CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-6840

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6841

    Last Modified: 23 Apr 2026

    Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6842

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6844

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the user comment form.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6851

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to inject arbitrary web script or HTML via the (1) email or (2) errr parameter.

    Published: 31 Dec 2006
    6
    Medium

    CVE-2006-6852

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml. NOTE: some of these details are obtained from third party information.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6856

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script.

    Published: 31 Dec 2006
    4.3
    Medium

    CVE-2006-6857

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules/credits/credits.php in Docebo LMS allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6858

    Last Modified: 23 Apr 2026

    Miredo 0.9.8 through 1.0.5 does not properly authenticate a Teredo bubble during UDP hole punching with HMAC-MD5-64 hashing, which allows remote attackers to impersonate an arbitrary Teredo client.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6859

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6860

    Last Modified: 23 Apr 2026

    Buffer overflow in the sendToMythTV function in MythControlServer.c in MythControl 1.0 and earlier allows remote attackers to execute arbitrary code via a crafted sendStr string to the Bluetooth interface. NOTE: some of these details are obtained from third party information.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6864

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter.

    Published: 31 Dec 2006
    7.8
    High

    CVE-2006-6866

    Last Modified: 23 Apr 2026

    STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6867

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3) bu/bu_parse.php, different vectors and a different affected version than CVE-2006-6809.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6868

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Dec 2006
    7.8
    High

    CVE-2006-6865

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitrary files via a %c0%ae. (Unicode dot dot) in the path parameter, which bypasses the checks for ".." sequences.

    Published: 31 Dec 2006
    5
    Medium

    CVE-2006-6872

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6873

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in mod.php in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via (1) the did parameter in a (a) viewdisk operation (diskusi mod), or the (2) cid parameter in a (b) viewlink (katalog mod) or (b) viewcat (diskusi mod) operation.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6874

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in friend.php in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Message or (2) Your Name field. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6875

    Last Modified: 23 Apr 2026

    Buffer overflow in the validateospheader function in the Open Settlement Protocol (OSP) module in OpenSER 1.1.0 and earlier allows remote attackers to execute arbitrary code via a crafted OSP header.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6876

    Last Modified: 23 Apr 2026

    Buffer overflow in the fetchsms function in the SMS handling module (libsms_getsms.c) in OpenSER 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SMS message, triggering memory corruption when the "beginning" buffer is copied to the third (pdu) argument.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6871

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewlink operation in mod.php, (2) the intypeid parameter in a showinfo operation in the informasi module in mod.php, (3) the "your Friend" field in friend.php, or (4) the "Main Text" field in admin.php.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6880

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6881

    Last Modified: 23 Apr 2026

    Buffer overflow in the Get_Wep function in cofvnet.c for ATMEL Linux PCI PCMCIA USB Drivers drivers 3.4.1.1 corruption allows attackers to execute arbitrary code via a long name argument.

    Published: 31 Dec 2006
    4.3
    Medium

    CVE-2006-6882

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in golden book allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6883

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in php4you.php in PHPIrc_bot 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE, since the dir variable is declared before being used

    Published: 31 Dec 2006
    9.3
    Critical

    CVE-2006-6884

    Last Modified: 23 Apr 2026

    Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.

    Published: 31 Dec 2006
    4.3
    Medium

    CVE-2006-6885

    Last Modified: 23 Apr 2026

    An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6889

    Last Modified: 23 Apr 2026

    FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6890

    Last Modified: 23 Apr 2026

    Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.

    Published: 31 Dec 2006
    5
    Medium

    CVE-2006-6891

    Last Modified: 23 Apr 2026

    Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6892

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the GetLocation function in online.php in Jonathon J. Freeman OvBB 0.13a allows remote attackers to inject arbitrary web script or HTML via the aRequest variable.

    Published: 31 Dec 2006
    7.8
    High

    CVE-2006-6898

    Last Modified: 23 Apr 2026

    Widcomm Bluetooth for Windows (BTW) before 4.0.1.1500 allows remote attackers to listen to and record conversations, aka the CarWhisperer attack.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6900

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6901

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6902

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Bluetooth stack in Microsoft Windows Mobile Pocket PC edition allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6905

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

    Published: 31 Dec 2006
    10
    Critical

    CVE-2006-6907

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Bluesoil Bluetooth stack has unknown impact and attack vectors.

    Published: 31 Dec 2006
    7.8
    High

    CVE-2006-6910

    Last Modified: 23 Apr 2026

    formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-7231

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in display.asp in Civica Software Civica allows remote attackers to execute arbitrary SQL commands via the Entry parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2006
    4.3
    Medium

    CVE-2006-7233

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.6.0, and possibly other versions before 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 31 Dec 2006
    5
    Medium

    CVE-2006-4579

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-4580

    Last Modified: 23 Apr 2026

    register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".

    Published: 31 Dec 2006
    5
    Medium

    CVE-2006-5265

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS) message.

    Published: 31 Dec 2006
    1.7
    Low

    CVE-2006-5749

    Last Modified: 23 Apr 2026

    The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.

    Published: 31 Dec 2006
    5
    Medium

    CVE-2006-5858

    Last Modified: 23 Apr 2026

    Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.

    Published: 31 Dec 2006
    6.8
    Medium

    CVE-2006-6845

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.

    Published: 31 Dec 2006
    5
    Medium

    CVE-2006-6847

    Last Modified: 23 Apr 2026

    An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6848

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO, possibly related to the Password parameter.

    Published: 31 Dec 2006
    7.5
    High

    CVE-2006-6854

    Last Modified: 23 Apr 2026

    The qcamvc_video_init function in qcamvc.c in De Marchi Daniele QuickCam VC Linux device driver (aka quickcam-vc) 1.0.9 and earlier does not properly check a boundary, triggering memory corruption, which might allow attackers to execute arbitrary code via a crafted QuickCam object.

    Published: 31 Dec 2006