Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29864 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6525 1 Ezhrs 1 Hr Assist 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-1712 1 Active Web Softwares 1 Active Auction House 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2007-2420 1 Burak Yilmaz 1 Burak Yilmaz Blog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-7061 1 Scriptsez.net 1 E-dating System 2025-04-09 9.3 HIGH N/A
Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.
CVE-2007-0224 1 Virtual Programming 1 Vp-asp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.
CVE-2007-3842 1 8e6 1 R3000 Enterprise Filter 2025-04-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise Filter before 2.0.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this may be the same as CVE-2007-2970.
CVE-2006-6348 1 Mowdbb 1 Mowdbb 2025-04-09 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.
CVE-2006-5625 1 Nx 1 N X Wcms 2025-04-09 5.1 MEDIUM N/A
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.
CVE-2007-0618 1 Ibm 1 Aix 2025-04-09 7.5 HIGH N/A
Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
CVE-2007-4847 1 Google 1 Picasa 2025-04-09 5.0 MEDIUM N/A
Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory.
CVE-2007-1490 1 Avaya 1 Communication Manager 2025-04-09 6.0 MEDIUM N/A
Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").
CVE-2006-5419 1 University Of Glasgow 1 Specimen Image Database 2025-04-09 7.5 HIGH N/A
PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter.
CVE-2007-2530 1 Tropicalm 1 Tropicalm Crowell Resource 2025-04-09 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL in the RESPATH parameter to (1) dosearch.php or (2) printfriendly.php.
CVE-2007-4035 1 Guidance Software 1 Encase 2025-04-09 5.0 MEDIUM N/A
Guidance Software EnCase does not properly handle (1) certain malformed MBR partition tables with many entries, which allows remote attackers to prevent logical collection of a disk image; (2) NTFS filesystems with directory loops, which allows remote attackers to prevent examination of certain directory contents; and (3) certain other malformed NTFS filesystems, which allows remote attackers to prevent examination of corrupted records. NOTE: the vendor disputes the significance of these issues, because physical collection can be used instead, because the vendor believes that relevant attackers typically do not corrupt an MBR or a filesystem, and because detection of a loop is valuable on its own
CVE-2007-4463 2 Fransois Gannier, Ghisler 2 Fileinfo Plugin, Total Commander 2025-04-09 5.0 MEDIUM N/A
The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.
CVE-2008-4819 1 Adobe 1 Flash Player 2025-04-09 6.8 MEDIUM N/A
Unspecified vulnerability in Adobe Flash Player 9.0.124.0 and earlier makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
CVE-2007-0387 1 Joomla 1 Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2006-5904 1 Mwchat Pro 1 Mwchat Pro 2025-04-09 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in MWChat Pro 7.0 allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[MWCHAT_Libs] parameter to (1) about.php, (2) buddy.php, (3) chat.php, (4) dialog.php, (5) head.php, (6) help.php, (7) index.php, and (8) license.php, different vectors than CVE-2005-1869.
CVE-2006-6132 1 Softacid 1 Link Exchange Lite 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Link Exchange Lite allow remote attackers to execute arbitrary SQL commands via (1) the search engine field to search.asp and (2) psearch parameter to linkslist.asp.
CVE-2007-2563 1 Versalsoft 1 Http File Upload Activex Control 2025-04-09 9.3 HIGH N/A
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.