Primary Vendor -- Product | Description | | CVSS Score | Source & Patch Info | Baby Katie Media -- very Simple Realty Lister (vsREAL) Baby Katie Media -- very Simple Car Lister (vSCAL)
| Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in index.php and the (2) title parameter in myslideshow.php. | | 2.3 | CVE-2006-2986 BUGTRAQ FRSIRT SECUNIA BID
| Cescripts -- Realty Room Rent
| Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. | | 1.9 | CVE-2006-3038 BUGTRAQ FRSIRT SECUNIA
| Cescripts -- Realty Home Rent
| Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. | | 1.9 | CVE-2006-3039 BUGTRAQ FRSIRT SECUNIA
| CFXe-CMS -- CFXe-CMS
| Cross-site scripting (XSS) vulnerability in search.cfm in CFXe-CMS 2.0 and earlier allows remote attackers to execute arbitrary web script or HTML via the voltext_suche parameter. | | 1.9 | CVE-2006-3043 OTHER-REF FRSIRT SECUNIA
| Easy Ad-Manager -- Easy Ad-Manager
| details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant from another vulnerability, since this vector also produces cross-site scripting (XSS). | | 2.3 | CVE-2006-3003 BUGTRAQ SECUNIA
| EmailArchitect -- Email Server
| Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp. | | 1.9 | CVE-2006-2974 FRSIRT SECTRACK SECUNIA
| Enthrallweb -- ePhotos
| Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp. | | 3.3 | CVE-2006-3027 BLOGSPOT FRSIRT SECUNIA
| Gentoo -- media-libs/jpeg Gentoo -- Gentoo Linux
| The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits. | | 2.3 | CVE-2006-3005 OTHER-REF GENTOO SECUNIA
| GNOME -- dhcdbd
| Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption. | | 2.3 | CVE-2006-3057 UBUNTU BID
| iFoto -- iFoto
| Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter. | | 2.3 | CVE-2006-3006 BUGTRAQ BUGTRAQ SECUNIA BID FRSIRT
| IntegraMOD -- IntegraMOD
| Cross-site scripting (XSS) vulnerability in index.php in IntegraMOD 1.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the STYLE_URL parameter. NOTE: it is possible that this issue is resultant from SQL injection. | | 2.3 | CVE-2006-2984 BUGTRAQ FRSIRT SECUNIA
| KDE -- KDE
| KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login. | | 1.9 | CVE-2006-2449 BUGTRAQ REDHAT UBUNTU BID
| KDE -- aRts
| artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges. | | 3.4 | CVE-2006-2916 KDE KDE BID
| L0j1k -- tinyMuw
| Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the input box in quickchat.php, and possibly other manipulations. | | 2.3 | CVE-2006-2969 BUGTRAQ FRSIRT SECUNIA
| L0j1k -- tinyMuw
| videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain sensitive information via a certain id parameter, probably with an invalid value, which reveals the path in an error message. | | 2.3 | CVE-2006-2970 BUGTRAQ FRSIRT
| LogiSphere -- LogiSphere
| Cross-site scripting (XSS) vulnerability in LogiSphere 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected in an error page. | | 1.9 | CVE-2006-3044 FRSIRT OSVDB SECTRACK SECUNIA
| Mafia Moblog -- Mafia Moblog
| Mafia Moblog 0.6M1 and earlier allows remote attackers to obtain the installation path in an error message via a direct request to (1) big.php and (2) upgrade.php. | | 2.3 | CVE-2006-2978 BUGTRAQ SECUNIA FRSIRT
| Microsoft -- Windows 2000 Microsoft -- Windows Server 2003 Microsoft -- Windows XP
| The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability." | | 1.6 | CVE-2006-2374 MS IDEFENSE BID FRSIRT SECUNIA
| Microsoft -- Internet Explorer Microsoft -- Windows Server 2003 Microsoft -- Windows XP
| Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption. | | 3.5 | CVE-2006-2378 IDEFENSE MS CERT-VN BID FRSIRT SECUNIA CERT SECTRACK
| Microsoft -- Windows NT Microsoft -- Windows 2000 Microsoft -- Windows Server 2003 Microsoft -- Windows XP
| Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing. | | 2.3 | CVE-2006-2379 MS CERT-VN BID SECUNIA CERT FRSIRT SECTRACK
| Microsoft -- Windows 2000
| Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability." | | 2.3 | CVE-2006-2380 MS BID FRSIRT SECTRACK SECUNIA
| Microsoft -- Internet Explorer
| Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability." | | 3.7 | CVE-2006-2384 MS BID FRSIRT SECTRACK SECUNIA
| Microsoft -- Internet Explorer
| Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-complicit remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file. | | 3.7 | CVE-2006-2385 MS BID FRSIRT SECTRACK SECUNIA
| Mole Group Ticket Booking Script -- Mole Group Ticket Booking Script
| Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) address1, (3) address2, (4) county, (5) postcode, (6) email, (7) phone, or (8) mobile parameters to booking2.php. | | 2.3 | CVE-2006-3049 BUGTRAQ MLIST FRSIRT SECUNIA
| My Photo Scrapbook -- My Photo Scrapbook
| Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp. | | 2.3 | CVE-2006-2993 OTHER-REF FRSIRT SECUNIA
| MyScrapbook -- MyScrapbook
| MyScrapbook 3.1 allows remote attackers to obtain sensitive information via a direct request to files in the txt-db-api directory such as txt-db-api/sql.php, which reveals the path in an error message. | | 2.3 | CVE-2006-3034 BUGTRAQ FRSIRT SECUNIA
| Net Portal Dynamic System -- Net Portal Dynamic System
| Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_extender.php, which reveals the path in an error message. | | 3.5 | CVE-2006-2950 BUGTRAQ OTHER-REF FRSIRT SECUNIA
| Net Portal Dynamic System -- Net Portal Dynamic System
| Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) Default_Theme parameter to header.php or (2) ModPath parameter to modules/cluster-paradise/cluster-E.php. | | 3.5 | CVE-2006-2952 BUGTRAQ OTHER-REF FRSIRT SECUNIA BID OSVDB OSVDB
| NullSoft -- Shoutcast Server
| Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ. | | 2.3 | CVE-2006-3007 BUGTRAQ BID FRSIRT SECUNIA
| Overkill -- Overkill
| Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet with fewer than 12 bytes, which results in a long length value to the crc32 function. | | 2.3 | CVE-2006-2971 BUGTRAQ BID FRSIRT SECUNIA
| PBL Guestbook -- PBL Guestbook
| Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information. | | 1.9 | CVE-2006-2975 BUGTRAQ FRSIRT SECUNIA
| PHP -- PHP
| Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename. | | 1.6 | CVE-2006-2660 OTHER-REF BUGTRAQ SECTRACK
| PHP Labware -- LabWiki
| Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter). | | 2.3 | CVE-2006-2968 BUGTRAQ MLIST BID SECTRACK
| phpCMS -- phpCMS
| Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpc ms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. | | 2.3 | CVE-2006-3019 BUGTRAQ FRSIRT SECUNIA
| Ringlink -- Ringlink
| Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2 allow remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element, and possibly other manipulations, in the ringid parameter in (1) next.cgi, (2) stats.cgi, or (3) list.cgi. | | 2.3 | CVE-2006-2991 BUGTRAQ BID FRSIRT SECUNIA OSVDB OSVDB OSVDB
| ScriptsEZ -- Ez Ringtone Manager
| Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in player.php and (2) keyword parameter when performing a search. | | 2.3 | CVE-2006-3004 BUGTRAQ BID FRSIRT SECUNIA
| Site Trade -- ST AdManager Lite
| Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ST AdManager Lite allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, (3) article, (4) bio, and (5) name parameters. | | 1.9 | CVE-2006-3037 BUGTRAQ FRSIRT SECUNIA
| Six Offene Systeme GmbH -- SixCMS
| Directory traversal vulnerability in detail.php in SixCMS 6.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter. | | 1.9 | CVE-2006-3050 BUGTRAQ OTHER-REF BID SECTRACK
| Syworks -- SafeNET
| Syworks SafeNET allows local users to bypass restrictions on network resource consumption by editing the policy.dat file. | | 1.6 | CVE-2006-2967 BUGTRAQ SECTRACK
| The Integramod Group -- IntegraMOD
| SQL injection vulnerability in index.php in IntegraMOD 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded "'" characters in the STYLE_URL parameter. | | 2.3 | CVE-2006-2985 BUGTRAQ MLIST
| Tikiwiki Project -- Tikiwiki
| Cross-site scripting (XSS) vulnerability in tikiwiki 1.9.3.2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | | 2.3 | CVE-2006-3047 BUGTRAQ OTHER-REF SECUNIA
| ViArt -- Shop
| Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not properly handled in block_forum_topics.php, and (2) item_id parameter in reviews.php, which is not properly handled in block_reviews.php. | | 1.9 | CVE-2006-2979 BUGTRAQ OTHER-REF MLIST FRSIRT SECUNIA BID
| ViArt Ltd -- ViArt Shop Free
| SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id parameter. | | 2.3 | CVE-2006-2980 MLIST OTHER-REF
| WinSCP -- WinSCP
| Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI. | | 3.7 | CVE-2006-3015 FULLDISC BID FRSIRT SECUNIA
| ZMS Publishing -- ZMS
| Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the raw parameter in the search field. | | 2.3 | CVE-2006-2997 OTHER-REF SECUNIA BUGTRAQ FRSIRT SECTRACK
|