Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 119 respecto a la semana anterior
Críticas / altas1267▼ 261 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Hosting Controller | 31/10/2006 | 16/6/2026 | Hosting Controller 6.1 versiones anteriores a Hotfix 3.3 permite a atacantes remotos (1) borrar el directorio virtual de un sitio de su elección mediante el párametro modificado ForumID en una acción "deshabilita foro" en DisableForum.asp y (2) crear un directorio virtual de foro de su elección mediante un paráemtro… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Lappy512 PHP Krazy Image Host Script | 3/10/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en display.php en Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a permite a un atacante remoto ejecutar comandos SQL de su elección a través del parámetro id. | |
| Modificada | Media (4.9) | 1.3% | 💥 Exploit | Symantec Client SecuritySymantec Host IDSSymantec Norton AntivirusSymantec Norton Internet Security+3 | 19/9/2006 | 16/6/2026 | El driver \Device\SymEvent en Symantec Norton Personal Firewall 2006 9.1.0.33, y otras versiones del Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, y 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0 y 10.1, Symantec pcAnywhere 11.5 y… | |
| Modificada | Alta (7.5) | 1.2% | — | Cchost | 14/9/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en las herramientas de Creative Commons anteriores a la versión 3.0. Permite a los atacantes remotos ejecutar comandos SQL a través de la URL de forma manual, y que usan para llenar campos en el fichero ID. NOTA: Algunos detalles se obtienen a partir de información de terceros. | |
| Modificada | Media (4.3) | 1.3% | — | Webligo Bloghoster | 11/8/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Webligo BlogHoster 2.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de "la parte De: (From:) del mensaje de comentario", probablemente relacionado con el parámetro apodo (nickname) de… | |
| Modificada | Media (4.3) | 1.3% | — | Total Online Solutions Advanced Webhost Billing System | 1/8/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en contact.php en Advanced Webhost Billing System (AWBS) 2.2.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) Name, (2) AccountUsername y (3) Message. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Idevspot AutohostIdevspot Phphostbot | 24/7/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en order/index.php en IDevSpot (1) PhpHostBot 1.0 y (2) AutoHost 3.0 permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro page. | |
| Modificada | Alta (7.5) | 1.1% | — | Freehost | 11/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en FreeHost permiten a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro (1) readme de FreeHost/misc.php o el parámetro (2) index de FreeHost/news.php. | |
| Modificada | Media (5.8) | 1.3% | — | Starflow Software Hostflow | 30/6/2006 | 16/6/2026 | new_ticket.cgi en Hostflow v2.2.1-15 permite a atacantes remotos robar y reproducir credenciales de autenticación a través de una etiqueta IMG en el parámetro "desc" ("campo de descrpción de Ticket") que apunta a una URL que URLs referer, posiblemente debido a una vulnerabilidad de secuencias de comandos en sitios… | |
| Modificada | Media (6.5) | 2.7% | 💥 Exploit | Hosting Controller | 22/6/2006 | 16/6/2026 | Vulnerabilidad no especificada en Hosting Controller antes de la versión v6.1 (alias Hotfix v3.2) permite, a atacantes remotos autenticados, obtener privilegios de administrador, listar todos los distribuidores, o cambiar las contraseñas de distribuidores a través de vectores no especificados. NOTA: debido a la falta… | |
| Modificada | Alta (7.5) | 1.4% | — | Alstrasoft Webhost Directory | 26/5/2006 | 16/6/2026 | SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Alstrasoft Webhost Directory | 26/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not require administrator privileges, and an auto-approve mechanism… | |
| Modificada | Media (5) | 1.7% | — | Alstrasoft Webhost Directory | 26/5/2006 | 16/6/2026 | (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Media (5) | 2.3% | — | Hostapd | 5/5/2006 | 16/6/2026 | Hostapd 0.3.7-2 permite a atacantes remotos provocar una denegación de servicio (fallo de segmentación) a través de un valor no especificado en el campo key_data_length de un marco EAPoL. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Virtual Hosting Control System | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter. | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+1 | 21/4/2006 | 16/6/2026 | Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell… | |
| Modificada | Alta (7.8) | 1.6% | — | Hosting Controller | 13/4/2006 | 16/6/2026 | Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this information is unknown; the details are obtained from third party… | |
| Modificada | Media (4) | 1.3% | — | Hosting Controller | 5/4/2006 | 16/6/2026 | Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter. | |
| Modificada | Media (5) | 2.2% | — | Hosting Controller | 5/4/2006 | 16/6/2026 | admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3… | |
| Modificada | Media (5.8) | 2.5% | 💥 Exploit | Webhost Automation Helm WEB Hosting Control Panel | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp. | |
| Modificada | Baja (2.1) | 0.39% | — | Symantec Ghost Solutions SuiteSymantec Norton Ghost | 19/3/2006 | 16/6/2026 | Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database. | |
| Modificada | Baja (3.2) | 0.32% | — | Symantec Ghost Solutions SuiteSymantec Norton Ghost | 19/3/2006 | 16/6/2026 | SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information. | |
| Modificada | Media (4.6) | 0.36% | — | Symantec Ghost Solutions SuiteSymantec Norton Ghost | 19/3/2006 | 16/6/2026 | The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks. | |
| Modificada | Media (5) | 1.6% | — | David Ravenscroft Hithost | 14/3/2006 | 16/6/2026 | Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might… | |
| Modificada | Alta (7.5) | 1.9% | — | Hosting Controller | 14/3/2006 | 16/6/2026 | SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |