
        </refs>
        <vuln_soft>
            <prod vendor="drupal" name="drupal">
                <vers num="4.5.6" />
                <vers num="4.6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" name="CVE-2006-0071" seq="2006-0071" severity="Medium" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="6.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16120">16120</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml" adv="1">GLSA-200601-01</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22211">22211</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18284">18284</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gentoo" name="app-crypt_pinentry">
                <vers edition="r1" num="0.7.2" />
            </prod>
            <prod vendor="gentoo" name="linux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0072" seq="2006-0072" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16122">16122</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/420677">20060102 SCO Openserver 5.0.x exploit</ref>
            <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c">http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.0.6" />
                <vers num="5.0.6a" />
                <vers num="5.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0073" seq="2006-0073" severity="Medium" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16119">16119</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22153">22153</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18283" adv="1">18283</ref>
        </refs>
        <vuln_soft>
            <prod vendor="discusware" name="discus_freeware">
                <vers num="3.10.5" />
            </prod>
            <prod vendor="discusware" name="discus_professional">
                <vers num="3.10.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0074" seq="2006-0074" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0" CVSS_score="7.5" modified="2009-06-02">
        <desc>
            <descript source="cve">SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.  NOTE: it was later reported that 1.1 and earlier are affected.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16109">16109</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22150">22150</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/8706">8706</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0005" adv="1">ADV-2006-0005</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18269" adv="1">18269</ref>
            <ref source="MISC" url="http://evuln.com/vulns/5/summary.html">http://evuln.com/vulns/5/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jevontech" name="phpenpals">
                <vers num="310704" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0075" seq="2006-0075" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16106" adv="1">16106</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded">20060101 [eVuln] phpBook PHP Code Execution</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0002" adv="1">ADV-2006-0002</ref>
            <ref source="MISC" patch="1" url="http://evuln.com/vulns/6/summary.html">http://evuln.com/vulns/6/summary.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18268" adv="1">18268</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnu" name="phpbook">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="1.2" />
                <vers num="1.3" />
                <vers num="1.3.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0076" seq="2006-0076" severity="High" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16105">16105</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded">20060531 Re: OaBoard 1.0 Remote File inclusion</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded">20060530 OaBoard 1.0 Remote File inclusion</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded" adv="1">20060101 [eVuln] oaBoard PHP Code Execution</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1016211">1016211</ref>
            <ref source="MISC" url="http://evuln.com/vulns/3/summary.html">http://evuln.com/vulns/3/summary.html</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2006-0077" seq="2006-0077" severity="Low" type="CVE" published="2006-01-03" CVSS_version="2.0 upgrade from v1.0" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16118">16118</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0013" adv="1">ADV-2006-0013</ref>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116">http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18253" adv="1">18253</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22160">22160</ref>
        </refs>
        <vuln_soft>
            <prod vendor="richard_dawe" name="file_extattr">
                <vers num="0.1" />
                <vers num="0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0078" seq="2006-0078" severity="Medium" type="CVE" published="2006-01-04" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16114">16114</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded" adv="1">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18271" adv="1">18271</ref>
            <ref source="MISC" url="http://evuln.com/vulns/10/summary.html" adv="1">http://evuln.com/vulns/10/summary.html</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22191">22191</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22190">22190</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0018">ADV-2006-0018</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067">http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/316">316</ref>
        </refs>
        <vuln_soft>
            <prod vendor="haddad_said" name="b-net_software">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0079" seq="2006-0079" severity="High" type="CVE" published="2006-01-04" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16115">16115</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded" adv="1">20060102 [eVuln] ScozBook "adminname" Authentication Bypass</ref>
            <ref source="MISC" url="http://evuln.com/vulns/11/summary.html">http://evuln.com/vulns/11/summary.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22221">22221</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0027">ADV-2006-0027</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/318">318</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8476">8476</ref>
        </refs>
        <vuln_soft>
            <prod vendor="scoznet" name="scozbook">
                <vers num="1.1_beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0080" seq="2006-0080" severity="Medium" type="CVE" published="2006-01-04" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16116">16116</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded">20060108 Html_Injection in vBulletin 3.5.2</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded" adv="1">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22220">22220</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22210">22210</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0033">ADV-2006-0033</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18299">18299</ref>
            <ref source="MISC" url="http://kapda.ir/advisory-177.html" adv="1">http://kapda.ir/advisory-177.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jelsoft" name="vbulletin">
                <vers num="3.5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2006-0081" seq="2006-0081" severity="High" type="CVE" published="2006-01-04" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.8" modified="2008-09-05">
        <desc>
            <descript source="cve">ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16127">16127</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22196">22196</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0017" adv="1">ADV-2006-0017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18286" adv="1">18286</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intel" name="graphics_accelerator_driver">
                <vers num="6.14.10.4308" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2006-0082" seq="2006-0082" severity="Medium" type="CVE" published="2006-01-04" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/12717">12717</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml" adv="1">GLSA-200602-13.xml</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml" adv="1">GLSA-200602-06</ref>
            <ref source="SLACKWARE" patch="1" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682">SSA:2006-045-03</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19183" adv="1">19183</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19030" adv="1">19030</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18851" adv="1">18851</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18607" adv="1">18607</ref>
            <ref source="MANDRIVA" patch="1" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:024" adv="1">MDKSA-2006:024</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-246-1">USN-246-1</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_06_sr.html">SUSE-SR:2006:006</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015623">1015623</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19408" adv="1">19408</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18871" adv="1">18871</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18261" adv="1">18261</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0178.html">RHSA-2006:0178</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-389">https://issues.rpath.com/browse/RPL-389</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded">20061127 rPSA-2006-0218-1 ImageMagick</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1213">DSA-1213</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/500">500</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28800">28800</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23090">23090</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22998">22998</ref>
        </refs>
        <vuln_soft>
            <prod vendor="imagemagick" name="imagemagick">
                <vers num="6.2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0084" seq="2006-0084" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16138">16138</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22198">22198</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0030" adv="1">ADV-2006-0030</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18292" adv="1">18292</ref>
            <ref source="MISC" url="http://evuln.com/vulns/13/summary.html" adv="1">http://evuln.com/vulns/13/summary.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015432">1015432</ref>
            <ref source="VIM" url="http://attrition.org/pipermail/vim/2006-January/000486.html">20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rasmp" name="rasmp">
                <vers num="2.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0085" seq="2006-0085" severity="High" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt" adv="1">http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0040" adv="1">ADV-2006-0040</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18302" adv="1">18302</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22206">22206</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nkads" name="nkads">
                <vers num="1.0alfa2" />
                <vers num="1.0alfa3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0086" seq="2006-0086" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0037" adv="1">ADV-2006-0037</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18309" adv="1">18309</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22202">22202</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22202-nextgen.txt">http://osvdb.org/ref/22/22202-nextgen.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="next_generation_image_gallery" name="next_generation_image_gallery">
                <vers num="0.0.1_lite" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0087" seq="2006-0087" severity="High" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16140">16140</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded" adv="1">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0029" adv="1">ADV-2006-0029</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18297" adv="1">18297</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22200">22200</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22199">22199</ref>
            <ref source="MISC" url="http://www.evuln.com/vulns/12/summary.html">http://www.evuln.com/vulns/12/summary.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015435">1015435</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/314">314</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lizard_cart" name="lizard_cart_cms">
                <vers num="1.0.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0088" seq="2006-0088" severity="High" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16110">16110</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded" adv="1">20060101 [eVuln] inTouch Authentication Bypass</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0026" adv="1">ADV-2006-0026</ref>
            <ref source="MISC" url="http://evuln.com/vulns/8/summary.html" adv="1">http://evuln.com/vulns/8/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23954">intouch-intouch-sql-injection(23954)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22382">22382</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intouch" name="intouch">
                <vers num="0.5.1_alpha" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0089" seq="2006-0089" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16136">16136</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0032" adv="1">ADV-2006-0032</ref>
            <ref source="MISC" url="http://users.pandora.be/bratax/advisories/b007.html" adv="1">http://users.pandora.be/bratax/advisories/b007.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18294" adv="1">18294</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22208">22208</ref>
        </refs>
        <vuln_soft>
            <prod vendor="esri" name="arcpad">
                <vers num="7.0.0.156" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0090" seq="2006-0090" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499">http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0031" adv="1">ADV-2006-0031</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18298" adv="1">18298</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16137">16137</ref>
        </refs>
        <vuln_soft>
            <prod vendor="idv_directory_viewer" name="idv_directory_viewer">
                <vers num="2005.1_b1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0091" seq="2006-0091" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0034" adv="1">ADV-2006-0034</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18285" adv="1">18285</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2" adv="1">20060103 Open Xchange XSS</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015431">1015431</ref>
        </refs>
        <vuln_soft>
            <prod vendor="open-xchange" name="open-xchange">
                <vers num="0.8.1.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2006-0092" seq="2006-0092" type="CVE" published="2006-01-05" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <vuln_types>
            <input />
        </vuln_types>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0093" seq="2006-0093" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22203">22203</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0039" adv="1">ADV-2006-0039</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18306" adv="1">18306</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22203-ecardmax.txt">http://osvdb.org/ref/22/22203-ecardmax.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ecardmax.com" name="atcard_me_php">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0094" seq="2006-0094" severity="High" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0028" adv="1">ADV-2006-0028</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17373" adv="1">17373</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0063" seq="2006-0063" severity="Medium" type="CVE" published="2006-01-05" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SREASON" url="http://securityreason.com/securityalert/313" adv="1">313</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/30" adv="1">20060105 phpBB 2.0.19 XSS</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22672">22672</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0051">ADV-2006-0051</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0341" seq="2006-0341" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0284" adv="1">ADV-2006-0284</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18551" adv="1">18551</ref>
            <ref source="FULLDISC" patch="1" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2" adv="1">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24256">mailsite-wconsole-xss(24256)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16330">16330</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22677">22677</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rockliffe" name="mailsite">
                <vers num="6.1.22" prev="1" />
                <vers num="7.0.3.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2006-0095" seq="2006-0095" severity="Low" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2" adv="1">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24189">kernel-dmcrypt-information-disclosure(24189)</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16301">16301</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded">FLSA:157459-4</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0132.html">RHSA-2006:0132</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html">FEDORA-2006-102</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22418">22418</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0235">ADV-2006-0235</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015740">1015740</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19160">19160</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18774">18774</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18527">18527</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18487">18487</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.13" />
                <vers edition="rc1" num="2.6.14" />
                <vers edition="rc2" num="2.6.14" />
                <vers edition="rc3" num="2.6.14" />
                <vers edition="rc4" num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers edition="rc1" num="2.6.15" />
                <vers edition="rc3" num="2.6.15" />
                <vers edition="rc4" num="2.6.15" />
                <vers edition="rc5" num="2.6.15" />
                <vers edition="rc6" num="2.6.15" />
                <vers edition="rc7" num="2.6.15" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers edition="2.6.20" num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0096" seq="2006-0096" severity="High" type="CVE" published="2006-01-06" CVSS_version="2.0" CVSS_score="7.2" modified="2008-11-20">
        <desc>
            <descript source="cve">wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044">MDKSA-2006:044</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16304">16304</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f">http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19374" adv="1">19374</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18977" adv="1">18977</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18527" adv="1">18527</ref>
            <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c">http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.23_ow2" />
                <vers num="2.4.24" />
                <vers num="2.4.24_ow1" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="pre1" num="2.4.27" />
                <vers edition="pre2" num="2.4.27" />
                <vers edition="pre3" num="2.4.27" />
                <vers edition="pre4" num="2.4.27" />
                <vers edition="pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.13" />
                <vers edition="rc1" num="2.6.14" />
                <vers edition="rc2" num="2.6.14" />
                <vers edition="rc3" num="2.6.14" />
                <vers edition="rc4" num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers edition="rc1" num="2.6.15" />
                <vers edition="rc3" num="2.6.15" />
                <vers edition="rc4" num="2.6.15" />
                <vers edition="rc5" num="2.6.15" />
                <vers edition="rc6" num="2.6.15" />
                <vers edition="rc7" num="2.6.15" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers edition="2.6.20" num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0097" seq="2006-0097" severity="High" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16145">16145</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded">20060105 Windows PHP 4.x "0-day" buffer overflow</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-4.php#4.4.3">http://www.php.net/ChangeLog-4.php#4.4.3</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22232">22232</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0046" adv="1">ADV-2006-0046</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18275" adv="1">18275</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html" adv="1">20060105 Windows PHP 4.x "0-day" buffer overflow</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html">20060108 RE: Windows PHP 4.x "0-day" buffer overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.3.10" />
                <vers num="4.4.0" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0098" seq="2006-0098" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16144">16144</ref>
            <ref source="OPENBSD" patch="1" url="http://www.openbsd.org/errata37.html#fd">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18296" adv="1">18296</ref>
            <ref source="MISC" patch="1" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22231">22231</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015437">1015437</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.7" />
                <vers num="3.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0099" seq="2006-0099" severity="High" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16126">16126</ref>
            <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl">http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl</ref>
            <ref source="MILW0RM" url="http://milw0rm.com/exploits/1401">1401</ref>
        </refs>
        <vuln_soft>
            <prod vendor="valdersoft" name="valdersoft_shopping_cart">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0100" seq="2006-0100" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the "Name of site" field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded">20060102 NicoFTP Stack Overflow</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/317">317</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nicosw" name="nicoftp">
                <vers num="3.0.1.19" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" severity="Medium" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0101" seq="2006-0101" published="2006-01-06" discovered="2006-01-06" CVSS_score="4.3">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23979">sblog-multiple-scripts-xss(23979)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22374">22374</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22373">22373</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0041" adv="1">ADV-2006-0041</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22373-sblog.txt">http://osvdb.org/ref/22/22373-sblog.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sblog" name="sblog">
                <vers num="0.7.1_build2005-12-02_beta" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0102" seq="2006-0102" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22256">22256</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0054" adv="1">ADV-2006-0054</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18293" adv="1">18293</ref>
            <ref source="MISC" url="http://evuln.com/vulns/14/summary.html" adv="1">http://evuln.com/vulns/14/summary.html</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ralph_capper" name="tinyphpforum">
                <vers num="3.46" />
                <vers num="3.47" />
                <vers num="3.48" />
                <vers num="3.49" />
                <vers num="3.499" />
                <vers num="3.5" />
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0103" seq="2006-0103" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded">20060417 Tiny PHP forum - vulns</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" adv="1">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22257">22257</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0054" adv="1">ADV-2006-0054</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18293" adv="1">18293</ref>
            <ref source="MISC" url="http://evuln.com/vulns/14/summary.html" adv="1">http://evuln.com/vulns/14/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24016">tinyphpforum-users-information-disclosure(24016)</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ralph_capper" name="tinyphpforum">
                <vers num="3.46" />
                <vers num="3.47" />
                <vers num="3.48" />
                <vers num="3.49" />
                <vers num="3.499" />
                <vers num="3.5" />
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0104" seq="2006-0104" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" adv="1">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0054" adv="1">ADV-2006-0054</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18293" adv="1">18293</ref>
            <ref source="MISC" url="http://evuln.com/vulns/14/summary.html" adv="1">http://evuln.com/vulns/14/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/14/exploit.html">http://evuln.com/vulns/14/exploit.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16163">16163</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22258">22258</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ralph_capper" name="tinyphpforum">
                <vers num="3.46" />
                <vers num="3.47" />
                <vers num="3.48" />
                <vers num="3.49" />
                <vers num="3.499" />
                <vers num="3.5" />
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0106" seq="2006-0106" severity="High" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0098" adv="1">ADV-2006-0098</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18323" adv="1">18323</ref>
            <ref source="MISC" patch="1" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197</ref>
            <ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html">[Dailydave] 20060105 WMF goes away :&lt;</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23846">win-wmf-execute-code(23846)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml">GLSA-200601-09</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-954">DSA-954</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18578">18578</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18549">18549</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18451">18451</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wine" name="wine">
                <vers num="0.9.2" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="2005-09-30" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0107" seq="2006-0107" severity="High" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16159">16159</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22252">22252</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18324" adv="1">18324</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24014">timecancms-sql-injection(24014)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="idea_development_id_oy" name="timecan_cms">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0108" seq="2006-0108" severity="High" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22253">22253</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22252">22252</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0078" adv="1">ADV-2006-0078</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24014">timecancms-sql-injection(24014)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="idea_development_id_oy" name="timecan_cms">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" severity="Medium" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0109" seq="2006-0109" published="2006-01-06" discovered="2006-01-06" CVSS_score="5.0">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18320" adv="1">18320</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16160">16160</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22243">22243</ref>
            <ref source="MISC" url="http://www.modularmerchant.com/forums/viewtopic.php?t=46">http://www.modularmerchant.com/forums/viewtopic.php?t=46</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0076" adv="1">ADV-2006-0076</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22243-modular.txt">http://osvdb.org/ref/22/22243-modular.txt</ref>
            <ref source="VIM" url="http://attrition.org/pipermail/vim/2006-February/000548.html">20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="modular_merchant" name="shopping_cart">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" severity="Medium" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0110" seq="2006-0110" published="2006-01-06" discovered="2006-01-06" CVSS_score="4.3">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16154">16154</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded">20060106 [eVuln] Proyecto Domus 'email' XSS Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22263">22263</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0073" adv="1">ADV-2006-0073</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18327" adv="1">18327</ref>
            <ref source="MISC" url="http://evuln.com/vulns/16/summary.html">http://evuln.com/vulns/16/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24020">domus-escribir-xss(24020)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="javier_suarez_sanz" name="foro_domus">
                <vers num="2.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" severity="Medium" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0111" seq="2006-0111" published="2006-01-06" discovered="2006-01-06" CVSS_score="5.0">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24019">boxcar-index-xss(24019)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22360">22360</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0080" adv="1">ADV-2006-0080</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22360-boxcar.txt">http://osvdb.org/ref/22/22360-boxcar.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="boxcar_media" name="shopping_cart">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0112" seq="2006-0112" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22201">22201</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0036" adv="1">ADV-2006-0036</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18310" adv="1">18310</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22201-espg.txt">http://osvdb.org/ref/22/22201-espg.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="enhanced_simple_php_gallery" name="enhanced_simple_php_gallery">
                <vers num="1.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0113" seq="2006-0113" severity="Medium" type="CVE" published="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18310" adv="1">18310</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22201-espg.txt">http://osvdb.org/ref/22/22201-espg.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22417">22417</ref>
        </refs>
        <vuln_soft>
            <prod vendor="enhanced_simple_php_gallery" name="enhanced_simple_php_gallery">
                <vers num="1.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" severity="Medium" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0114" seq="2006-0114" published="2006-01-09" discovered="2006-01-30" CVSS_score="5.0">
        <desc>
            <descript source="cve">The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16185">16185</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0097">ADV-2006-0097</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18361">18361</ref>
            <ref source="CONFIRM" url="http://forum.joomla.org/index.php/topic,29031.0.html" adv="1">http://forum.joomla.org/index.php/topic,29031.0.html</ref>
            <ref source="CONFIRM" url="http://forge.joomla.org/sf/go/artf2950">http://forge.joomla.org/sf/go/artf2950</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24042">joomla-vcard-information-disclosure(24042)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="joomla" name="joomla">
                <vers num="1.0.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0115" seq="2006-0115" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16155">16155</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22250">22250</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22249">22249</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22248">22248</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0079" adv="1">ADV-2006-0079</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18325" adv="1">18325</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22248-oneplug.txt">http://osvdb.org/ref/22/22248-oneplug.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oneplug_solutions" name="oneplug_cms">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0116" seq="2006-0116" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16156">16156</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22251">22251</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0075" adv="1">ADV-2006-0075</ref>
            <ref source="VIM" url="http://www.attrition.org/pipermail/vim/2006-January/000515.html">20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18322" adv="1">18322</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22251-inetstore.txt">http://osvdb.org/ref/22/22251-inetstore.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="inetstore" name="inetstore_online">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0117" seq="2006-0117" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16158">16158</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18328" adv="1">18328</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24205">lotus-cdtomime-dos(24205)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="6.5.0" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers edition="" num="6.5.4" />
                <vers edition=":fp1" num="6.5.4" />
                <vers edition=":fp2" num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_domino_enterprise_server">
                <vers num="6.5.2" />
                <vers num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_notes">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers num="6.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0118" seq="2006-0118" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16158">16158</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18328" adv="1">18328</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24206">lotus-long-formula-bo(24206)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="6.5.0" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers edition="" num="6.5.4" />
                <vers edition=":fp1" num="6.5.4" />
                <vers edition=":fp2" num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_domino_enterprise_server">
                <vers num="6.5.2" />
                <vers num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_notes">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers num="6.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0119" seq="2006-0119" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16158">16158</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18328" adv="1">18328</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/18020">18020</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/2564">ADV-2006-2564</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1016390">1016390</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20855">20855</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27413">domino-smtp-nrouter-dos(27413)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24211">lotus-web-unspecified-xss(24211)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24207">lotus-multiple-unspecified(24207)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="6.5.0" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers edition="" num="6.5.4" />
                <vers edition=":fp1" num="6.5.4" />
                <vers edition=":fp2" num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_domino_enterprise_server">
                <vers num="6.5.2" />
                <vers num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_notes">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers num="6.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0120" seq="2006-0120" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16158">16158</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18328" adv="1">18328</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24217">lotus-ssl-keyring-dos(24217)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24216">lotus-certificate-parsing-dos(24216)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24215">lotus-delete-attachment-dos(24215)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24214">lotus-bmp-dos(24214)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24213">lotus-compact-dos(24213)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24212">lotus-outofoffice-dos(24212)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="6.5.0" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers edition="" num="6.5.4" />
                <vers edition=":fp1" num="6.5.4" />
                <vers edition=":fp2" num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_domino_enterprise_server">
                <vers num="6.5.2" />
                <vers num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_notes">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers num="6.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2006-0121" seq="2006-0121" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16158">16158</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18328" adv="1">18328</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT</ref>
            <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24223">lotus-ssl-handshake-dos(24223)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="6.5.0" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers edition="" num="6.5.4" />
                <vers edition=":fp1" num="6.5.4" />
                <vers edition=":fp2" num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_domino_enterprise_server">
                <vers num="6.5.2" />
                <vers num="6.5.4" />
            </prod>
            <prod vendor="ibm" name="lotus_notes">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
                <vers num="6.5.3" />
                <vers num="6.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0122" seq="2006-0122" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</descript>
        </desc>
        <sols>
            <sol source="nvd">Vendor provided solution:

"Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability.  For more information visit www.aquifercms.com."</sol>
        </sols>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/22247">22247</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16162">16162</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0074" adv="1">ADV-2006-0074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18326" adv="1">18326</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22247-aquifer.txt">http://osvdb.org/ref/22/22247-aquifer.txt</ref>
            <ref source="VIM" url="http://attrition.org/pipermail/vim/2006-January/000509.html">20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="aquifer_cms" name="aquifer_cms">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" severity="High" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0123" seq="2006-0123" published="2006-01-09" discovered="2006-01-05" CVSS_score="7.5">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16157">16157</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" adv="1">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22241">22241</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22240">22240</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0077" adv="1">ADV-2006-0077</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015445">1015445</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18300" adv="1">18300</ref>
            <ref source="MISC" url="http://evuln.com/vulns/15/summary.html" adv="1">http://evuln.com/vulns/15/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adn_forum" name="adn_forum">
                <vers num="1.0" />
                <vers num="1.0b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0124" seq="2006-0124" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2009-04-03">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16157">16157</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" adv="1">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0077" adv="1">ADV-2006-0077</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18300" adv="1">18300</ref>
            <ref source="MISC" url="http://evuln.com/vulns/15/summary.html" adv="1">http://evuln.com/vulns/15/summary.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22242">22242</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015445">1015445</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adn_forum" name="adn_forum">
                <vers num="1.0" />
                <vers num="1.0b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0125" seq="2006-0125" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22228">22228</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0053" adv="1">ADV-2006-0053</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18163" adv="1">18163</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16166">16166</ref>
        </refs>
        <vuln_soft>
            <prod vendor="appserv_open_project" name="appserv">
                <vers num="2.4.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0126" seq="2006-0126" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/22223">22223</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0052" adv="1">ADV-2006-0052</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18301" adv="1">18301</ref>
            <ref source="CONFIRM" url="http://dist.schmorp.de/rxvt-unicode/Changes">http://dist.schmorp.de/rxvt-unicode/Changes</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rxvt-unicode" name="rxvt-unicode">
                <vers num="6.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" name="CVE-2006-0127" seq="2006-0127" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/22229">22229</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0055" adv="1">ADV-2006-0055</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18318" adv="1">18318</ref>
            <ref source="FULLDISC" patch="1" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" adv="1">20060104 Rockliffe Directory Transversal Vulnerability</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html">20060105 Re: Rockliffe Directory Transversal Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rockliffe" name="mailsite">
                <vers num="6.1.22.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0128" seq="2006-0128" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</ref>
            <ref source="FULLDISC" patch="1" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" adv="1">20060104 Rockliffe Directory Transversal Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39991">rockliffe-imap-unspecified-bo(39991)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rockliffe" name="mailsite">
                <vers num="6.1.22.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0129" seq="2006-0129" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0055" adv="1">ADV-2006-0055</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18318" adv="1">18318</ref>
            <ref source="MISC" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22230">22230</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" adv="1">20060104 Rockliffe Mailsite User Enumeration Flaw</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rockliffe" name="mailsite">
                <vers num="7.0.3.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0130" seq="2006-0130" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" adv="1">20060104 Rockliffe Mailsite User Enumeration Flaw</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rockliffe" name="mailsite">
                <vers num="7.0.3.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0131" seq="2006-0131" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded" adv="1">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</ref>
            <ref source="MISC" url="http://echo.or.id/adv/adv26-K-159-2006.txt">http://echo.or.id/adv/adv26-K-159-2006.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="boastmachine" name="boastmachine">
                <vers num="3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0132" seq="2006-0132" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0090" adv="1">ADV-2006-0090</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18355" adv="1">18355</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16175">16175</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded">20060104 SysCP WebFTP local file inclusion vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24018">webftp-language-file-include(24018)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webftp" name="webftp">
                <vers num="1.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-2006-0133" seq="2006-0133" severity="Low" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="3.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16103">16103</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16102">16102</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded" adv="1">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015429">1015429</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="5.3_ml03" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0134" seq="2006-0134" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16161">16161</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0093" adv="1">ADV-2006-0093</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015450">1015450</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18392" adv="1">18392</ref>
            <ref source="MISC" url="http://evuln.com/vulns/17/summary.html">http://evuln.com/vulns/17/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/17/exploit.html">http://evuln.com/vulns/17/exploit.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24007">thewebforum-register-xss(24007)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22295">22295</ref>
        </refs>
        <vuln_soft>
            <prod vendor="thewebforum" name="thewebforum">
                <vers num="1.2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0135" seq="2006-0135" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16161">16161</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0093" adv="1">ADV-2006-0093</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015450">1015450</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18392" adv="1">18392</ref>
            <ref source="MISC" url="http://evuln.com/vulns/17/summary.html">http://evuln.com/vulns/17/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/17/exploit.html">http://evuln.com/vulns/17/exploit.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24027">thewebforum-login-sql-injection(24027)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22294">22294</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/321">321</ref>
        </refs>
        <vuln_soft>
            <prod vendor="thewebforum" name="thewebforum">
                <vers num="1.2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0136" seq="2006-0136" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16113">16113</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0025" adv="1">ADV-2006-0025</ref>
            <ref source="MISC" url="http://evuln.com/vulns/7/summary.html">http://evuln.com/vulns/7/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/7/exploit.html">http://evuln.com/vulns/7/exploit.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phanatic_softwares" name="chimera_web_portal">
                <vers num="0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0137" seq="2006-0137" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16113">16113</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0025" adv="1">ADV-2006-0025</ref>
            <ref source="MISC" url="http://evuln.com/vulns/7/summary.html">http://evuln.com/vulns/7/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/7/exploit.html">http://evuln.com/vulns/7/exploit.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23963">chimera-linkcategory-sql-injection(23963)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22420">22420</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phanatic_softwares" name="chimera_web_portal">
                <vers num="0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0138" seq="2006-0138" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.securiteam.com/exploits/5JP090KHFQ.html" adv="1">http://www.securiteam.com/exploits/5JP090KHFQ.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22186">22186</ref>
        </refs>
        <vuln_soft>
            <prod vendor="amsn" name="amsn">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0139" seq="2006-0139" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16168">16168</ref>
            <ref source="CONFIRM" patch="1" url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924" adv="1">http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924</ref>
            <ref source="MISC" patch="1" url="http://www.hamid.ir/security/megabbs.txt" adv="1">http://www.hamid.ir/security/megabbs.txt</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0095" adv="1">ADV-2006-0095</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18342" adv="1">18342</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24050">megabbs-sendprivatemessage-disclosure(24050)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015452">1015452</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pd9_software" name="megabbs">
                <vers num="2.0" />
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0140" seq="2006-0140" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0" CVSS_score="4.3" modified="2009-01-22">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24021">navboard-post-xss(24021)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16165">16165</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded" adv="1">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22277">22277</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0092" adv="1">ADV-2006-0092</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18345" adv="1">18345</ref>
            <ref source="MISC" url="http://evuln.com/vulns/19/summary.html" adv="1">http://evuln.com/vulns/19/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="navboard" name="navboard">
                <vers num="16" />
                <vers edition="beta2" num="17" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" severity="Medium" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0141" seq="2006-0141" published="2006-01-09" discovered="2006-01-09" CVSS_score="5.0">
        <desc>
            <descript source="cve">Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0099">ADV-2006-0099</ref>
            <ref source="CONFIRM" patch="1" url="http://www.eudora.co.nz/updates.html">http://www.eudora.co.nz/updates.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18356" adv="1">18356</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16179">16179</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24033">eims-corrupted-mail-dos(24033)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24032">eims-ntlm-auth-dos(24032)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eudora" name="internet_mail_server">
                <vers num="3.2.6" />
                <vers num="3.2.7" />
                <vers num="3.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0142" seq="2006-0142" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16183">16183</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0096" adv="1">ADV-2006-0096</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18359" adv="1">18359</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24031">andromeda-script-xss(24031)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="andromeda_software" name="andromeda">
                <vers num="1.9.3.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0143" seq="2006-0143" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015453">1015453</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16167">16167</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded" adv="1">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded" adv="1">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0115" adv="1">ADV-2006-0115</ref>
            <ref source="CONFIRM" url="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx">http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24044">win-gre-wmf-dos(24044)</ref>
            <ref source="MISC" url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":datacenter_server" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition=":professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:professional" num="" />
                <vers edition="sp3:server" num="" />
                <vers edition="sp4" num="" />
                <vers edition="sp4:server" num="" />
                <vers edition="sp4:datacenter_server" num="" />
                <vers edition="sp4:advanced_server" num="" />
                <vers edition="sp4:professional" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2003_server">
                <vers edition="sp1" num="datacenter_64-bit" />
                <vers edition="" num="enterprise" />
                <vers edition=":64-bit" num="enterprise" />
                <vers edition="sp1" num="enterprise" />
                <vers edition="sp1" num="enterprise_64-bit" />
                <vers edition="" num="r2" />
                <vers edition=":64-bit" num="r2" />
                <vers edition=":datacenter_64-bit" num="r2" />
                <vers edition="sp1" num="r2" />
                <vers edition="" num="standard" />
                <vers edition=":64-bit" num="standard" />
                <vers edition="sp1" num="standard" />
                <vers num="standard_64-bit" />
                <vers edition="sp1" num="web" />
            </prod>
            <prod vendor="microsoft" name="windows_98">
                <vers edition="gold" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_98se">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_me">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":64-bit" num="" />
                <vers edition=":media_center" num="" />
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:home" num="" />
                <vers edition="sp1:media_center" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:media_center" num="" />
                <vers edition="sp2:home" num="" />
                <vers edition="sp2:tablet_pc" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0083" seq="2006-0083" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18357" adv="1">18357</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24034">smstools-logging-format-string(24034)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16188">16188</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22287">22287</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-930">DSA-930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18343" adv="1">18343</ref>
        </refs>
        <vuln_soft>
            <prod vendor="stefan_frings" name="sms_server_tools">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0144" seq="2006-0144" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0148" adv="1">ADV-2006-0148</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18390" adv="1">18390</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24076">gopear-proxy-redirection(24076)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16174">16174</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded">20060109 New PEAR / Apache2Triad Exploit</ref>
            <ref source="CONFIRM" url="http://apache2triad.net/forums/viewtopic.php?p=14670">http://apache2triad.net/forums/viewtopic.php?p=14670</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache2triad" name="apache2triad">
                <vers num="" />
            </prod>
            <prod vendor="php" name="pear">
                <vers num="0.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0145" seq="2006-0145" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16173">16173</ref>
            <ref source="MISC" url="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html" adv="1">http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22293">22293</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18712" adv="1">18712</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18388" adv="1">18388</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">NetBSD-SA2006-001</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24035">netbsd-kernfs-memory-disclosure(24035)</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/405">405</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netbsd" name="netbsd">
                <vers edition="beta" num="1.6" />
                <vers num="1.6.1" />
                <vers num="1.6.2" />
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0146" seq="2006-0146" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.xaraya.com/index.php/news/569">http://www.xaraya.com/index.php/news/569</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16187">16187</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded">20060202 Bug for libs in php link directory 2.0</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/22290">22290</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" adv="1">GLSA-200604-07</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/1419" adv="1">ADV-2006-1419</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/1304" adv="1">ADV-2006-1304</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0447" adv="1">ADV-2006-0447</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0370" adv="1">ADV-2006-0370</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0105" adv="1">ADV-2006-0105</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0104" adv="1">ADV-2006-0104</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0103" adv="1">ADV-2006-0103</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0101" adv="1">ADV-2006-0101</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1031" adv="1">DSA-1031</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1030" adv="1">DSA-1030</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1029" adv="1">DSA-1029</ref>
            <ref source="MISC" patch="1" url="http://secunia.com/secunia_research/2005-64/advisory/" adv="1">http://secunia.com/secunia_research/2005-64/advisory/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19699" adv="1">19699</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19591" adv="1">19591</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19590" adv="1">19590</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19563" adv="1">19563</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19555" adv="1">19555</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18720" adv="1">18720</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18276" adv="1">18276</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18260" adv="1">18260</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18233" adv="1">18233</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/17418" adv="1">17418</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24051">adodb-server-command-execution(24051)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded">20070418 MediaBeez Sql query Execution .. Wear isn't ?? :)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</ref>
            <ref source="CONFIRM" url="http://www.maxdev.com/Article550.phtml">http://www.maxdev.com/Article550.phtml</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/1305" adv="1">ADV-2006-1305</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0102" adv="1">ADV-2006-0102</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/713">713</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24954" adv="1">24954</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19691" adv="1">19691</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19600" adv="1">19600</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18267" adv="1">18267</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18254" adv="1">18254</ref>
            <ref source="MISC" url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="john_lim" name="adodb">
                <vers num="4.66" />
                <vers num="4.68" />
            </prod>
            <prod vendor="mantis" name="mantis">
                <vers num="0.19.4" />
                <vers num="1.0.0_rc4" />
            </prod>
            <prod vendor="mediabeez" name="mediabeez">
                <vers num="" />
            </prod>
            <prod vendor="moodle" name="moodle">
                <vers num="1.5.3" />
            </prod>
            <prod vendor="postnuke_software_foundation" name="postnuke">
                <vers num="0.761" />
            </prod>
            <prod vendor="the_cacti_group" name="cacti">
                <vers num="0.8.6g" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0147" seq="2006-0147" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/22291">22291</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" adv="1">GLSA-200604-07</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/1332" adv="1">ADV-2006-1332</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0104" adv="1">ADV-2006-0104</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0103" adv="1">ADV-2006-0103</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0102" adv="1">ADV-2006-0102</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0101" adv="1">ADV-2006-0101</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1030" adv="1">DSA-1030</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1029" adv="1">DSA-1029</ref>
            <ref source="MISC" patch="1" url="http://secunia.com/secunia_research/2005-64/advisory/" adv="1">http://secunia.com/secunia_research/2005-64/advisory/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19628" adv="1">19628</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19591" adv="1">19591</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19590" adv="1">19590</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19555" adv="1">19555</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18276" adv="1">18276</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18260" adv="1">18260</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18254" adv="1">18254</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18233" adv="1">18233</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/17418" adv="1">17418</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/1305" adv="1">ADV-2006-1305</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19600" adv="1">19600</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18267" adv="1">18267</ref>
            <ref source="MISC" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
            <ref source="MISC" url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</ref>
            <ref source="MILW0RM" url="http://milw0rm.com/exploits/1663">1663</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24052">adodb-tmssql-command-execution(24052)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19691">19691</ref>
        </refs>
        <vuln_soft>
            <prod vendor="john_lim" name="adodb">
                <vers num="4.66" />
                <vers num="4.68" />
            </prod>
            <prod vendor="mantis" name="mantis">
                <vers num="0.19.4" />
                <vers num="1.0.0_rc4" />
            </prod>
            <prod vendor="moodle" name="moodle">
                <vers num="1.5.3" />
            </prod>
            <prod vendor="postnuke_software_foundation" name="postnuke">
                <vers num="0.761" />
            </prod>
            <prod vendor="the_cacti_group" name="cacti">
                <vers num="0.8.6g" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0148" seq="2006-0148" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16164">16164</ref>
            <ref source="MISC" url="http://www.ipomonis.com/advisories/xlpd.txt" adv="1">http://www.ipomonis.com/advisories/xlpd.txt</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015444">1015444</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24041">xlpd-connection-dos(24041)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netsarang" name="xlpd">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0149" seq="2006-0149" severity="Medium" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015451" adv="1">1015451</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html" adv="1">20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="simpbook" name="simpbook">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" severity="High" CVSS_version="2.0 upgrade from v1.0" type="CVE" modified="2008-09-05" name="CVE-2006-0150" seq="2006-0150" published="2006-01-09" discovered="2005-12-22" CVSS_score="7.5">
        <desc>
            <descript source="cve">Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MANDRIVA" patch="1" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017" adv="1">MDKSA-2006:017</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16177">16177</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2006-0179.html" adv="1">RHSA-2006:0179</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0117" adv="1">ADV-2006-0117</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-952" adv="1">DSA-952</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18568" adv="1">18568</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18412" adv="1">18412</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18405" adv="1">18405</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18382" adv="1">18382</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded" adv="1">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</ref>
            <ref source="CONFIRM" url="http://www.rudedog.org/auth_ldap/Changes.html">http://www.rudedog.org/auth_ldap/Changes.html</ref>
            <ref source="MISC" url="http://www.digitalarmaments.com/2006090173928420.html" adv="1">http://www.digitalarmaments.com/2006090173928420.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015456">1015456</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24030">apache-authldap-format-string(24030)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dave_carrigan" name="auth_ldap">
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
                <vers num="1.3.3" />
                <vers num="1.3.4" />
                <vers num="1.4.0" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0151" seq="2006-0151" severity="High" type="CVE" published="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
            <env />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18363" adv="1">18363</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2">USN-235-2</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16184">16184</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18358" adv="1">18358</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0010">2006-0010</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-946">DSA-946</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822">SSA:2006-045-08</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21692">21692</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19016">19016</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18906">18906</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18558">18558</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18549">18549</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</ref>
        </refs>
        <vuln_soft>
            <prod vendor="todd_miller" name="sudo">
                <vers num="1.5.6" />
                <vers num="1.5.7" />
                <vers num="1.5.8" />
                <vers num="1.5.9" />
                <vers num="1.6" />
                <vers num="1.6.1" />
                <vers num="1.6.2" />
                <vers num="1.6.3" />
                <vers num="1.6.3_p1" />
                <vers num="1.6.3_p2" />
                <vers num="1.6.3_p3" />
                <vers num="1.6.3_p4" />
                <vers num="1.6.3_p5" />
                <vers num="1.6.3_p6" />
                <vers num="1.6.3_p7" />
                <vers num="1.6.4" />
                <vers num="1.6.4_p1" />
                <vers num="1.6.4_p2" />
                <vers num="1.6.5" />
                <vers num="1.6.5_p1" />
                <vers num="1.6.5_p2" />
                <vers num="1.6.6" />
                <vers num="1.6.7" />
                <vers num="1.6.7_p5" />
                <vers num="1.6.8" />
                <vers num="1.6.8_p1" />
                <vers num="1.6.8_p12" />
                <vers num="1.6.8_p2" />
                <vers num="1.6.8_p5" />
                <vers num="1.6.8_p7" />
                <vers num="1.6.8_p8" />
                <vers num="1.6.8_p9" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers edition="" num="4.1" />
                <vers edition=":ppc" num="4.1" />
                <vers edition=":ia64" num="4.1" />
                <vers edition="" num="5.04" />
                <vers edition=":powerpc" num="5.04" />
                <vers edition=":amd64" num="5.04" />
                <vers edition=":i386" num="5.04" />
                <vers edition="" num="5.10" />
                <vers edition=":powerpc" num="5.10" />
                <vers edition=":i386" num="5.10" />
                <vers edition=":amd64" num="5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0152" seq="2006-0152" severity="Medium" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16180">16180</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0094" adv="1">ADV-2006-0094</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18360" adv="1">18360</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24029">phpchamber-searchresult-xss(24029)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22282">22282</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpchamber" name="phpchamber">
                <vers num="1.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0153" seq="2006-0153" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16178">16178</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0091" adv="1">ADV-2006-0091</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18354" adv="1">18354</ref>
            <ref source="MISC" url="http://evuln.com/vulns/18/summary.html" adv="1">http://evuln.com/vulns/18/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24038">427bb-scripts-security-bypass(24038)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22274">22274</ref>
        </refs>
        <vuln_soft>
            <prod vendor="427bb" name="fourtwosevenbb">
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0154" seq="2006-0154" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16169">16169</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0091" adv="1">ADV-2006-0091</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18354" adv="1">18354</ref>
            <ref source="MISC" url="http://evuln.com/vulns/18/summary.html" adv="1">http://evuln.com/vulns/18/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24039">427bb-showthread-sql-injection(24039)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22275">22275</ref>
        </refs>
        <vuln_soft>
            <prod vendor="427bb" name="fourtwosevenbb">
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0155" seq="2006-0155" severity="Medium" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0091" adv="1">ADV-2006-0091</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18354" adv="1">18354</ref>
            <ref source="MISC" url="http://evuln.com/vulns/18/summary.html">http://evuln.com/vulns/18/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24040">427bb-posts-xss(24040)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22276">22276</ref>
        </refs>
        <vuln_soft>
            <prod vendor="427bb" name="fourtwosevenbb">
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0156" seq="2006-0156" severity="Medium" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16172">16172</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded" adv="1">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0121" adv="1">ADV-2006-0121</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18386" adv="1">18386</ref>
            <ref source="MISC" url="http://evuln.com/vulns/20" adv="1">http://evuln.com/vulns/20</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24043">foxrum-bbcode-xss(24043)</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/325">325</ref>
        </refs>
        <vuln_soft>
            <prod vendor="foxrum" name="foxrum">
                <vers num="4.0.4f" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0157" seq="2006-0157" severity="Medium" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16182">16182</ref>
            <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl">http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18601">18601</ref>
        </refs>
        <vuln_soft>
            <prod vendor="reamday_enterprises" name="magic_news_plus">
                <vers num="1.0.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0158" seq="2006-0158" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22205">22205</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0038" adv="1">ADV-2006-0038</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18305" adv="1">18305</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22205-sitesuite.txt">http://osvdb.org/ref/22/22205-sitesuite.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cyberdoc" name="sitesuite_cms">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0159" seq="2006-0159" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22264">22264</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0073" adv="1">ADV-2006-0073</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18327" adv="1">18327</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24017">domus-escribir-sql-injection(24017)</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0160" seq="2006-0160" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24046">venomboard-addpost-sql-injection(24046)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16176">16176</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22297">22297</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0122" adv="1">ADV-2006-0122</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18383" adv="1">18383</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2" adv="1">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2" adv="1">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref>
            <ref source="MISC" url="http://evuln.com/vulns/21/summary.html" adv="1">http://evuln.com/vulns/21/summary.html</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/326">326</ref>
        </refs>
        <vuln_soft>
            <prod vendor="venom_board" name="venom_board">
                <vers num="1.22" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0161" seq="2006-0161" severity="Medium" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1" adv="1">101933</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0113">ADV-2006-0113</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015455">1015455</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18371">18371</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534" sig="1">oval:org.mitre.oval:def:1534</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0162" seq="2006-0162" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/385908">VU#385908</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16191">16191</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0116" adv="1">ADV-2006-0116</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18379" adv="1">18379</ref>
            <ref source="CONFIRM" url="http://www.clamav.net/doc/0.88/ChangeLog">http://www.clamav.net/doc/0.88/ChangeLog</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24047">clamav-libclamav-upx-bo(24047)</ref>
            <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html">http://www.zerodayinitiative.com/advisories/ZDI-06-001.html</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0002/">2006-0002</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22318">22318</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml">GLSA-200601-07</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-947">DSA-947</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015457">1015457</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/342">342</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18548">18548</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18478">18478</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18463">18463</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18453">18453</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</ref>
        </refs>
        <vuln_soft>
            <prod vendor="clam_anti-virus" name="clamav">
                <vers num="." />
                <vers num="0.51" />
                <vers num="0.52" />
                <vers num="0.53" />
                <vers num="0.54" />
                <vers num="0.60" />
                <vers num="0.65" />
                <vers num="0.67" />
                <vers num="0.68" />
                <vers num="0.68.1" />
                <vers num="0.70" />
                <vers num="0.75.1" />
                <vers num="0.80" />
                <vers num="0.80_rc1" />
                <vers num="0.80_rc2" />
                <vers num="0.80_rc3" />
                <vers num="0.80_rc4" />
                <vers num="0.81" />
                <vers num="0.82" />
                <vers num="0.83" />
                <vers num="0.84" />
                <vers num="0.84_rc1" />
                <vers num="0.84_rc2" />
                <vers num="0.85" />
                <vers num="0.85.1" />
                <vers num="0.86" />
                <vers num="0.86.1" />
                <vers num="0.86.2" />
                <vers num="0.87" />
                <vers num="0.87.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0105" seq="2006-0105" severity="Medium" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24049">postgresql-connection-request-dos(24049)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16201">16201</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</ref>
            <ref source="CONFIRM" url="http://www.postgresql.org/about/news.456">http://www.postgresql.org/about/news.456</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0114">ADV-2006-0114</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015482">1015482</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/327">327</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18419">18419</ref>
        </refs>
        <vuln_soft>
            <prod vendor="postgresql" name="postgresql">
                <vers num="8.0" />
                <vers num="8.0.1" />
                <vers num="8.0.2" />
                <vers num="8.0.3" />
                <vers num="8.0.4" />
                <vers num="8.0.5" />
                <vers num="8.1.0" />
                <vers num="8.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2006-0020" seq="2006-0020" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0" CVSS_score="9.3" modified="2008-09-05">
        <desc>
            <descript source="cve">An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/312956" adv="1">VU#312956</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" adv="1">TA06-045A</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16516">16516</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx">MS06-004</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0469" adv="1">ADV-2006-0469</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18729" adv="1">18729</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22976">22976</ref>
            <ref source="CONFIRM" url="http://www.microsoft.com/technet/security/advisory/913333.mspx" adv="1">http://www.microsoft.com/technet/security/advisory/913333.mspx</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18912" adv="1">18912</ref>
            <ref source="MLIST" url="http://linuxbox.org/pipermail/funsec/2006-January/002828.html" adv="1">[funsec] 20060110 Another WMF flaw without a Microsoft patch</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638" sig="1">oval:org.mitre.oval:def:1638</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition="sp4" num="" />
                <vers edition="sp4:" num="" />
                <vers edition="sp4::fr" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2003_server">
                <vers num="r2" />
                <vers num="sp1" />
            </prod>
            <prod vendor="microsoft" name="windows_98">
                <vers edition="gold" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_98se">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_me">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition="sp1" num="" />
                <vers edition="sp1:tablet_pc" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:tablet_pc" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2006-0010" seq="2006-0010" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0" CVSS_score="9.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/915930" adv="1">VU#915930</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16194">16194</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx" adv="1">MS06-002</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0118" adv="1">ADV-2006-0118</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18365" adv="1">18365</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23922">win-embedded-fonts-bo(23922)</ref>
            <ref source="MISC" url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/18829">18829</ref>
            <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html">EEYEB20050801</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015459">1015459</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18391" adv="1">18391</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18311" adv="1">18311</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714" sig="1">oval:org.mitre.oval:def:714</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698" sig="1">oval:org.mitre.oval:def:698</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491" sig="1">oval:org.mitre.oval:def:1491</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462" sig="1">oval:org.mitre.oval:def:1462</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185" sig="1">oval:org.mitre.oval:def:1185</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126" sig="1">oval:org.mitre.oval:def:1126</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":professional" num="" />
                <vers edition=":datacenter_server" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:professional" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:server" num="" />
                <vers edition="sp4" num="" />
                <vers edition="sp4:server" num="" />
                <vers edition="sp4:professional" num="" />
                <vers edition="sp4:datacenter_server" num="" />
                <vers edition="sp4:advanced_server" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2003_server">
                <vers edition="sp1" num="datacenter_64-bit" />
                <vers edition="" num="enterprise" />
                <vers edition=":64-bit" num="enterprise" />
                <vers edition="sp1" num="enterprise" />
                <vers edition="sp1" num="enterprise_64-bit" />
                <vers edition="" num="r2" />
                <vers edition=":64-bit" num="r2" />
                <vers edition=":datacenter_64-bit" num="r2" />
                <vers edition="sp1" num="r2" />
                <vers edition="" num="standard" />
                <vers edition=":64-bit" num="standard" />
                <vers edition="sp1" num="standard" />
                <vers num="standard_64-bit" />
                <vers edition="sp1" num="web" />
            </prod>
            <prod vendor="microsoft" name="windows_98">
                <vers edition="gold" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_98se">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_me">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="sp1" num="3.5.1" />
                <vers edition="sp2" num="3.5.1" />
                <vers edition="sp3" num="3.5.1" />
                <vers edition="sp4" num="3.5.1" />
                <vers edition="sp5" num="3.5.1" />
                <vers edition="sp5:alpha" num="3.5.1" />
                <vers edition="" num="4.0" />
                <vers edition=":terminal_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":terminal_server_alpha" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":alpha" num="4.0" />
                <vers edition=":server" num="4.0" />
                <vers edition="sp1" num="4.0" />
                <vers edition="sp1:alpha" num="4.0" />
                <vers edition="sp1:workstation" num="4.0" />
                <vers edition="sp1:terminal_server" num="4.0" />
                <vers edition="sp1:server" num="4.0" />
                <vers edition="sp1:enterprise_server" num="4.0" />
                <vers edition="sp2" num="4.0" />
                <vers edition="sp2:terminal_server" num="4.0" />
                <vers edition="sp2:workstation" num="4.0" />
                <vers edition="sp2:alpha" num="4.0" />
                <vers edition="sp2:server" num="4.0" />
                <vers edition="sp2:enterprise_server" num="4.0" />
                <vers edition="sp3" num="4.0" />
                <vers edition="sp3:terminal_server" num="4.0" />
                <vers edition="sp3:alpha" num="4.0" />
                <vers edition="sp3:enterprise_server" num="4.0" />
                <vers edition="sp3:server" num="4.0" />
                <vers edition="sp3:workstation" num="4.0" />
                <vers edition="sp4" num="4.0" />
                <vers edition="sp4:enterprise_server" num="4.0" />
                <vers edition="sp4:alpha" num="4.0" />
                <vers edition="sp4:terminal_server" num="4.0" />
                <vers edition="sp4:workstation" num="4.0" />
                <vers edition="sp4:server" num="4.0" />
                <vers edition="sp5" num="4.0" />
                <vers edition="sp5:server" num="4.0" />
                <vers edition="sp5:enterprise_server" num="4.0" />
                <vers edition="sp5:alpha" num="4.0" />
                <vers edition="sp5:terminal_server" num="4.0" />
                <vers edition="sp5:workstation" num="4.0" />
                <vers edition="sp6" num="4.0" />
                <vers edition="sp6:enterprise_server" num="4.0" />
                <vers edition="sp6:server" num="4.0" />
                <vers edition="sp6:workstation" num="4.0" />
                <vers edition="sp6:terminal_server" num="4.0" />
                <vers edition="sp6:alpha" num="4.0" />
                <vers edition="sp6a" num="4.0" />
                <vers edition="sp6a:alpha" num="4.0" />
                <vers edition="sp6a:server" num="4.0" />
                <vers edition="sp6a:workstation" num="4.0" />
                <vers edition="sp6a:terminal_server" num="4.0" />
                <vers edition="sp6a:enterprise_server" num="4.0" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":64-bit" num="" />
                <vers edition=":media_center" num="" />
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:home" num="" />
                <vers edition="sp1:media_center" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:home" num="" />
                <vers edition="sp2:tablet_pc" num="" />
                <vers edition="sp2:media_center" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0002" seq="2006-0002" severity="High" type="CVE" published="2006-01-10" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" adv="1">TA06-010A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/252146" adv="1">VU#252146</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16197">16197</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded">20060110 Microsoft Outlook Critical Vulnerability</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded">20060110 Microsoft Exchange Critical Vulnerability</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx" adv="1">MS06-003</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0119" adv="1">ADV-2006-0119</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015461">1015461</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015460">1015460</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18368" adv="1">18368</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22878">win-tnef-overflow(22878)</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/331">331</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/330">330</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624" sig="1">oval:org.mitre.oval:def:624</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485" sig="1">oval:org.mitre.oval:def:1485</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456" sig="1">oval:org.mitre.oval:def:1456</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316" sig="1">oval:org.mitre.oval:def:1316</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165" sig="1">oval:org.mitre.oval:def:1165</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082" sig="1">oval:org.mitre.oval:def:1082</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="exchange_server">
                <vers edition="sp3" num="2000" />
                <vers edition="sp1" num="5.0" />
                <vers edition="sp2" num="5.0" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp3" num="5.5" />
                <vers edition="sp4" num="5.5" />
            </prod>
            <prod vendor="microsoft" name="office">
                <vers edition="sp3" num="2000" />
                <vers edition="sp1" num="2003" />
                <vers edition="sp2" num="2003" />
                <vers edition="sp3" num="xp" />
            </prod>
            <prod vendor="microsoft" name="outlook">
                <vers edition="sp3" num="2000" />
                <vers edition="sp3" num="2002" />
                <vers num="2003" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2006-0035" seq="2006-0035" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.9" modified="2008-09-05">
        <desc>
            <descript source="cve">The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="TRUSTIX" patch="1" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18482" adv="1">18482</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961" adv="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24202">kernel-afnetlink-dos(24202)</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0220">ADV-2006-0220</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="rc1" num="2.6.14" />
                <vers edition="rc2" num="2.6.14" />
                <vers edition="rc3" num="2.6.14" />
                <vers edition="rc4" num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers edition="rc1" num="2.6.15" />
                <vers edition="rc3" num="2.6.15" />
                <vers edition="rc4" num="2.6.15" />
                <vers edition="rc5" num="2.6.15" />
                <vers edition="rc6" num="2.6.15" />
                <vers edition="rc7" num="2.6.15" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0054" seq="2006-0054" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16209">16209</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18378" adv="1">18378</ref>
            <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc">FreeBSD-SA-06:04</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24073">ipfw-icmp-fragment-dos(24073)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22319">22319</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015477">1015477</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="release" num="6.0" />
                <vers edition="stable" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2006-0055" seq="2006-0055" severity="Low" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16207">16207</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18404" adv="1">18404</ref>
            <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc">FreeBSD-SA-06:02</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24074">ee-ispell-op-symlink(24074)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22320">22320</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015469">1015469</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="release" num="4.10" />
                <vers edition="release_p8" num="4.10" />
                <vers edition="releng" num="4.10" />
                <vers edition="release_p3" num="4.11" />
                <vers edition="releng" num="4.11" />
                <vers edition="stable" num="4.11" />
                <vers edition="alpha" num="5.0" />
                <vers edition="release_p14" num="5.0" />
                <vers edition="releng" num="5.0" />
                <vers edition="alpha" num="5.1" />
                <vers edition="release" num="5.1" />
                <vers edition="release_p5" num="5.1" />
                <vers edition="releng" num="5.1" />
                <vers num="5.2" />
                <vers edition="release" num="5.2.1" />
                <vers edition="releng" num="5.2.1" />
                <vers edition="release" num="5.3" />
                <vers edition="releng" num="5.3" />
                <vers edition="stable" num="5.3" />
                <vers edition="pre-release" num="5.4" />
                <vers edition="release" num="5.4" />
                <vers edition="releng" num="5.4" />
                <vers edition="release" num="6.0" />
                <vers edition="stable" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0163" seq="2006-0163" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-10-03">
        <desc>
            <descript source="cve">SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44978">phpnukeev-search-sql-injection(44978)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16186">16186</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22316">22316</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0120">ADV-2006-0120</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18394">18394</ref>
            <ref source="MISC" url="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html" adv="1">http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke_ev">
                <vers num="7.7_r1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0164" seq="2006-0164" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0123" adv="1">ADV-2006-0123</ref>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=384232">http://sourceforge.net/project/shownotes.php?release_id=384232</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18346" adv="1">18346</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24062">phgstats-php-file-include(24062)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/17469">17469</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22302">22302</ref>
        </refs>
        <vuln_soft>
            <prod vendor="woah-projekt" name="phgstats">
                <vers num="0.1" />
                <vers num="0.2" />
                <vers num="0.3" />
                <vers num="0.3.1" />
                <vers num="0.4" />
                <vers num="0.4.1" />
                <vers num="0.4.2" />
                <vers num="0.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0165" seq="2006-0165" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0126" adv="1">ADV-2006-0126</ref>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417">http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18372" adv="1">18372</ref>
            <ref source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24053">webgui-forms-xss(24053)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="plain_black" name="webgui">
                <vers num="5.5.8" />
                <vers num="6.2.10_gamma" />
                <vers num="6.2.11_gamma" />
                <vers num="6.3.0_beta" />
                <vers num="6.4.0_beta" />
                <vers num="6.5.0_beta" />
                <vers num="6.5.1_beta" />
                <vers num="6.5.2_beta" />
                <vers num="6.5.3_beta" />
                <vers num="6.5.4_gamma" />
                <vers num="6.5.5_gamma" />
                <vers num="6.5.6_gamma" />
                <vers num="6.6.0_beta" />
                <vers num="6.6.1_beta" />
                <vers num="6.6.2_gamma" />
                <vers num="6.6.3_gamma" />
                <vers num="6.6.4_gamma" />
                <vers num="6.6.5" />
                <vers num="6.7.0_beta" />
                <vers num="6.7.1_beta" />
                <vers num="6.7.2_beta" />
                <vers num="6.7.3_gamma" />
                <vers num="6.7.4_gamma" />
                <vers num="6.7.5_gamma" />
                <vers num="6.7.6_gamma" />
                <vers num="6.7.7_gamma" />
                <vers num="6.7.8_gamma" />
                <vers num="6.8.1_beta" />
                <vers num="6.8.2_beta" />
                <vers num="6.8.3_gamma" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0166" seq="2006-0166" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0143" adv="1">ADV-2006-0143</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015462">1015462</ref>
            <ref source="CONFIRM" patch="1" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18402" adv="1">18402</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24061">systemworks-nprotect-hidden(24061)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="norton_system_works">
                <vers num="2005" />
                <vers num="2005_premier" />
                <vers num="2006" />
                <vers num="2006_premier" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0167" seq="2006-0167" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24075">myphpim-login-sql-injection(24075)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24066">myphpim-calendar-sql-injection(24066)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16210">16210</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22325">22325</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22324">22324</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0147" adv="1">ADV-2006-0147</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18399" adv="1">18399</ref>
            <ref source="MISC" url="http://evuln.com/vulns/22/summary.html" adv="1">http://evuln.com/vulns/22/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="myphpim" name="myphpim">
                <vers num="01.05" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0168" seq="2006-0168" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the "Create New todo" page.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24071">myphpim-todo-xss(24071)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16210">16210</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22326">22326</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0147" adv="1">ADV-2006-0147</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18399" adv="1">18399</ref>
            <ref source="MISC" url="http://evuln.com/vulns/22/summary.html" adv="1">http://evuln.com/vulns/22/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="myphpim" name="myphpim">
                <vers num="01.05" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0169" seq="2006-0169" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24070">myphpim-addresses-file-upload(24070)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16208">16208</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421626/100/0/threaded" adv="1">20060111 [eVuln] MyPhPim Arbitrary File Upload</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0147" adv="1">ADV-2006-0147</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18399" adv="1">18399</ref>
            <ref source="MISC" url="http://evuln.com/vulns/23/summary.html">http://evuln.com/vulns/23/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="myphpim" name="myphpim">
                <vers num="01.05" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2006-0170" seq="2006-0170" type="CVE" published="2006-01-11" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0171" seq="2006-0171" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16199">16199</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421312/100/0/threaded">20060106 Orjinweb E-commerce</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24097">orjinweb-url-file-include(24097)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22387">22387</ref>
        </refs>
        <vuln_soft>
            <prod vendor="orjinweb" name="orjinweb_e-commerce">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" name="CVE-2006-0172" seq="2006-0172" severity="Low" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="3.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0145" adv="1">ADV-2006-0145</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" adv="1">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
            <ref source="MISC" url="http://www.securenetwork.it/advisories/sn-2006-01.html" adv="1">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18411" adv="1">18411</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24067">hummingbird-enterprise-xss(24067)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hummingbird" name="enterprise_collaboration">
                <vers num="5.2" />
                <vers num="5.21" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" name="CVE-2006-0173" seq="2006-0173" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0145" adv="1">ADV-2006-0145</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" adv="1">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
            <ref source="MISC" url="http://www.securenetwork.it/advisories/sn-2006-01.html" adv="1">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18411" adv="1">18411</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24068">hummingbird-enterprise-file-download(24068)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hummingbird" name="enterprise_collaboration">
                <vers num="5.2" />
                <vers num="5.21" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" name="CVE-2006-0174" seq="2006-0174" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
            <ref source="MISC" url="http://www.securenetwork.it/advisories/sn-2006-01.html">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24069">hummingbird-enterprise-information-disclosure(24069)</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/328">328</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hummingbird" name="collaboration">
                <vers num="5.2" />
                <vers num="5.21" prev="1" />
            </prod>
            <prod vendor="hummingbird" name="enterprise_collaboration">
                <vers num="5.2" />
                <vers num="5.21" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0175" seq="2006-0175" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16196">16196</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421615/100/0/threaded">20060111 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34(search_form.asp)</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html">20060109 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24048">webwizforums-searchform-xss(24048)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22398">22398</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0176" seq="2006-0176" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16203">16203</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421849/100/0/threaded">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24102">xmame-multiple-parameters-bo(24102)</ref>
            <ref source="CONFIRM" url="http://x.mame.net/changes-unix.html">http://x.mame.net/changes-unix.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xmame" name="xmame">
                <vers num="0.102" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0177" seq="2006-0177" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16205">16205</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html">20060110 SUID root overflows in UNICOS and partial shellcode</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24276">unicos-command-line-bo(24276)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cray" name="unicos">
                <vers num="9.0.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0178" seq="2006-0178" severity="High" type="CVE" published="2006-01-11" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16205">16205</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html">20060110 SUID root overflows in UNICOS and partial shellcode</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24277">unicos-ftp-format-string(24277)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cray" name="unicos">
                <vers num="9.0.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0179" seq="2006-0179" severity="Medium" type="CVE" published="2006-01-11" CVSS_version="2.0" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0202" adv="1">ADV-2006-0202</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015488">1015488</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18479" adv="1">18479</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24117">cisco-ipphone-synflood-dos(24117)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16200">16200</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22469">22469</ref>
            <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml" adv="1">20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com</ref>
            <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl">http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ip_phone_7940">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0180" seq="2006-0180" severity="Medium" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16206">16206</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0149" adv="1">ADV-2006-0149</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18417" adv="1">18417</ref>
            <ref source="MISC" url="http://evuln.com/vulns/24/summary.html" adv="1">http://evuln.com/vulns/24/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24077">calogic-newevent-xss(24077)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422163/100/0/threaded">20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22322">22322</ref>
        </refs>
        <vuln_soft>
            <prod vendor="calogic" name="calogic_calendars">
                <vers num="1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0181" seq="2006-0181" severity="High" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16211">16211</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml" adv="1">20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24065">cisco-csmars-default-password(24065)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22346">22346</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0154">ADV-2006-0154</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015471">1015471</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/335">335</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18424">18424</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="cs-mars">
                <vers num="4.1" />
                <vers num="4.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0182" seq="2006-0182" severity="High" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0152" adv="1">ADV-2006-0152</ref>
            <ref source="MISC" url="http://evuln.com/vulns/25/summary.html" adv="1">http://evuln.com/vulns/25/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24104">acal-login-auth-bypass(24104)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22344">22344</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/343">343</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18432">18432</ref>
        </refs>
        <vuln_soft>
            <prod vendor="acal" name="calendar_project">
                <vers num="2.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2006-0183" seq="2006-0183" severity="Medium" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="6.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0152" adv="1">ADV-2006-0152</ref>
            <ref source="MISC" url="http://evuln.com/vulns/25/summary.html" adv="1">http://evuln.com/vulns/25/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24107">acal-header-footer-code-execute(24107)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22345">22345</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/343">343</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18432">18432</ref>
        </refs>
        <vuln_soft>
            <prod vendor="acal" name="calendar_project">
                <vers num="2.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0184" seq="2006-0184" severity="High" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0146" adv="1">ADV-2006-0146</ref>
            <ref source="MISC" url="http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt" adv="1">http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18408" adv="1">18408</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24072">asptopsites-goto-sql-injection(24072)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22330">22330</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html">20060110 AspTopSites SQL injection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mainenet_enterprises" name="asptopsites">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0185" seq="2006-0185" severity="Medium" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16192">16192</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421322">20060107 Php-Nuke Pool and News Module IMG Tag Cross Site</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0125" adv="1">ADV-2006-0125</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18374" adv="1">18374</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php-nuke" name="news_module">
                <vers num="" />
            </prod>
            <prod vendor="php-nuke" name="pool_module">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2006-0186" seq="2006-0186" type="CVE" published="2006-01-12" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <vuln_types>
            <input />
        </vuln_types>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2006-0187" seq="2006-0187" severity="Medium" type="CVE" published="2006-01-12" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16225">16225</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421943/100/0/threaded">20060113 Visual Studio Remote Code Execution</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0151" adv="1">ADV-2006-0151</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18409" adv="1">18409</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24116">visualstudio-usercontrol-code-execution(24116)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="visual_studio_.net">
                <vers num="2005" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0189" seq="2006-0189" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.</descript>
        </desc>
        <sols>
            <sol source="nvd">This is the vendor provided solution:

"eStara has released Softphone version 3.0.1.47 to resolve the buffer overflow demonstrated in parsing SDP with long "a=" lines.  Licensed customers can download a new version via the email sent to them with purchase, customers testing may go back to http://www.estara.com/softphone/ to obtain a new free trial.   Version information can be gathered by going to Help->About.  eStara highly recommends all customers upgrade to avoid this issue.  If there's further questions please email us: softphone@estara.com.
 
eStara would like to thank ZwelL for bringing the issue to our attention."</sol>
        </sols>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24090">estara-sip-sdp-bo(24090)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16213">16213</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421596/100/0/threaded" adv="1">20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0167">ADV-2006-0167</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015481">1015481</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18410">18410</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22348">22348</ref>
        </refs>
        <vuln_soft>
            <prod vendor="estara" name="softphone">
                <vers num="3.0.1.14" />
                <vers num="3.0.1.46" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0190" seq="2006-0190" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0165" adv="1">ADV-2006-0165</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1" adv="1">102066</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18421" adv="1">18421</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24084">solaris-unspecified-root-access(24084)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16224">16224</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015478">1015478</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:702" sig="1">oval:org.mitre.oval:def:702</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="10.0" />
                <vers edition=":sparc" num="10.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2006-0191" seq="2006-0191" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.9" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0166" adv="1">ADV-2006-0166</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1" adv="1">102108</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18420" adv="1">18420</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24085">solaris-find-proc-dos(24085)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16222">16222</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22347">22347</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015479">1015479</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1608" sig="1">oval:org.mitre.oval:def:1608</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="10.0" />
                <vers edition=":sparc" num="10.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0192" seq="2006-0192" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24087">aspsurvey-loginvalidate-sql-injection(24087)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16496">16496</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423949/100/0/threaded">20060204 sql injection in ASP Survey</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22342">22342</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0164" adv="1">ADV-2006-0164</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18422" adv="1">18422</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/414">414</ref>
        </refs>
        <vuln_soft>
            <prod vendor="philip_loftin" name="aspsurvey">
                <vers num="1.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0193" seq="2006-0193" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/421704/100/0/threaded" adv="1">20060112 H-Sphere Security Vulnerability</ref>
            <ref source="CONFIRM" url="http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r">http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24096">hsphere-login-xss(24096)</ref>
            <ref source="CONFIRM" url="http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r">http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22372">22372</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0172">ADV-2006-0172</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18447">18447</ref>
        </refs>
        <vuln_soft>
            <prod vendor="positive_software" name="h-sphere">
                <vers num="2.4.1" />
                <vers num="2.4.1_patch_1" />
                <vers num="2.4.1_patch_2" />
                <vers num="2.4.1_patch_3" />
                <vers num="2.4.1_patch_4" />
                <vers num="2.4.1_patch_5" />
                <vers num="2.4.1_patch_6" />
                <vers num="2.4.1_patch_7" />
                <vers num="2.4.2" />
                <vers num="2.4.2_beta_1" />
                <vers num="2.4.2_beta_2" />
                <vers num="2.4.2_beta_3" />
                <vers num="2.4.2_patch_1" />
                <vers num="2.4.2_patch_2" />
                <vers num="2.4.2_patch_3" />
                <vers num="2.4.2_patch_4" />
                <vers num="2.4.2_patch_5" />
                <vers num="2.4.2_rc1" />
                <vers num="2.4.2_rc2" />
                <vers num="2.4.3" />
                <vers num="2.4.3_beta_1" />
                <vers num="2.4.3_beta_2" />
                <vers num="2.4.3_patch_1" />
                <vers num="2.4.3_patch_2" />
                <vers num="2.4.3_patch_3" />
                <vers num="2.4.3_patch_4" />
                <vers num="2.4.3_patch_5" />
                <vers num="2.4.3_patch_6" />
                <vers num="2.4.3_patch_7" />
                <vers num="2.4.3_patch_8" />
                <vers num="2.4.3_rc1" />
                <vers num="2.4.3_rc2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0194" seq="2006-0194" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16216">16216</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421729/100/0/threaded" adv="1">20060112 FogBugz Cross Site Scripting Vulnerability</ref>
            <ref source="CONFIRM" url="http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html">http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24103">fogbugz-login-xss(24103)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22370">22370</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0174">ADV-2006-0174</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18443">18443</ref>
        </refs>
        <vuln_soft>
            <prod vendor="fog_creek_software" name="fogbugz">
                <vers num="4.029" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0196" seq="2006-0196" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24082">slsnif-home-bo(24082)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421583/100/0/threaded">20060111 Serial Line Sniffer 0.4.4 Buffer Overflow</ref>
            <ref source="MISC" url="http://shellcoders.com/sintigan/slsnif-ploit.pl">http://shellcoders.com/sintigan/slsnif-ploit.pl</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0212">ADV-2006-0212</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18497">18497</ref>
        </refs>
        <vuln_soft>
            <prod vendor="serial_line_sniffer" name="serial_line_sniffer">
                <vers num="0.4.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0197" seq="2006-0197" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded" adv="1">20060108 xorg server 6.8.2 and below on 64bit arch</ref>
        </refs>
        <vuln_soft>
            <prod vendor="x.org" name="x.org">
                <vers num="6.8.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0198" seq="2006-0198" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481" adv="1">http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16189">16189</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded">20060107 Xoops Pool Module IMG Tag Cross Site Scripting</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24091">xoops-pool-imagetag-xss(24091)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xoops" name="xoops_pool_module">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0199" seq="2006-0199" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24098">mininuke-news-sql-injection(24098)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421727/100/0/threaded" adv="1">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injectionvulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22384">22384</ref>
            <ref source="MISC" url="http://www.nukedx.com/?viewdoc=7">http://www.nukedx.com/?viewdoc=7</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0173" adv="1">ADV-2006-0173</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18439" adv="1">18439</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/340">340</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mini-nuke" name="cms_system">
                <vers num="1.8.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2006-0200" seq="2006-0200" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0" CVSS_score="9.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/24095">php-extmysqli-format-string(24095)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16219">16219</ref>
            <ref source="CONFIRM" patch="1" url="http://www.php.net/release_5_1_2.php">http://www.php.net/release_5_1_2.php</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0177" adv="1">ADV-2006-0177</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18431" adv="1">18431</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421705/100/0/threaded" adv="1">20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability</ref>
            <ref source="MISC" url="http://www.hardened-php.net/advisory_022006.113.html" adv="1">http://www.hardened-php.net/advisory_022006.113.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015485">1015485</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/337">337</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="5.1" />
                <vers num="5.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0201" seq="2006-0201" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0183" adv="1">ADV-2006-0183</ref>
            <ref source="MISC" url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" adv="1">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16218">16218</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421739" adv="1">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18444" adv="1">18444</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22378">22378</ref>
        </refs>
        <vuln_soft>
            <prod vendor="paypal" name="php_toolkit">
                <vers num="0.50" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-2006-0202" seq="2006-0202" severity="Low" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="3.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0183" adv="1">ADV-2006-0183</ref>
            <ref source="MISC" url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" adv="1">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16218">16218</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421739" adv="1">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18444" adv="1">18444</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22379">22379</ref>
        </refs>
        <vuln_soft>
            <prod vendor="paypal" name="php_toolkit">
                <vers num="0.50" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0203" seq="2006-0203" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24101">mininuke-membership-change-password(24101)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421748/100/0/threaded" adv="1">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remoteuser password change exploit</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22385">22385</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0173" adv="1">ADV-2006-0173</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18439" adv="1">18439</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remote user password change exploit</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html" adv="1">20060129 [xpl#2] MiniNuke 1.8.2 - change member's passwrod &lt; Perl ></ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/344">344</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mini-nuke" name="cms_system">
                <vers num="1.8.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0204" seq="2006-0204" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24106">wordcircle-index-xss(24106)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16227">16227</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" adv="1">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22359">22359</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0185" adv="1">ADV-2006-0185</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18440" adv="1">18440</ref>
            <ref source="MISC" url="http://evuln.com/vulns/28/summary.html" adv="1">http://evuln.com/vulns/28/summary.html</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/345">345</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wordcircle" name="wordcircle">
                <vers num="2.17" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2006-0205" seq="2006-0205" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24108">wordcircle-login-security-bypass(24108)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24105">wordcircle-sql-injection(24105)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16227">16227</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421745/100/0/threaded" adv="1">20060112 [eVuln] Wordcircle Authentication Bypass</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22358">22358</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0185" adv="1">ADV-2006-0185</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18440" adv="1">18440</ref>
            <ref source="MISC" url="http://evuln.com/vulns/28/summary.html">http://evuln.com/vulns/28/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/27/summary.html">http://evuln.com/vulns/27/summary.html</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/346">346</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/345">345</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wordcircle" name="wordcircle">
                <vers num="2.17" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0206" seq="2006-0206" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16229">16229</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18450" adv="1">18450</ref>
            <ref source="MISC" url="http://evuln.com/vulns/29/summary.html" adv="1">http://evuln.com/vulns/29/summary.html</ref>
            <ref source="MISC" url="http://evuln.com/vulns/29/exploit.html">http://evuln.com/vulns/29/exploit.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24110">lwc-cal-execute-code(24110)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22376">22376</ref>
            <ref source="VIM" url="http://attrition.org/pipermail/vim/2006-March/000612.html">20060318 Source VERIFY - Light Weight Calendar issue is eval injection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="light_weight_calendar" name="light_weight_calendar">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0207" seq="2006-0207" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/24094">php-session-response-splitting(24094)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16220">16220</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" adv="1">GLSA-200603-22</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0369" adv="1">ADV-2006-0369</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0177" adv="1">ADV-2006-0177</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015484" adv="1">1015484</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19355" adv="1">19355</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19179" adv="1">19179</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18697" adv="1">18697</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18431" adv="1">18431</ref>
            <ref source="MANDRIVA" patch="1" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:028" adv="1">MDKSA-2006:028</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1">USN-261-1</ref>
            <ref source="CONFIRM" url="http://www.php.net/release_5_1_2.php">http://www.php.net/release_5_1_2.php</ref>
            <ref source="MISC" url="http://www.hardened-php.net/advisory_012006.112.html" adv="1">http://www.hardened-php.net/advisory_012006.112.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19012" adv="1">19012</ref>
            <ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1331">DSA-1331</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25945">25945</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="rc1" num="5.0" />
                <vers edition="rc2" num="5.0" />
                <vers edition="rc3" num="5.0" />
                <vers num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1" />
                <vers num="5.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2006-0208" seq="2006-0208" severity="Low" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="2.6" modified="2009-01-07">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16803">16803</ref>
            <ref source="CONFIRM" patch="1" url="http://www.php.net/release_5_1_2.php">http://www.php.net/release_5_1_2.php</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" adv="1">GLSA-200603-22</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0369" adv="1">ADV-2006-0369</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0177" adv="1">ADV-2006-0177</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19355" adv="1">19355</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/19179" adv="1">19179</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18697" adv="1">18697</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18431" adv="1">18431</ref>
            <ref source="MANDRIVA" patch="1" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:028" adv="1">MDKSA-2006:028</ref>
            <ref source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1">USN-261-1</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-4.php#4.4.2">http://www.php.net/ChangeLog-4.php#4.4.2</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19012" adv="1">19012</ref>
            <ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0501.html">RHSA-2006:0501</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/2685">ADV-2006-2685</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21564">21564</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21252">21252</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20951">20951</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20222">20222</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20210">20210</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19832">19832</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0549.html">RHSA-2006:0549</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0276.html">RHSA-2006:0276</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">20060501-01-U</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="beta1" num="4.0" />
                <vers edition="beta2" num="4.0" />
                <vers edition="beta3" num="4.0" />
                <vers edition="beta4" num="4.0" />
                <vers edition="beta_4_patch1" num="4.0" />
                <vers edition="rc1" num="4.0" />
                <vers edition="rc2" num="4.0" />
                <vers num="4.0.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.3" />
                <vers num="4.3.1" />
                <vers num="4.3.10" />
                <vers num="4.3.11" />
                <vers num="4.3.2" />
                <vers num="4.3.3" />
                <vers num="4.3.4" />
                <vers num="4.3.5" />
                <vers num="4.3.6" />
                <vers num="4.3.7" />
                <vers num="4.3.8" />
                <vers num="4.3.9" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0209" seq="2006-0209" severity="High" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0153" adv="1">ADV-2006-0153</ref>
            <ref source="MISC" url="http://evuln.com/vulns/26/summary.html">http://evuln.com/vulns/26/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24080">tanklogger-generalfunctions-sql-injection(24080)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16228">16228</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421743/100/0/threaded">20060112 [eVuln] TankLogger SQL Injection Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22369">22369</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22368">22368</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/341">341</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18441">18441</ref>
            <ref source="VIM" url="http://attrition.org/pipermail/vim/2006-January/000480.html">20060113 Verified TankLogger SQl inject by source inspection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tanklogger" name="tanklogger">
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0210" seq="2006-0210" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16214">16214</ref>
            <ref source="CONFIRM" url="http://www.interspire.com/forum/showthread.php?p=29606">http://www.interspire.com/forum/showthread.php?p=29606</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24112">trackpointnx-login-xss(24112)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421740/100/0/threaded">20060112 Interspire TrackPoint NX XSS Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22377">22377</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0175">ADV-2006-0175</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18445">18445</ref>
        </refs>
        <vuln_soft>
            <prod vendor="interspire" name="trackpoint_nx">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0211" seq="2006-0211" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421791/100/0/threaded">20060112 Helm XSS Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24139">helm-forgotpassword-xss(24139)</ref>
            <ref source="CONFIRM" url="http://www.webhostautomation.com/webhost-301">http://www.webhostautomation.com/webhost-301</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16234">16234</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22454">22454</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0203">ADV-2006-0203</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18492">18492</ref>
        </refs>
        <vuln_soft>
            <prod vendor="helm_hosting" name="helm_hosting_control_panel">
                <vers num="3.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0212" seq="2006-0212" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16236">16236</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0184" adv="1">ADV-2006-0184</ref>
            <ref source="MISC" url="http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt" adv="1">http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18437" adv="1">18437</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2" adv="1">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2" adv="1">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421993/100/0/threaded">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22380">22380</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015486">1015486</ref>
            <ref source="MISC" url="http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2">http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="toshiba" name="bluetooth_stack">
                <vers num="3.00.11" />
                <vers num="3.00.12" />
                <vers num="3.00.31a" />
                <vers num="3.00.32" />
                <vers num="3.01.03" />
                <vers num="3.10.00" />
                <vers num="3.20.00" />
                <vers num="3.20.01" />
                <vers num="3.20.02" />
                <vers num="3.20.04" />
                <vers num="4.00.01t" />
                <vers num="4.00.11" />
                <vers num="4.00.23t" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2006-0213" seq="2006-0213" severity="Medium" type="CVE" published="2006-01-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0186" adv="1">ADV-2006-0186</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18438" adv="1">18438</ref>
            <ref source="CONFIRM" patch="1" url="http://kolab.org/security/kolab-vendor-notice-08.txt" adv="1">http://kolab.org/security/kolab-vendor-notice-08.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24123">kolab-smtp-logging(24123)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22381">22381</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kolab" name="kolab_groupware_server">
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2005-12-15_pre2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0214" seq="2006-0214" severity="High" type="CVE" published="2006-01-15" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-20">
        <desc>
            <descript source="cve">Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24136">ezdatabase-visitorupload-file-include(24136)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16237">16237</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/351">351</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18043">18043</ref>
            <ref source="MISC" url="http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html">http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="indexcor" name="ezdatabase">
                <vers num="2.0" />
                <vers num="2.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0215" seq="2006-0215" severity="Medium" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.  NOTE: this issue might be resultant from CVE-2006-0216.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22352">22352</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22352-qualityppc.txt" adv="1">http://osvdb.org/ref/22/22352-qualityppc.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="qualityebiz" name="quality_ppc">
                <vers num="1.0_build_1644" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0216" seq="2006-0216" severity="Medium" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to obtain sensitive information, possibly the installation path of the application, via unspecified "meta characters" to the cpage parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/22353">22353</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22353-qualityppc.txt">http://osvdb.org/ref/22/22353-qualityppc.txt</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22352-qualityppc.txt">http://osvdb.org/ref/22/22352-qualityppc.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="qualityebiz" name="quality_ppc">
                <vers num="1.0_build_1644" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0217" seq="2006-0217" severity="Medium" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16239">16239</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22444">22444</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22443">22443</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0187">ADV-2006-0187</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18477" adv="1">18477</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0517.html">20060115 Ultimate Auction &lt;=3.67</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24138">ultimate-auction-item-xss(24138)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16254">16254</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ultimate_auction" name="ultimate_auction">
                <vers num="3.67" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0218" seq="2006-0218" severity="High" type="CVE" published="2006-01-16" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection.  NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603.  However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://community.mybboard.net/showthread.php?tid=5852" adv="1">http://community.mybboard.net/showthread.php?tid=5852</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0219" seq="2006-0219" severity="High" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://community.mybboard.net/showthread.php?tid=5960">http://community.mybboard.net/showthread.php?tid=5960</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16230">16230</ref>
            <ref source="MISC" url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151">http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151</ref>
            <ref source="MISC" url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088">http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24115">mybb-usercp-script-sql-injection(24115)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mybulletinboard" name="mybulletinboard">
                <vers num="1.0.2" />
                <vers num="1.01" />
                <vers num="1.0_final" />
                <vers num="1.0_preview_release_2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0220" seq="2006-0220" severity="Medium" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16232">16232</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421914/100/0/threaded">20060113 DCP Portal Cross-Site Scripting Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24153">dcpportal-calendar-search-xss(24153)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="codeworx_technologies" name="dcp-portal">
                <vers num="5.3" />
                <vers num="5.3.1" />
                <vers num="5.3.2" />
                <vers num="6.0" />
                <vers num="6.1" />
                <vers num="6.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0221" seq="2006-0221" severity="High" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24266">cm3-login-sql-injection(24266)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16231">16231</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421941/100/0/threaded">20060113 DDSN CMS Admin Panel SQL Injection Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22696">22696</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ddsn" name="cm3cms">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0222" seq="2006-0222" severity="Medium" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24235">template-seller-fullview-xss(24235)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16233">16233</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421916/100/0/threaded">20060113 AlstraSoft Template Seller Pro Cross-Site Scripting Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22746">22746</ref>
        </refs>
        <vuln_soft>
            <prod vendor="alstrasoft" name="template_seller">
                <vers edition=":pro" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0223" seq="2006-0223" severity="Medium" type="CVE" published="2006-01-16" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16235">16235</ref>
            <ref source="MISC" patch="1" url="http://www.123flashchat.com/flash-chat-server-v512.html">http://www.123flashchat.com/flash-chat-server-v512.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22440">22440</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0198">ADV-2006-0198</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18455">18455</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24137">123flashchat-user-directory-traversal(24137)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="topcmm_computing" name="123_flash_chat_server">
                <vers num="5.0" />
                <vers num="5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" name="CVE-2006-0227" seq="2006-0227" severity="Low" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0200" adv="1">ADV-2006-0200</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1">102033</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015492">1015492</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18498" adv="1">18498</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24127">solaris-lpsched-dos(24127)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16245">16245</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22442">22442</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22441">22441</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:662" sig="1">oval:org.mitre.oval:def:662</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="10.0" />
                <vers edition=":x86" num="10.0" />
                <vers edition=":sparc" num="10.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers num="9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0228" seq="2006-0228" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16261">16261</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0199" adv="1">ADV-2006-0199</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18458" adv="1">18458</ref>
            <ref source="CONFIRM" url="http://www.grsecurity.org/news.php#grsec218">http://www.grsecurity.org/news.php#grsec218</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24156">grsecurity-rbac-admin-privileges(24156)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="grsecurity" name="grsecurity_kernel_patch">
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.1.0" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2006-0229" seq="2006-0229" severity="Low" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when Wehntrust creates the autostart key.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/422046/100/0/threaded">20060116 Re: [Full-disclosure] WehnTrust - When you have to trust Wehntrust</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16268">16268</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422020/100/0/threaded">20060116 WehnTrust - When you have to trust Wehntrust</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24315">wehntrust-service-start-file-execution(24315)</ref>
            <ref source="MISC" url="http://www.wehnus.com/downloads.pl">http://www.wehnus.com/downloads.pl</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wehnus" name="wehntrust">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0233" seq="2006-0233" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24140">microblog-functions-xss(24140)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16272">16272</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422145/100/0/threaded" adv="1">20060117 [eVuln] microBlog BBCode XSS Vulnerability</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015496">1015496</ref>
            <ref source="MISC" url="http://evuln.com/vulns/36/summary.html">http://evuln.com/vulns/36/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microblog" name="microblog">
                <vers num="2.0_rc10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0234" seq="2006-0234" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16270">16270</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422141/100/0/threaded" adv="1">20060117 [eVuln] microBlog SQL Injection Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24132">microblog-index-sql-injection(24132)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22512">22512</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0239">ADV-2006-0239</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015496">1015496</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18442">18442</ref>
            <ref source="MISC" url="http://evuln.com/vulns/35/summary.html">http://evuln.com/vulns/35/summary.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microblog" name="microblog">
                <vers num="2.0_rc10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0235" seq="2006-0235" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16247">16247</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422105/100/0/threaded" adv="1">20060116 White Album Sql &amp;#304;njection biyosecurity.be</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24271">whitealbum-pictures-sql-injection(24271)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22520">22520</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0241">ADV-2006-0241</ref>
            <ref source="MISC" url="http://www.biyosecurity.be/bugs/whitealbum.txt">http://www.biyosecurity.be/bugs/whitealbum.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18460">18460</ref>
        </refs>
        <vuln_soft>
            <prod vendor="white_angle" name="white_album">
                <vers num="2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2006-0236" seq="2006-0236" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16271">16271</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/422148/100/0/threaded" adv="1">20060117 Secunia Research: Mozilla Thunderbird Attachment SpoofingVulnerability</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0230" adv="1">ADV-2006-0230</ref>
            <ref source="MISC" patch="1" url="http://secunia.com/secunia_research/2005-22/advisory" adv="1">http://secunia.com/secunia_research/2005-22/advisory</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/15907" adv="1">15907</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=300246">https://bugzilla.mozilla.org/show_bug.cgi?id=300246</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:021">MDKSA-2006:021</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24164">thunderbird-attachment-ext-spoofing(24164)</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:021">MDKSA-2006:021</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="thunderbird">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers edition="beta2" num="1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0237" seq="2006-0237" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16255">16255</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0214" adv="1">ADV-2006-0214</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18470" adv="1">18470</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24150">gtpicommerce-index-xss(24150)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gtp" name="icommerce">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0238" seq="2006-0238" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.lesterchan.net/blogs/">http://www.lesterchan.net/blogs/</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18471" adv="1">18471</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16241">16241</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0192" adv="1">ADV-2006-0192</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24163">wpstats-script-sql-injection(24163)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22450">22450</ref>
            <ref source="CONFIRM" url="http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability">http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22450-wpstats.txt">http://osvdb.org/ref/22/22450-wpstats.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gamerz" name="wp-stats">
                <vers num="2.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" name="CVE-2006-0239" seq="2006-0239" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16243">16243</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422102/100/0/threaded">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0194" adv="1">ADV-2006-0194</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18488" adv="1">18488</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24154">simpleblog-comment-xss(24154)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22448">22448</ref>
            <ref source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=21926">http://www.hackerscenter.com/archive/view.asp?id=21926</ref>
        </refs>
        <vuln_soft>
            <prod vendor="8pixel.net" name="simple_blog">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0240" seq="2006-0240" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24155">simpleblog-month-sql-injection(24155)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16243">16243</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422102/100/0/threaded" adv="1">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22447">22447</ref>
            <ref source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=21926">http://www.hackerscenter.com/archive/view.asp?id=21926</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0194" adv="1">ADV-2006-0194</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18488" adv="1">18488</ref>
        </refs>
        <vuln_soft>
            <prod vendor="8pixel.net" name="simple_blog">
                <vers num="2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0241" seq="2006-0241" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16277">16277</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422133/100/0/threaded">20060117 XSS in WBNews &lt; = v1.1.0</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0237">ADV-2006-0237</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18499">18499</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webmobo" name="wbnews">
                <vers num="1.1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2006-0242" seq="2006-0242" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="6.4" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/archive/1/422124/100/0/threaded">20060117 IndonesiaHack Advisory HTML injection in PHP Fusebox</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16274">16274</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/355">355</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php_fusebox" name="php_fusebox">
                <vers num="4.0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0243" seq="2006-0243" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16281">16281</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0229" adv="1">ADV-2006-0229</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18454" adv="1">18454</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24187">smbcms-sitesearch-xss(24187)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22494">22494</ref>
        </refs>
        <vuln_soft>
            <prod vendor="smbcms" name="smbcms">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0244" seq="2006-0244" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16263">16263</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422158/100/0/threaded">20060116 Re: Directory traversal in phpXplorer</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421997/100/0/threaded" adv="1">20060116 Directory traversal in phpXplorer</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0232" adv="1">ADV-2006-0232</ref>
            <ref source="MISC" url="http://www.arrelnet.com/advisories/adv20060116.html" adv="1">http://www.arrelnet.com/advisories/adv20060116.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18518" adv="1">18518</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39982">phpxplorer-sshare-directory-traversal(39982)</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/353">353</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpxplorer" name="phpxplorer">
                <vers num="0.9.33" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0245" seq="2006-0245" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php.  NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16259">16259</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22471">22471</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0227" adv="1">ADV-2006-0227</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18519" adv="1">18519</ref>
            <ref source="MISC" url="http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html" adv="1">http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html</ref>
            <ref source="MISC" url="http://bugs.cubecart.com/?do=details&amp;id=459" adv="1">http://bugs.cubecart.com/?do=details&amp;id=459</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24177">cubecart-index-script-xss(24177)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="devellion" name="cubecart">
                <vers num="3.0.7-pl1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0246" seq="2006-0246" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16265">16265</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22462">22462</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0213" adv="1">ADV-2006-0213</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18472" adv="1">18472</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22462-widexl.txt">http://osvdb.org/ref/22/22462-widexl.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24161">downloadtracker-down-xss(24161)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="widexl" name="download_tracker">
                <vers num="1.0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0247" seq="2006-0247" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16264">16264</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22461">22461</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0188" adv="1">ADV-2006-0188</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18469" adv="1">18469</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22461-anyboard.txt">http://osvdb.org/ref/22/22461-anyboard.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24167">netbula-anyboard-script-xss(24167)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netbula" name="anyboard">
                <vers num="9.9.5.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0248" seq="2006-0248" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0218" adv="1">ADV-2006-0218</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18483" adv="1">18483</ref>
            <ref source="MISC" url="http://blog.globalnetworks.gr/?p=4">http://blog.globalnetworks.gr/?p=4</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24304">virata-emweb-unauth-access(24304)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intracom" name="jetspeed">
                <vers num="500" />
                <vers num="520" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0249" seq="2006-0249" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16249">16249</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22463">22463</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0191" adv="1">ADV-2006-0191</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015493">1015493</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18504" adv="1">18504</ref>
            <ref source="MISC" url="http://evuln.com/vulns/33/summary.html">http://evuln.com/vulns/33/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24146">geoBlog-viewcat-sql-injection(24146)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bitdamaged" name="geoblog">
                <vers num="mod_1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2006-0250" seq="2006-0250" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="6.4" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16267">16267</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422086/100/0/threaded">20060116 Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad Format String Vulnerability</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0234" adv="1">ADV-2006-0234</ref>
            <ref source="MISC" url="http://www.digitalarmaments.com/2006040164883273.html">http://www.digitalarmaments.com/2006040164883273.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18525" adv="1">18525</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24178">cmusnmp-snmpinput-format-string(24178)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22493">22493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="carnegie_mellon_university" name="snmptrapd">
                <vers num="3.6" />
                <vers num="3.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0251" seq="2006-0251" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16251">16251</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22439">22439</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0189" adv="1">ADV-2006-0189</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18468" adv="1">18468</ref>
            <ref source="MISC" url="http://osvdb.org/ref/22/22439-faqomatic.txt">http://osvdb.org/ref/22/22439-faqomatic.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24165">faqomatic-fom-xss(24165)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="faq-o-matic" name="faq-o-matic">
                <vers num="2.711" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0252" seq="2006-0252" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16242" adv="1">16242</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422052/100/0/threaded" adv="1">20060115 [eVuln] Benders Calendar SQL Injection</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22449">22449</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0190" adv="1">ADV-2006-0190</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015491" adv="1">1015491</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18462" adv="1">18462</ref>
            <ref source="MISC" url="http://evuln.com/vulns/30/summary.html" adv="1">http://evuln.com/vulns/30/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24120">benderscalendar-sql-injection(24120)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="benders_calendar" name="benders_calendar">
                <vers num="1.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2006-0253" seq="2006-0253" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the Bluetooth OBEX Object Push service in "Blue Neighbors.EXE" in AmbiCom Blue Neighbors 2.50 Build 2500 and earlier allows remote attackers to execute arbitrary code via a long file name, as demonstrated via a long RFILE argument to ussp-push.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422481/100/0/threaded">20060120 DMA[2006-0115a] - 'AmbiCom Bluetooth Object Push Overflow'</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0219" adv="1">ADV-2006-0219</ref>
            <ref source="MISC" url="http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt">http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18466" adv="1">18466</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24179">ambicom-bluetooth-objectpush-bo(24179)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16258">16258</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/366">366</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ambicom" name="blue_neighbors">
                <vers num="2.50_build_2500" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0254" seq="2006-0254" severity="Medium" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create">https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create</ref>
            <ref source="CONFIRM" url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create">https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16260">16260</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421996/100/0/threaded" adv="1">20060115 Apache Geronimo 1.0 - CSS and persistent HTML-Injectionvulnerabilities</ref>
            <ref source="MISC" url="http://www.oliverkarow.de/research/geronimo_css.txt" adv="1">http://www.oliverkarow.de/research/geronimo_css.txt</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0217" adv="1">ADV-2006-0217</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18485" adv="1">18485</ref>
            <ref source="MISC" url="http://issues.apache.org/jira/browse/GERONIMO-1474" adv="1">http://issues.apache.org/jira/browse/GERONIMO-1474</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24159">geronimo-webaccesslog-viewer-xss(24159)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24158">geronimo-jspexamples-xss(24158)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31493">31493</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0630.html">RHSA-2008:0630</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="geronimo">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-0255" seq="2006-0255" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16290">16290</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422263/100/0/threaded">20060117 [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0258" adv="1">ADV-2006-0258</ref>
            <ref source="MISC" url="http://secdev.zoller.lu/research/checkpoint.txt">http://secdev.zoller.lu/research/checkpoint.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="checkpoint" name="vpn-1">
                <vers edition=":fp1" num="" />
                <vers edition="sp1" num="4.1" />
                <vers edition="sp2" num="4.1" />
                <vers edition="sp3" num="4.1" />
                <vers edition="sp4" num="4.1" />
                <vers edition="sp5" num="4.1" />
                <vers edition="sp5a" num="4.1" />
                <vers edition="sp6" num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0044" seq="2006-0044" severity="High" type="CVE" published="2006-01-17" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the "handling of submitted form fields".</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0196" adv="1">ADV-2006-0196</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-942" adv="1">DSA-942</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18457" adv="1">18457</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16252">16252</ref>
            <ref source="CONFIRM" url="http://www.object-craft.com.au/projects/albatross/news.html">http://www.object-craft.com.au/projects/albatross/news.html</ref>
            <ref source="MISC" url="http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz">http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24130">albatross-context-command-execution(24130)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22451">22451</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18496">18496</ref>
        </refs>
        <vuln_soft>
            <prod vendor="albatross" name="albatross">
                <vers num="1.00" />
                <vers num="1.01" />
                <vers num="1.10" />
                <vers num="1.20" />
                <vers num="1.30" />
                <vers num="1.32" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0256" seq="2006-0256" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.3" />
                <vers num="8.1.7.4" />
                <vers num="9.0.1.5" />
                <vers num="9.2.0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0257" seq="2006-0257" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015499" adv="1">1015499</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22540">22540</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="10.2.0.1" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0258" seq="2006-0258" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="8.1.7.4" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" severity="High" CVSS_version="2.0" type="CVE" modified="2008-09-05" name="CVE-2006-0259" seq="2006-0259" published="2006-01-18" discovered="2006-01-17" CVSS_score="10.0">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22544">22544</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0260" seq="2006-0260" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMS_METADATA_UTIL package; (g) MAKE_FILTER, FETCH_VIEWS_ERROR, FETCH_FILTERS, FETCH_VIEWS, SET_FILTER_COMMON, DO_FILTER_SCRIPT, SET_TABLE_FILTERS, and MAKE_FILTER_TEXT functions in the DBMS_METADATA_INT package; and (h) GET_PREPOST_TABLE_ACT function in the DBMS_METADATA package.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22643">22643</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22637">22637</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22543">22543</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0261" seq="2006-0261" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component.  NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24168">oracle-masterkey-plaintext(24168)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422255/30/7430/threaded">20060117 Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html">http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="8.1.7.4" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0262" seq="2006-0262" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="8.1.7.4" />
            </prod>
            <prod vendor="oracle" name="oracle10g">
                <vers num="enterprise_10.1.0.4" />
                <vers num="personal_10.1.0.4" />
                <vers num="standard_10.1.0.4" />
            </prod>
            <prod vendor="oracle" name="oracle8i">
                <vers num="enterprise_8.1.7.4" />
                <vers num="standard_8.1.7.4" />
            </prod>
            <prod vendor="oracle" name="oracle9i">
                <vers num="enterprise_9.0.1.5" />
                <vers num="enterprise_9.0.1.5_fips" />
                <vers num="standard_9.2.0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0263" seq="2006-0263" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/870172">VU#870172</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22551">22551</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22550">22550</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22547">22547</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="10.2.0.1" />
                <vers num="8.1.7.4" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2006-0264" seq="2006-0264" type="CVE" published="2006-01-18" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0259.  Reason: This candidate is subsumed by CVE-2006-0259.  An error during initial CVE analysis used the wrong set of affected versions for "DB10". Notes: All CVE users should reference CVE-2006-0259 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0265" seq="2006-0265" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" adv="1">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22642">22642</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22641">22641</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22640">22640</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22639">22639</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22555">22555</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="10.2.0.1" />
                <vers num="8.1.7.4" />
                <vers num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2006-0266" seq="2006-0266" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2006-0267" seq="2006-0267" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.2.0.6 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB20.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.4" />
                <vers num="9.2.0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2006-0268" seq="2006-0268" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.4" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
                <vers num="9.2.0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" name="CVE-2006-0269" seq="2006-0269" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="5.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22563">22563</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="oracle10g">
                <vers num="standard_10.1.0.5" />
                <vers num="standard_10.2.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0270" seq="2006-0270" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27.  NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24186">oracle-sga-masterkey-plaintext(24186)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422262/30/7400/threaded">20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html">http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="10.2.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0271" seq="2006-0271" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Upgrade &amp; Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22566">22566</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="8.1.7.4" />
            </prod>
            <prod vendor="oracle" name="oracle10g">
                <vers num="enterprise_10.1.0.4" />
                <vers num="personal_10.1.0.4" />
                <vers num="standard_10.1.0.4" />
            </prod>
            <prod vendor="oracle" name="oracle8i">
                <vers num="enterprise_8.1.7.4" />
                <vers num="standard_8.1.7.4" />
            </prod>
            <prod vendor="oracle" name="oracle9i">
                <vers num="enterprise_9.0.1.5" />
                <vers num="standard_9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2006-0272" seq="2006-0272" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29.  NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/891644">VU#891644</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24376">oracle-xdbdbmx-xmlschema-bo(24376)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
            <ref source="MISC" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="MISC" url="http://www.argeniss.com/research/ARGENISS-ADV-010601.txt">http://www.argeniss.com/research/ARGENISS-ADV-010601.txt</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html">20060126 [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT}</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="oracle10g">
                <vers num="enterprise_10.1.0.4" />
                <vers num="personal_10.1.0.4" />
                <vers num="standard_10.1.0.4" />
            </prod>
            <prod vendor="oracle" name="oracle9i">
                <vers num="standard_9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0273" seq="2006-0273" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.0" />
                <vers num="9.0.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0274" seq="2006-0274" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.0.2" />
                <vers num="9.0.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0275" seq="2006-0275" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04.  NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422261/30/7430/threaded">20060117 Oracle Reports - Read parts of files via customize(fixed after 875 days)</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html">http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="9.0.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0276" seq="2006-0276" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless &amp; Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="collaboration_suite">
                <vers edition="r2" num="9.0.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0277" seq="2006-0277" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0278" seq="2006-0278" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0279" seq="2006-0279" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0280" seq="2006-0280" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="peoplesoft_enterprise_portal">
                <vers edition="bundle15" num="8.4" />
                <vers edition="bundle10" num="8.8" />
                <vers edition="bundle2" num="8.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0281" seq="2006-0281" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="enterpriseone">
                <vers num="8.95.f1" />
                <vers num="sp23_l1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0282" seq="2006-0282" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers edition="r1" num="1.0.2.2" />
                <vers edition="r2" num="10.1.2.0.2" />
                <vers num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="collaboration_suite">
                <vers edition="r2" num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers num="8.1.7.4" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0283" seq="2006-0283" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects &amp; Convert Tablespace component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.0.2" />
            </prod>
            <prod vendor="oracle" name="collaboration_suite">
                <vers edition="r2" num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0284" seq="2006-0284" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers edition="r2" num="10.1.2.0.2" />
                <vers num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0285" seq="2006-0285" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="1.0.2.2" />
                <vers num="10.1.2.0.2" />
                <vers num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="8.1.7.4" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0286" seq="2006-0286" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="1.0.2.2" />
                <vers num="10.1.2.0.2" />
                <vers num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
                <vers edition="" num="9.0.1.5" />
                <vers edition=":fips" num="9.0.1.5" />
                <vers num="9.2.0.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0287" seq="2006-0287" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.0.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="10.1.0.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0288" seq="2006-0288" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804" adv="1">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="9.0.4.1" />
            </prod>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0289" seq="2006-0289" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005-2378 and REP06 is the same as CVE-2005-2371, both of which involve directory traversal.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422257/30/7430/threaded">20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded">20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html">http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html</ref>
            <ref source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html">http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="6.0.8.26_ps17" />
            </prod>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0290" seq="2006-0290" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.1" />
                <vers num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="collaboration_suite">
                <vers edition="r2" num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="9.2.0.7" />
            </prod>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0291" seq="2006-0291" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html" adv="1">http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0323" adv="1">ADV-2006-0323</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0243" adv="1">ADV-2006-0243</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18608" adv="1">18608</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18493" adv="1">18493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.1.0" />
                <vers num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="collaboration_suite">
                <vers edition="r2" num="9.0.4.2" />
            </prod>
            <prod vendor="oracle" name="database_server">
                <vers num="10.2.0.1" />
            </prod>
            <prod vendor="oracle" name="e-business_suite">
                <vers num="11.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0302" seq="2006-0302" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16285">16285</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18511" adv="1">18511</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041438.html" adv="1">20060116 ZyXel P2000W (Version 2) VoIP wireless phone undocumented port UDP/9090</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24145">zyxel-p2000w-default-port(24145)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22516">22516</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zyxel" name="p2000w_version_2_voip_wifi_phone">
                <vers num="wv.00.02" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2006-0303" seq="2006-0303" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18513" adv="1">18513</ref>
            <ref source="CONFIRM" url="http://www.joomla.org/content/view/738/66/">http://www.joomla.org/content/view/738/66/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="joomla" name="joomla">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0304" seq="2006-0304" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/18486" adv="1">18486</ref>
            <ref source="MISC" patch="1" url="http://aluigi.altervista.org/adv/dualsbof-adv.txt" adv="1">http://aluigi.altervista.org/adv/dualsbof-adv.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24191">dualdhcpdns-options-field-bo(24191)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16298">16298</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0245">ADV-2006-0245</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015495">1015495</ref>
        </refs>
        <vuln_soft>
            <prod vendor="achal_dhir" name="dual_dhcp_dns_server">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0305" seq="2006-0305" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Clipcomm CPW-100E VoIP 802.11b Wireless Handset Phone running firmware 1.1.12 (051129) and CP-100E VoIP 802.11b Wireless Phone running firmware 1.1.60 allows remote attackers to gain unauthorized access via the debug service on TCP port 60023.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16289">16289</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18505" adv="1">18505</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041439.html" adv="1">20060116 Clipcomm CP-100E VoIP wireless desktop phone open debug service TCP/60023</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041436.html" adv="1">20060116 Clipcomm CPW-100E VoIP wireless handset phone open debug service TCP/60023</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24144">clipcomm-cp100e-default-port(24144)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="clipcomm" name="cp-100e_voip_wifi_phone">
                <vers num="1.1.60" />
            </prod>
            <prod vendor="clipcomm" name="cpw-100e_voip_wifi_phone">
                <vers num="1.1.12" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0306" seq="2006-0306" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16276">16276</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22529">22529</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0236" adv="1">ADV-2006-0236</ref>
            <ref source="MISC" url="http://www.designfolks.com.au/karma/DMPrimer/" adv="1">http://www.designfolks.com.au/karma/DMPrimer/</ref>
            <ref source="CONFIRM" url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015504">1015504</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18531" adv="1">18531</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
                <vers num="11.0" />
                <vers edition="sp1" num="11.1" />
            </prod>
            <prod vendor="ca" name="brightstor_mobile_backup">
                <vers num="r4.0" />
            </prod>
            <prod vendor="ca" name="business_protection_suite">
                <vers num="2.0" />
            </prod>
            <prod vendor="ca" name="desktop_protection_suite">
                <vers num="2.0" />
            </prod>
            <prod vendor="ca" name="server_protection_suite">
                <vers num="2" />
            </prod>
            <prod vendor="ca" name="unicenter_remote_control">
                <vers num="5.2" />
                <vers edition="sp1" num="6.0" />
                <vers edition="sp1:" num="6.0" />
                <vers edition="sp1::en" num="6.0" />
                <vers edition="sp1::fr" num="6.0" />
                <vers edition="" num="6.0_build_6.0.56.3" />
                <vers edition=":" num="6.0_build_6.0.56.3" />
                <vers edition="::en" num="6.0_build_6.0.56.3" />
                <vers edition="" num="6.0_build_6.0.74" />
                <vers edition=":" num="6.0_build_6.0.74" />
                <vers edition="::de" num="6.0_build_6.0.74" />
                <vers edition="::en" num="6.0_build_6.0.74" />
                <vers edition="::fr" num="6.0_build_6.0.74" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0307" seq="2006-0307" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption and log file consumption) via unspecified "unrecognized network messages" that are not properly handled.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015504">1015504</ref>
            <ref source="CONFIRM" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16276">16276</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22529">22529</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0236" adv="1">ADV-2006-0236</ref>
            <ref source="CONFIRM" url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18531" adv="1">18531</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
                <vers num="11.0" />
                <vers edition="sp1" num="11.1" />
            </prod>
            <prod vendor="ca" name="brightstor_mobile_backup">
                <vers num="r4.0" />
            </prod>
            <prod vendor="ca" name="business_protection_suite">
                <vers num="2.0" />
            </prod>
            <prod vendor="ca" name="desktop_protection_suite">
                <vers num="2.0" />
            </prod>
            <prod vendor="ca" name="server_protection_suite">
                <vers num="2" />
            </prod>
            <prod vendor="ca" name="unicenter_remote_control">
                <vers num="5.2" />
                <vers edition="sp1" num="6.0" />
                <vers edition="sp1:" num="6.0" />
                <vers edition="sp1::en" num="6.0" />
                <vers edition="sp1::fr" num="6.0" />
                <vers edition="" num="6.0_build_6.0.56.3" />
                <vers edition=":" num="6.0_build_6.0.56.3" />
                <vers edition="::en" num="6.0_build_6.0.56.3" />
                <vers edition="" num="6.0_build_6.0.74" />
                <vers edition=":" num="6.0_build_6.0.74" />
                <vers edition="::de" num="6.0_build_6.0.74" />
                <vers edition="::en" num="6.0_build_6.0.74" />
                <vers edition="::fr" num="6.0_build_6.0.74" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0308" seq="2006-0308" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33092">htmltonuke-htmltonuke-file-include(33092)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16282">16282</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3524">3524</ref>
        </refs>
        <vuln_soft>
            <prod vendor="htmltonuke" name="htmltonuke">
                <vers num="2.0_alpha" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" name="CVE-2006-0309" seq="2006-0309" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422064/100/0/threaded">20060116 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421929/100/0/threaded">20060113 Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0238" adv="1">ADV-2006-0238</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015490">1015490</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18461" adv="1">18461</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24125">linksys-null-length-dos(24125)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16307">16307</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422266/100/0/threaded">20060117 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linksys" name="befvp41">
                <vers num="1.01.04" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-0310" seq="2006-0310" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16286">16286</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0240" adv="1">ADV-2006-0240</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16889" adv="1">16889</ref>
            <ref source="MISC" url="http://evuln.com/vulns/37/summary.html" adv="1">http://evuln.com/vulns/37/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24141">aoblogger-url-xss(24141)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22526">22526</ref>
            <ref source="CONFIRM" url="http://mikeheltonisawesome.com/viewcomments.php?idd=46">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mike_helton" name="aoblogger">
                <vers num="2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0311" seq="2006-0311" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16286">16286</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0240" adv="1">ADV-2006-0240</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16889" adv="1">16889</ref>
            <ref source="MISC" url="http://evuln.com/vulns/37/summary.html" adv="1">http://evuln.com/vulns/37/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24142">aoblogger-login-sql-injection(24142)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22527">22527</ref>
            <ref source="CONFIRM" url="http://mikeheltonisawesome.com/viewcomments.php?idd=46">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mike_helton" name="aoblogger">
                <vers num="2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2006-0312" seq="2006-0312" severity="Medium" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/16286">16286</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0240" adv="1">ADV-2006-0240</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16889" adv="1">16889</ref>
            <ref source="MISC" url="http://evuln.com/vulns/37/summary.html" adv="1">http://evuln.com/vulns/37/summary.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24143">aoblogger-create-security-bypass(24143)</ref>
            <ref source="CONFIRM" url="http://mikeheltonisawesome.com/viewcomments.php?idd=46">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mike_helton" name="aoblogger">
                <vers num="2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0313" seq="2006-0313" severity="High" type="CVE" published="2006-01-18" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2008-09-05">
        