<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" nvd_xml_version="2.0" pub_date="2009-11-07T03:30:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2006-0018">
        <vuln:cve-id>CVE-2006-0018</vuln:cve-id>
        <vuln:published-datetime>2005-11-29T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:55:02.087-04:00</vuln:last-modified-datetime>
        <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0064">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:devellion:cubecart:3.0.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:devellion:cubecart:3.0.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0064</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:55:14.307-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-03T17:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0016">ADV-2006-0016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/1398">1398</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0065">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vego:vego_web_forum:1.26" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vego:vego_web_forum:1.26</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0065</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:15.780-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:50:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0003">ADV-2006-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18273">18273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/1/summary.html">http://evuln.com/vulns/1/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16107">16107</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22140">22140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/315">315</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0066">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpjournaler:phpjournaler:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpjournaler:phpjournaler:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0066</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:15.920-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16111">16111</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22149">22149</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0006">ADV-2006-0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18265">18265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/9/summary.html">http://evuln.com/vulns/9/summary.html</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0067">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vego:vego_links_builder:2.00" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vego:vego_links_builder:2.00</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0067</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:16.077-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0004">ADV-2006-0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18272">18272</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/2/summary.html">http://evuln.com/vulns/2/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16108">16108</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22139">22139</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0068">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:primo_place:primo_cart:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:primo_place:primo_cart:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0068</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-20T00:44:31.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0008">ADV-2006-0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18264">18264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16125">16125</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22147">22147</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22146">22146</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html">http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0069">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:chipmunk_scripts:chipmunk_guestbook:1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:chipmunk_scripts:chipmunk_guestbook:1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0069</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:16.357-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:48:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19087">19087</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16112">16112</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18270">18270</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/4/summary.html">http://evuln.com/vulns/4/summary.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0070">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0070</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:16.497-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded">20060103 Re: Drupal all versiyon xss cehennem.org</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/420671/100/0/threaded">20060102 Drupal all versiyon xss cehennem.org</vuln:reference>
        </vuln:references>
        <vuln:summary>** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0071">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gentoo:app-crypt_pinentry:0.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:gentoo:app-crypt_pinentry:0.7.2:r1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:gentoo:linux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:gentoo:linux</vuln:product>
            <vuln:product>cpe:/a:gentoo:app-crypt_pinentry:0.7.2:r1</vuln:product>
            <vuln:product>cpe:/a:gentoo:app-crypt_pinentry:0.7.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0071</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:16.653-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16120">16120</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml">GLSA-200601-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22211">22211</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18284">18284</vuln:reference>
        </vuln:references>
        <vuln:summary>The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0072">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6a" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.3</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.6a</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.4</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.5</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0072</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:16.797-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:42:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16122">16122</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/420677">20060102 SCO Openserver 5.0.x exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c">http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0073">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:discusware:discus_freeware:3.10.5" />
                <cpe-lang:fact-ref name="cpe:/a:discusware:discus_professional:3.10.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:discusware:discus_freeware:3.10.5</vuln:product>
            <vuln:product>cpe:/a:discusware:discus_professional:3.10.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0073</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:16.967-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16119">16119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22153">22153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18283">18283</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0074">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jevontech:phpenpals:310704" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jevontech:phpenpals:310704</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0074</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-06-02T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:20:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16109">16109</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22150">22150</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/8706">8706</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0005">ADV-2006-0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18269">18269</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/5/summary.html">http://evuln.com/vulns/5/summary.html</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.  NOTE: it was later reported that 1.1 and earlier are affected.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0075">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gnu:phpbook:1.0</vuln:product>
            <vuln:product>cpe:/a:gnu:phpbook:1.1</vuln:product>
            <vuln:product>cpe:/a:gnu:phpbook:1.2</vuln:product>
            <vuln:product>cpe:/a:gnu:phpbook:1.3</vuln:product>
            <vuln:product>cpe:/a:gnu:phpbook:1.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0075</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:17.263-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:22:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16106">16106</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded">20060101 [eVuln] phpBook PHP Code Execution</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0002">ADV-2006-0002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/6/summary.html">http://evuln.com/vulns/6/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18268">18268</vuln:reference>
        </vuln:references>
        <vuln:summary>Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0076">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oaboard:oaboard:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2006-0076</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:17.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:23:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16105">16105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded">20060531 Re: OaBoard 1.0 Remote File inclusion</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded">20060530 OaBoard 1.0 Remote File inclusion</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded">20060101 [eVuln] oaBoard PHP Code Execution</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016211">1016211</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/3/summary.html">http://evuln.com/vulns/3/summary.html</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:richard_dawe:file_extattr:0.1" />
                <cpe-lang:fact-ref name="cpe:/a:richard_dawe:file_extattr:0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:richard_dawe:file_extattr:0.1</vuln:product>
            <vuln:product>cpe:/a:richard_dawe:file_extattr:0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0077</vuln:cve-id>
        <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:17.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16118">16118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0013">ADV-2006-0013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116">http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18253">18253</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22160">22160</vuln:reference>
        </vuln:references>
        <vuln:summary>Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0078">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:haddad_said:b-net_software:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:haddad_said:b-net_software:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0078</vuln:cve-id>
        <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:17.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16114">16114</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18271">18271</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/10/summary.html">http://evuln.com/vulns/10/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22191">22191</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22190">22190</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0018">ADV-2006-0018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067">http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/316">316</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0079">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:scoznet:scozbook:1.1_beta" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:scoznet:scozbook:1.1_beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0079</vuln:cve-id>
        <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:17.873-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16115">16115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded">20060102 [eVuln] ScozBook "adminname" Authentication Bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/11/summary.html">http://evuln.com/vulns/11/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22221">22221</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0027">ADV-2006-0027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/318">318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8476">8476</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</vuln:summary>
    </entry>
    <entry id="CVE-2006-0080">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0080</vuln:cve-id>
        <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.013-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16116">16116</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded">20060108 Html_Injection in vBulletin 3.5.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22220">22220</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22210">22210</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0033">ADV-2006-0033</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18299">18299</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://kapda.ir/advisory-177.html">http://kapda.ir/advisory-177.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0081">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intel:graphics_accelerator_driver:6.14.10.4308" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intel:graphics_accelerator_driver:6.14.10.4308</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0081</vuln:cve-id>
        <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-04T08:17:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16127">16127</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22196">22196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0017">ADV-2006-0017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18286">18286</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</vuln:reference>
        </vuln:references>
        <vuln:summary>ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0082">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.2.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:imagemagick:imagemagick:6.2.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0082</vuln:cve-id>
        <vuln:published-datetime>2006-01-04T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.327-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.1</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12717">12717</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml">GLSA-200602-13.xml</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml">GLSA-200602-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682">SSA:2006-045-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19183">19183</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19030">19030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18851">18851</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18607">18607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-246-1">USN-246-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_06_sr.html">SUSE-SR:2006:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015623">1015623</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19408">19408</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18871">18871</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18261">18261</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0178.html">RHSA-2006:0178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-389">https://issues.rpath.com/browse/RPL-389</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded">20061127 rPSA-2006-0218-1 ImageMagick</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1213">DSA-1213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/500">500</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28800">28800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23090">23090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22998">22998</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0084">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rasmp:rasmp:2.0.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rasmp:rasmp:2.0.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0084</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.623-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-05T08:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16138">16138</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22198">22198</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0030">ADV-2006-0030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18292">18292</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/13/summary.html">http://evuln.com/vulns/13/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015432">1015432</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://attrition.org/pipermail/vim/2006-January/000486.html">20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</vuln:summary>
    </entry>
    <entry id="CVE-2006-0085">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nkads:nkads:1.0alfa2" />
                <cpe-lang:fact-ref name="cpe:/a:nkads:nkads:1.0alfa3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nkads:nkads:1.0alfa3</vuln:product>
            <vuln:product>cpe:/a:nkads:nkads:1.0alfa2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0085</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.763-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:55:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt">http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0040">ADV-2006-0040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18302">18302</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22206">22206</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0086">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:next_generation_image_gallery:next_generation_image_gallery:0.0.1_lite" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:next_generation_image_gallery:next_generation_image_gallery:0.0.1_lite</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0086</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.920-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:58:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0037">ADV-2006-0037</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18309">18309</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22202">22202</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22202-nextgen.txt">http://osvdb.org/ref/22/22202-nextgen.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0087">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lizard_cart:lizard_cart_cms:1.0.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lizard_cart:lizard_cart_cms:1.0.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0087</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:19.077-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:59:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16140">16140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0029">ADV-2006-0029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18297">18297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22200">22200</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22199">22199</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.evuln.com/vulns/12/summary.html">http://www.evuln.com/vulns/12/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015435">1015435</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/314">314</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0088">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intouch:intouch:0.5.1_alpha" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intouch:intouch:0.5.1_alpha</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0088</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:19.217-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:02:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16110">16110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded">20060101 [eVuln] inTouch Authentication Bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0026">ADV-2006-0026</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/8/summary.html">http://evuln.com/vulns/8/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23954">intouch-intouch-sql-injection(23954)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22382">22382</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0089">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:esri:arcpad:7.0.0.156" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:esri:arcpad:7.0.0.156</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0089</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:19.373-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:03:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16136">16136</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0032">ADV-2006-0032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://users.pandora.be/bratax/advisories/b007.html">http://users.pandora.be/bratax/advisories/b007.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18294">18294</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22208">22208</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0090">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:idv_directory_viewer:idv_directory_viewer:2005.1_b1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:idv_directory_viewer:idv_directory_viewer:2005.1_b1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0090</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:19.513-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499">http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0031">ADV-2006-0031</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18298">18298</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16137">16137</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0091">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:open-xchange:open-xchange:0.8.1.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:open-xchange:open-xchange:0.8.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0091</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:19.653-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0034">ADV-2006-0034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18285">18285</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2">20060103 Open Xchange XSS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015431">1015431</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0092">
        <vuln:cve-id>CVE-2006-0092</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:55:26.397-04:00</vuln:last-modified-datetime>
        <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0093">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ecardmax.com:atcard_me_php" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ecardmax.com:atcard_me_php</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0093</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:19.903-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22203">22203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0039">ADV-2006-0039</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18306">18306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22203-ecardmax.txt">http://osvdb.org/ref/22/22203-ecardmax.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0094">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oaboard:oaboard:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2006-0094</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:20.043-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T09:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0028">ADV-2006-0028</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17373">17373</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0063">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.19" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2006-0063</vuln:cve-id>
        <vuln:published-datetime>2006-01-05T14:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:15.483-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/313">http://securityreason.com/securityalert/313</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/30">20060105 phpBB 2.0.19 XSS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22672">22672</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0051">ADV-2006-0051</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0341">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:6.1.22" />
                <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:7.0.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rockliffe:mailsite:7.0.3.1</vuln:product>
            <vuln:product>cpe:/a:rockliffe:mailsite:6.1.22</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0341</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:59.917-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-23T10:32:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0284">ADV-2006-0284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18551">18551</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24256">mailsite-wconsole-xss(24256)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16330">16330</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22677">22677</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0095">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0095</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:20.200-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24189">kernel-dmcrypt-information-disclosure(24189)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2006/0004">2006-0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16301">16301</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded">FLSA:157459-4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0132.html">RHSA-2006:0132</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html">FEDORA-2006-102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22418">22418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0235">ADV-2006-0235</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1017">DSA-1017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015740">1015740</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/388">388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20398">20398</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19374">19374</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19160">19160</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18774">18774</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18527">18527</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18487">18487</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</vuln:reference>
        </vuln:references>
        <vuln:summary>dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0096">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0096</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-11-20T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044">MDKSA-2006:044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16304">16304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f">http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1017">DSA-1017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19374">19374</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18977">18977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18527">18527</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c">http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c</vuln:reference>
        </vuln:references>
        <vuln:summary>wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0097">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0097</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:21.123-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:17:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16145">16145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded">20060105 Windows PHP 4.x "0-day" buffer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/ChangeLog-4.php#4.4.3">http://www.php.net/ChangeLog-4.php#4.4.3</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22232">22232</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0046">ADV-2006-0046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18275">18275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html">20060105 Windows PHP 4.x "0-day" buffer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html">20060108 RE: Windows PHP 4.x "0-day" buffer overflow</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0098">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.7" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:openbsd:openbsd:3.8</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0098</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:21.280-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16144">16144</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata37.html#fd">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18296">18296</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22231">22231</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015437">1015437</vuln:reference>
        </vuln:references>
        <vuln:summary>The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:valdersoft:valdersoft_shopping_cart:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:valdersoft:valdersoft_shopping_cart:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0099</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:55:27.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:27:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16126">16126</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl">http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/1401">1401</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0100">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nicosw:nicoftp:3.0.1.19" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nicosw:nicoftp:3.0.1.19</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0100</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:21.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:30:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded">20060102 NicoFTP Stack Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/317">317</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the "Name of site" field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0101">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sblog:sblog:0.7.1_build2005-12-02_beta" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sblog:sblog:0.7.1_build2005-12-02_beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0101</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:21.747-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23979">sblog-multiple-scripts-xss(23979)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22374">22374</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22373">22373</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0041">ADV-2006-0041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22373-sblog.txt">http://osvdb.org/ref/22/22373-sblog.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0102">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.46" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.47" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.48" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.49" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.499" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.5" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.47</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.48</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.46</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.499</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.49</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.5</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0102</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:21.887-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22256">22256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015436">1015436</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18293">18293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/14/summary.html">http://evuln.com/vulns/14/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/320">320</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0103">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.46" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.47" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.48" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.49" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.499" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.5" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.47</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.48</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.46</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.499</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.49</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.5</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0103</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:55:31.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded">20060417 Tiny PHP forum - vulns</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22257">22257</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015436">1015436</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18293">18293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/14/summary.html">http://evuln.com/vulns/14/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24016">tinyphpforum-users-information-disclosure(24016)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/320">320</vuln:reference>
        </vuln:references>
        <vuln:summary>TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0104">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.46" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.47" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.48" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.49" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.499" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.5" />
                <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.47</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.48</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.46</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.499</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.49</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.5</vuln:product>
            <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0104</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:22.217-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-06T08:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18293">18293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/14/summary.html">http://evuln.com/vulns/14/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/14/exploit.html">http://evuln.com/vulns/14/exploit.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16163">16163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22258">22258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015436">1015436</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/320">320</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0106">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wine:wine:0.9.2" />
                <cpe-lang:fact-ref name="cpe:/a:wine:wine:0.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:wine:wine:0.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:wine:wine:2005-09-30" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wine:wine:0.9.4</vuln:product>
            <vuln:product>cpe:/a:wine:wine:2005-09-30</vuln:product>
            <vuln:product>cpe:/a:wine:wine:0.9.5</vuln:product>
            <vuln:product>cpe:/a:wine:wine:0.9.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0106</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T13:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:22.543-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0098">ADV-2006-0098</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18323">18323</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html">[Dailydave] 20060105 WMF goes away :&lt;</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23846">win-wmf-execute-code(23846)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml">GLSA-200601-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-954">DSA-954</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18578">18578</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18549">18549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18451">18451</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</vuln:reference>
        </vuln:references>
        <vuln:summary>gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0107">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:idea_development_id_oy:timecan_cms" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:idea_development_id_oy:timecan_cms</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0107</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:22.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16159">16159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22252">22252</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18324">18324</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24014">timecancms-sql-injection(24014)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0108">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:idea_development_id_oy:timecan_cms" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:idea_development_id_oy:timecan_cms</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0108</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:22.857-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22253">22253</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22252">22252</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0078">ADV-2006-0078</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24014">timecancms-sql-injection(24014)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0109">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:modular_merchant:shopping_cart" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:modular_merchant:shopping_cart</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0109</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:23.013-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:40:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18320">18320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16160">16160</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22243">22243</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.modularmerchant.com/forums/viewtopic.php?t=46">http://www.modularmerchant.com/forums/viewtopic.php?t=46</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0076">ADV-2006-0076</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22243-modular.txt">http://osvdb.org/ref/22/22243-modular.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://attrition.org/pipermail/vim/2006-February/000548.html">20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0110">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:javier_suarez_sanz:foro_domus:2.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:javier_suarez_sanz:foro_domus:2.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0110</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:23.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-05-11T10:55:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16154">16154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded">20060106 [eVuln] Proyecto Domus 'email' XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22263">22263</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0073">ADV-2006-0073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18327">18327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/16/summary.html">http://evuln.com/vulns/16/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24020">domus-escribir-xss(24020)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0111">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:boxcar_media:shopping_cart" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:boxcar_media:shopping_cart</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0111</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:23.403-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24019">boxcar-index-xss(24019)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22360">22360</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0080">ADV-2006-0080</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22360-boxcar.txt">http://osvdb.org/ref/22/22360-boxcar.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0112">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0112</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T20:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:23.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:33:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22201">22201</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0036">ADV-2006-0036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18310">18310</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22201-espg.txt">http://osvdb.org/ref/22/22201-espg.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0113">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0113</vuln:cve-id>
        <vuln:published-datetime>2006-01-06T20:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:23.733-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18310">18310</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22201-espg.txt">http://osvdb.org/ref/22/22201-espg.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22417">22417</vuln:reference>
        </vuln:references>
        <vuln:summary>Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0114">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:joomla:joomla:1.0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0114</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-09T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:23.873-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T08:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16185">16185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0097">ADV-2006-0097</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18361">18361</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://forum.joomla.org/index.php/topic,29031.0.html">http://forum.joomla.org/index.php/topic,29031.0.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://forge.joomla.org/sf/go/artf2950">http://forge.joomla.org/sf/go/artf2950</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24042">joomla-vcard-information-disclosure(24042)</vuln:reference>
        </vuln:references>
        <vuln:summary>The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0115">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oneplug_solutions:oneplug_cms" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:oneplug_solutions:oneplug_cms</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0115</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:24.030-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T08:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16155">16155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22250">22250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22249">22249</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22248">22248</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0079">ADV-2006-0079</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18325">18325</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22248-oneplug.txt">http://osvdb.org/ref/22/22248-oneplug.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0116">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:inetstore:inetstore_online" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:inetstore:inetstore_online</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0116</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:24.187-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T08:29:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16156">16156</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22251">22251</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0075">ADV-2006-0075</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.attrition.org/pipermail/vim/2006-January/000515.html">20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18322">18322</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22251-inetstore.txt">http://osvdb.org/ref/22/22251-inetstore.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0117">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0117</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:24.340-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T10:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16158">16158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18328">18328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24205">lotus-cdtomime-dos(24205)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".</vuln:summary>
    </entry>
    <entry id="CVE-2006-0118">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0118</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:24.530-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T10:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16158">16158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18328">18328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24206">lotus-long-formula-bo(24206)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0119">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0119</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:24.700-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16158">16158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18328">18328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/18020">18020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2564">ADV-2006-2564</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016390">1016390</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20855">20855</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/27413">domino-smtp-nrouter-dos(27413)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24211">lotus-web-unspecified-xss(24211)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24207">lotus-multiple-unspecified(24207)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</vuln:summary>
    </entry>
    <entry id="CVE-2006-0120">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0120</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:24.873-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:15:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16158">16158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18328">18328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24217">lotus-ssl-keyring-dos(24217)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24216">lotus-certificate-parsing-dos(24216)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24215">lotus-delete-attachment-dos(24215)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24214">lotus-bmp-dos(24214)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24213">lotus-compact-dos(24213)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24212">lotus-outofoffice-dos(24212)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</vuln:summary>
    </entry>
    <entry id="CVE-2006-0121">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0121</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:25.060-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:17:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16158">16158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18328">18328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24223">lotus-ssl-handshake-dos(24223)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0122">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:aquifer_cms:aquifer_cms" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:aquifer_cms:aquifer_cms</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0122</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:25.247-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:18:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22247">22247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16162">16162</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0074">ADV-2006-0074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18326">18326</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22247-aquifer.txt">http://osvdb.org/ref/22/22247-aquifer.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://attrition.org/pipermail/vim/2006-January/000509.html">20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0123">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0b" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:adn_forum:adn_forum:1.0</vuln:product>
            <vuln:product>cpe:/a:adn_forum:adn_forum:1.0b</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0123</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-05T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:25.387-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:23:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16157">16157</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded">20060105 [eVuln] ADNForum Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22241">22241</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22240">22240</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0077">ADV-2006-0077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015445">1015445</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18300">18300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/15/summary.html">http://evuln.com/vulns/15/summary.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0124">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0b" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:adn_forum:adn_forum:1.0</vuln:product>
            <vuln:product>cpe:/a:adn_forum:adn_forum:1.0b</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0124</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-04-03T00:46:08.983-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:24:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16157">16157</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded">20060105 [eVuln] ADNForum Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0077">ADV-2006-0077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18300">18300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/15/summary.html">http://evuln.com/vulns/15/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22242">22242</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015445">1015445</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0125">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:appserv_open_project:appserv:2.4.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:appserv_open_project:appserv:2.4.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0125</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:25.687-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:27:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22228">22228</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0053">ADV-2006-0053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18163">18163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16166">16166</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0126">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rxvt-unicode:rxvt-unicode:6.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rxvt-unicode:rxvt-unicode:6.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0126</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:25.840-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:30:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22223">22223</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0052">ADV-2006-0052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18301">18301</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://dist.schmorp.de/rxvt-unicode/Changes">http://dist.schmorp.de/rxvt-unicode/Changes</vuln:reference>
        </vuln:references>
        <vuln:summary>rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0127">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:6.1.22.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rockliffe:mailsite:6.1.22.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0127</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:25.983-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22229">22229</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0055">ADV-2006-0055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18318">18318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html">20060104 Rockliffe Directory Transversal Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html">20060105 Re: Rockliffe Directory Transversal Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0128">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:6.1.22.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rockliffe:mailsite:6.1.22.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0128</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:26.123-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html">20060104 Rockliffe Directory Transversal Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39991">rockliffe-imap-unspecified-bo(39991)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0129">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:7.0.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rockliffe:mailsite:7.0.3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0129</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:26.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0055">ADV-2006-0055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18318">18318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22230">22230</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html">20060104 Rockliffe Mailsite User Enumeration Flaw</vuln:reference>
        </vuln:references>
        <vuln:summary>Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0130">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:7.0.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rockliffe:mailsite:7.0.3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0130</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:26.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:10:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html">20060104 Rockliffe Mailsite User Enumeration Flaw</vuln:reference>
        </vuln:references>
        <vuln:summary>Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0131">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:boastmachine:boastmachine:3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:boastmachine:boastmachine:3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0131</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:26.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://echo.or.id/adv/adv26-K-159-2006.txt">http://echo.or.id/adv/adv26-K-159-2006.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0132">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:webftp:webftp:1.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:webftp:webftp:1.2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0132</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:26.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0090">ADV-2006-0090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18355">18355</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16175">16175</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded">20060104 SysCP WebFTP local file inclusion vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24018">webftp-language-file-include(24018)</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0133">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3_ml03" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:5.3_ml03</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0133</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:26.873-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>3.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16103">16103</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16102">16102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015429">1015429</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0134">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:thewebforum:thewebforum:1.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:thewebforum:thewebforum:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0134</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:27.027-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:18:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16161">16161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0093">ADV-2006-0093</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015450">1015450</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18392">18392</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/17/summary.html">http://evuln.com/vulns/17/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/17/exploit.html">http://evuln.com/vulns/17/exploit.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24007">thewebforum-register-xss(24007)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22295">22295</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0135">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:thewebforum:thewebforum:1.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:thewebforum:thewebforum:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0135</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:27.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:20:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16161">16161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0093">ADV-2006-0093</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015450">1015450</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18392">18392</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/17/summary.html">http://evuln.com/vulns/17/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/17/exploit.html">http://evuln.com/vulns/17/exploit.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24027">thewebforum-login-sql-injection(24027)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22294">22294</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/321">321</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</vuln:summary>
    </entry>
    <entry id="CVE-2006-0136">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phanatic_softwares:chimera_web_portal:0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phanatic_softwares:chimera_web_portal:0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0136</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:27.310-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:24:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16113">16113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0025">ADV-2006-0025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/7/summary.html">http://evuln.com/vulns/7/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/7/exploit.html">http://evuln.com/vulns/7/exploit.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0137">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phanatic_softwares:chimera_web_portal:0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phanatic_softwares:chimera_web_portal:0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0137</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:27.467-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:24:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16113">16113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0025">ADV-2006-0025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/7/summary.html">http://evuln.com/vulns/7/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/7/exploit.html">http://evuln.com/vulns/7/exploit.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23963">chimera-linkcategory-sql-injection(23963)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22420">22420</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0138">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amsn:amsn" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amsn:amsn</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0138</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:27.607-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/exploits/5JP090KHFQ.html">http://www.securiteam.com/exploits/5JP090KHFQ.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22186">22186</vuln:reference>
        </vuln:references>
        <vuln:summary>aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</vuln:summary>
    </entry>
    <entry id="CVE-2006-0139">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pd9_software:megabbs:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:pd9_software:megabbs:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pd9_software:megabbs:2.0</vuln:product>
            <vuln:product>cpe:/a:pd9_software:megabbs:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0139</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T13:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:27.763-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T13:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16168">16168</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924">http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.hamid.ir/security/megabbs.txt">http://www.hamid.ir/security/megabbs.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0095">ADV-2006-0095</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18342">18342</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24050">megabbs-sendprivatemessage-disclosure(24050)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015452">1015452</vuln:reference>
        </vuln:references>
        <vuln:summary>The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0140">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:navboard:navboard:16" />
                <cpe-lang:fact-ref name="cpe:/a:navboard:navboard:17:beta2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:navboard:navboard:17:beta2</vuln:product>
            <vuln:product>cpe:/a:navboard:navboard:16</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0140</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T14:07:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-22T17:15:32.960-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24021">navboard-post-xss(24021)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16165">16165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22277">22277</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0092">ADV-2006-0092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18345">18345</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/19/summary.html">http://evuln.com/vulns/19/summary.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0141">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eudora:internet_mail_server:3.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:eudora:internet_mail_server:3.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:eudora:internet_mail_server:3.2.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eudora:internet_mail_server:3.2.7</vuln:product>
            <vuln:product>cpe:/a:eudora:internet_mail_server:3.2.6</vuln:product>
            <vuln:product>cpe:/a:eudora:internet_mail_server:3.2.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0141</vuln:cve-id>
        <vuln:discovered-datetime>2006-01-09T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-09T14:07:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:28.077-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-05-10T15:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0099">ADV-2006-0099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.eudora.co.nz/updates.html">http://www.eudora.co.nz/updates.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18356">18356</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16179">16179</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24033">eims-corrupted-mail-dos(24033)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24032">eims-ntlm-auth-dos(24032)</vuln:reference>
        </vuln:references>
        <vuln:summary>Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0142">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:andromeda_software:andromeda:1.9.3.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:andromeda_software:andromeda:1.9.3.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0142</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T14:07:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:28.217-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T09:01:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16183">16183</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0096">ADV-2006-0096</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18359">18359</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24031">andromeda-script-xss(24031)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0143">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0143</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T15:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:28.373-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:58:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015453">1015453</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16167">16167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0115">ADV-2006-0115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx">http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24044">win-gre-wmf-dos(24044)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0083">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:stefan_frings:sms_server_tools" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:stefan_frings:sms_server_tools</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0083</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T15:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:18.467-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-09T15:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18357">18357</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24034">smstools-logging-format-string(24034)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16188">16188</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22287">22287</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-930">DSA-930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18343">18343</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0144">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache2triad:apache2triad" />
                <cpe-lang:fact-ref name="cpe:/a:php:pear:0.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache2triad:apache2triad</vuln:product>
            <vuln:product>cpe:/a:php:pear:0.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0144</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:28.623-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0148">ADV-2006-0148</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18390">18390</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24076">gopear-proxy-redirection(24076)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16174">16174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded">20060109 New PEAR / Apache2Triad Exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://apache2triad.net/forums/viewtopic.php?p=14670">http://apache2triad.net/forums/viewtopic.php?p=14670</vuln:reference>
        </vuln:references>
        <vuln:summary>The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0145">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6:beta" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:netbsd:netbsd:2.0</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.6:beta</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:2.1</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:2.0.1</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.6.2</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:2.0.3</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:2.0.2</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0145</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:28.777-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16173">16173</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html">http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22293">22293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18712">18712</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18388">18388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NETBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">NetBSD-SA2006-001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24035">netbsd-kernfs-memory-disclosure(24035)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/405">405</vuln:reference>
        </vuln:references>
        <vuln:summary>The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0146">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.66" />
                <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.68" />
                <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:0.19.4" />
                <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:1.0.0_rc4" />
                <cpe-lang:fact-ref name="cpe:/a:mediabeez:mediabeez" />
                <cpe-lang:fact-ref name="cpe:/a:moodle:moodle:1.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.761" />
                <cpe-lang:fact-ref name="cpe:/a:the_cacti_group:cacti:0.8.6g" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mediabeez:mediabeez</vuln:product>
            <vuln:product>cpe:/a:mantis:mantis:0.19.4</vuln:product>
            <vuln:product>cpe:/a:the_cacti_group:cacti:0.8.6g</vuln:product>
            <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.761</vuln:product>
            <vuln:product>cpe:/a:mantis:mantis:1.0.0_rc4</vuln:product>
            <vuln:product>cpe:/a:john_lim:adodb:4.68</vuln:product>
            <vuln:product>cpe:/a:john_lim:adodb:4.66</vuln:product>
            <vuln:product>cpe:/a:moodle:moodle:1.5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0146</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:28.937-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.xaraya.com/index.php/news/569">http://www.xaraya.com/index.php/news/569</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16187">16187</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded">20060202 Bug for libs in php link directory 2.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22290">22290</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/1419">ADV-2006-1419</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/1304">ADV-2006-1304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0447">ADV-2006-0447</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0370">ADV-2006-0370</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0105">ADV-2006-0105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0104">ADV-2006-0104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0103">ADV-2006-0103</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0101">ADV-2006-0101</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1031">DSA-1031</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1030">DSA-1030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1029">DSA-1029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/secunia_research/2005-64/advisory/">http://secunia.com/secunia_research/2005-64/advisory/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19699">19699</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19591">19591</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19590">19590</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19563">19563</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19555">19555</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18720">18720</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18276">18276</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18260">18260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18233">18233</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17418">17418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24051">adodb-server-command-execution(24051)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded">20070418 MediaBeez Sql query Execution .. Wear isn't ?? :)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.maxdev.com/Article550.phtml">http://www.maxdev.com/Article550.phtml</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/1305">ADV-2006-1305</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0102">ADV-2006-0102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/713">713</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24954">24954</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19691">19691</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19600">19600</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18267">18267</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18254">18254</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</vuln:reference>
        </vuln:references>
        <vuln:summary>The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0147">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.66" />
                <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.68" />
                <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:0.19.4" />
                <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:1.0.0_rc4" />
                <cpe-lang:fact-ref name="cpe:/a:moodle:moodle:1.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.761" />
                <cpe-lang:fact-ref name="cpe:/a:the_cacti_group:cacti:0.8.6g" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mantis:mantis:0.19.4</vuln:product>
            <vuln:product>cpe:/a:the_cacti_group:cacti:0.8.6g</vuln:product>
            <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.761</vuln:product>
            <vuln:product>cpe:/a:mantis:mantis:1.0.0_rc4</vuln:product>
            <vuln:product>cpe:/a:john_lim:adodb:4.68</vuln:product>
            <vuln:product>cpe:/a:john_lim:adodb:4.66</vuln:product>
            <vuln:product>cpe:/a:moodle:moodle:1.5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0147</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:29.107-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22291">22291</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0104">ADV-2006-0104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0103">ADV-2006-0103</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0102">ADV-2006-0102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0101">ADV-2006-0101</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1030">DSA-1030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1029">DSA-1029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/secunia_research/2005-64/advisory/">http://secunia.com/secunia_research/2005-64/advisory/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19628">19628</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19591">19591</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19590">19590</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19555">19555</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18276">18276</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18260">18260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18254">18254</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18233">18233</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17418">17418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/1305">ADV-2006-1305</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1031">DSA-1031</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19600">19600</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18267">18267</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/simplog_092_incl_xpl.html">http://retrogod.altervista.org/simplog_092_incl_xpl.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/1663">1663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24052">adodb-tmssql-command-execution(24052)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19691">19691</vuln:reference>
        </vuln:references>
        <vuln:summary>Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0148">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:netsarang:xlpd:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:netsarang:xlpd:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0148</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:29.263-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16164">16164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ipomonis.com/advisories/xlpd.txt">http://www.ipomonis.com/advisories/xlpd.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015444">1015444</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24041">xlpd-connection-dos(24041)</vuln:reference>
        </vuln:references>
        <vuln:summary>NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0149">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:simpbook:simpbook:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:simpbook:simpbook:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0149</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:29.403-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:42:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015451">1015451</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html">20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0150">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.4.2</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.4.0</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.4.3</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.4</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.2</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.3</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.0</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.6.0</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.1</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.3</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.4</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.1</vuln:product>
            <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0150</vuln:cve-id>
        <vuln:discovered-datetime>2005-12-22T00:00:00.000-05:00</vuln:discovered-datetime>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:29.560-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:46:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017">MDKSA-2006:017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16177">16177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0179.html">RHSA-2006:0179</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0117">ADV-2006-0117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-952">DSA-952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18568">18568</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18412">18412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18405">18405</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18382">18382</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.rudedog.org/auth_ldap/Changes.html">http://www.rudedog.org/auth_ldap/Changes.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.digitalarmaments.com/2006090173928420.html">http://www.digitalarmaments.com/2006090173928420.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015456">1015456</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24030">apache-authldap-format-string(24030)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0151">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.7" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.8" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.9" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p1" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p2" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p3" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p4" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p5" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p6" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p7" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4_p1" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4_p2" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5_p1" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5_p2" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.6" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7_p5" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p1" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p12" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p2" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p5" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p7" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p8" />
                <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::amd64" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::i386" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::powerpc" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::amd64" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::i386" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p9</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p8</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p7</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.4_p2</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p5</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.4_p1</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.5_p2</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p2</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.5_p1</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p1</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p1</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p2</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p7</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p12</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p3</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p4</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::powerpc</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p5</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::i386</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p6</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::amd64</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.6</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.5</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.8</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.7</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.2</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.1</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.4</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.3</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.5.7</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.5.6</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.5.9</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::i386</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.5.8</vuln:product>
            <vuln:product>cpe:/a:todd_miller:sudo:1.6.7_p5</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::amd64</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0151</vuln:cve-id>
        <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:29.730-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T09:22:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18363">18363</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2">USN-235-2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16184">16184</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18358">18358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2006/0010">2006-0010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-946">DSA-946</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822">SSA:2006-045-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21692">21692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19016">19016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18906">18906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18558">18558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18549">18549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</vuln:reference>
        </vuln:references>
        <vuln:summary>sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0152">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpchamber:phpchamber:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpchamber:phpchamber:1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0152</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:29.980-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16180">16180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0094">ADV-2006-0094</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18360">18360</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24029">phpchamber-searchresult-xss(24029)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22282">22282</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0153">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2.1</vuln:product>
            <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0153</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:30.123-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16178">16178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18354">18354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/18/summary.html">http://evuln.com/vulns/18/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24038">427bb-scripts-security-bypass(24038)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22274">22274</vuln:reference>
        </vuln:references>
        <vuln:summary>427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0154">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2.1</vuln:product>
            <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0154</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:30.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16169">16169</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18354">18354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/18/summary.html">http://evuln.com/vulns/18/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24039">427bb-showthread-sql-injection(24039)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22275">22275</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0155">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2.1</vuln:product>
            <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0155</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:30.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18354">18354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/18/summary.html">http://evuln.com/vulns/18/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24040">427bb-posts-xss(24040)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22276">22276</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0156">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:foxrum:foxrum:4.0.4f" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:foxrum:foxrum:4.0.4f</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0156</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:30.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16172">16172</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0121">ADV-2006-0121</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18386">18386</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/20">http://evuln.com/vulns/20</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24043">foxrum-bbcode-xss(24043)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/325">325</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0157">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:reamday_enterprises:magic_news_plus:1.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:reamday_enterprises:magic_news_plus:1.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0157</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:30.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:18:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16182">16182</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl">http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18601">18601</vuln:reference>
        </vuln:references>
        <vuln:summary>settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0158">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cyberdoc:sitesuite_cms" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:cyberdoc:sitesuite_cms</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0158</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:30.857-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22205">22205</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0038">ADV-2006-0038</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18305">18305</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/ref/22/22205-sitesuite.txt">http://osvdb.org/ref/22/22205-sitesuite.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0159">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:javier_suarez_sanz:foro_domus:2.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2006-0159</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:31.013-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:23:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22264">22264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0073">ADV-2006-0073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18327">18327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24017">domus-escribir-sql-injection(24017)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0160">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:venom_board:venom_board:1.22" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:venom_board:venom_board:1.22</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0160</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:31.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-10T08:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24046">venomboard-addpost-sql-injection(24046)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16176">16176</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22297">22297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0122">ADV-2006-0122</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18383">18383</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2">20060109 [eVuln] Venom Board SQL Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2">20060109 [eVuln] Venom Board SQL Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://evuln.com/vulns/21/summary.html">http://evuln.com/vulns/21/summary.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/326">326</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0161">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0161</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T14:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:31.310-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:51:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1534" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1">101933</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0113">ADV-2006-0113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015455">1015455</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19087">19087</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18371">18371</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0162">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:." />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.51" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.52" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.53" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.54" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.65" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.67" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68.1" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.70" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.75.1" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc3" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc4" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.81" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.82" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.83" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85.1" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.1" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.2" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87" />
                <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87.1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc2</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.2</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc4</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc2</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc3</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:.</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68.1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.67</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.83</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.65</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.82</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.81</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85.1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.75.1</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.51</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.70</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.52</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.53</vuln:product>
            <vuln:product>cpe:/a:clam_anti-virus:clamav:0.54</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0162</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T14:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:31.467-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/385908">VU#385908</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16191">16191</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0116">ADV-2006-0116</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18379">18379</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.clamav.net/doc/0.88/ChangeLog">http://www.clamav.net/doc/0.88/ChangeLog</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24047">clamav-libclamav-upx-bo(24047)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html">http://www.zerodayinitiative.com/advisories/ZDI-06-001.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2006/0002/">2006-0002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22318">22318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml">GLSA-200601-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-947">DSA-947</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015457">1015457</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/342">342</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18548">18548</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18478">18478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18463">18463</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18453">18453</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0105">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:postgresql:postgresql:8.1.0</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.1.1</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0.3</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0.2</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0.5</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0.4</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0105</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T15:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:22.387-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24049">postgresql-connection-request-dos(24049)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16201">16201</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.postgresql.org/about/news.456">http://www.postgresql.org/about/news.456</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0114">ADV-2006-0114</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015482">1015482</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/327">327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18419">18419</vuln:reference>
        </vuln:references>
        <vuln:summary>PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0020">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0020</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:08.483-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1638" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638" />
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/312956">VU#312956</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16516">16516</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx">MS06-004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0469">ADV-2006-0469</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18729">18729</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22976">22976</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/advisory/913333.mspx">http://www.microsoft.com/technet/security/advisory/913333.mspx</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18912">18912</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://linuxbox.org/pipermail/funsec/2006-January/002828.html">[funsec] 20060110 Another WMF flaw without a Microsoft patch</vuln:reference>
        </vuln:references>
        <vuln:summary>An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</vuln:summary>
    </entry>
    <entry id="CVE-2006-0010">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp2" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp3" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp4" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp5" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp5:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server_alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp5</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp4</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp3</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp5:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp2</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server_alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:alpha</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0010</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T17:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:714" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:698" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1491" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1462" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1185" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1126" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126" />
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/915930">VU#915930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16194">16194</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx">MS06-002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0118">ADV-2006-0118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18365">18365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23922">win-embedded-fonts-bo(23922)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/18829">18829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>EEYE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html">EEYEB20050801</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015459">1015459</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18391">18391</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18311">18311</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0002">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp4" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
            <vuln:product>cpe:/a:microsoft:outlook:2000:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.0:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.0:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:outlook:2002:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp4</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
            <vuln:product>cpe:/a:microsoft:exchange_server:5.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0002</vuln:cve-id>
        <vuln:published-datetime>2006-01-10T17:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:05.437-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T08:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:624" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1485" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1456" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1316" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1165" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1082" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/252146">VU#252146</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16197">16197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded">20060110 Microsoft Outlook Critical Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded">20060110 Microsoft Exchange Critical Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx">MS06-003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0119">ADV-2006-0119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015461">1015461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015460">1015460</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18368">18368</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/22878">win-tnef-overflow(22878)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/331">331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/330">330</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0035">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0035</vuln:cve-id>
        <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:11.247-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-11T16:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2006/0004">2006-0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18482">18482</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16414">16414</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24202">kernel-afnetlink-dos(24202)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0220">ADV-2006-0220</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/388">388</vuln:reference>
        </vuln:references>
        <vuln:summary>The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0054">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:stable" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:6.0:stable</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:6.0:release</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0054</vuln:cve-id>
        <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:14.483-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-12T07:57:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16209">16209</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18378">18378</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc">FreeBSD-SA-06:04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24073">ipfw-icmp-fragment-dos(24073)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22319">22319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015477">1015477</vuln:reference>
        </vuln:references>
        <vuln:summary>The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0055">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release_p8" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:release_p3" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:stable" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:release_p14" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:alpha" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release_p5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:stable" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:pre-release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:releng" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:stable" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:5.0:alpha</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.10:release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.3:stable</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.11:stable</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.0:release_p14</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.10:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.3:release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.4:pre-release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.10:release_p8</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.3:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:6.0:stable</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.0:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.11:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.4:release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.1:release_p5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.10</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:6.0:release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.1:alpha</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.11:release_p3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.4:releng</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0055</vuln:cve-id>
        <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:14.637-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-12T08:01:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16207">16207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18404">18404</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc">FreeBSD-SA-06:02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/24074">ee-ispell-op-symlink(24074)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22320">22320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015469">1015469</vuln:reference>
        </vuln:references>
        <vuln:summary>The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0163">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke_ev:7.7_r1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke_ev:7.7_r1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0163</vuln:cve-id>
        <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-03T00:45:56.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-12T08:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/44978">phpnukeev-search-sql-injection(44978)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16186">16186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22316">22316</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0120">ADV-2006-0120</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18394">18394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html">http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</vuln:summary>
    </entry>
    <entry id="CVE-2006-0164">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.1" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.2" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.3" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.4" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.3</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.4</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.1</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.2</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.3.1</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.4.1</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.4.2</vuln:product>
            <vuln:product>cpe:/a:woah-projekt:phgstats:0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-0164</vuln:cve-id>
        <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:58:31.810-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-12T08:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_O