CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-6824

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d also affect 2.24.

    Published: 29 Dec 2006
    7.5
    High

    CVE-2006-6812

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.

    Published: 29 Dec 2006
    7.5
    High

    CVE-2006-6813

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 29 Dec 2006
    6.3
    Medium

    CVE-2006-6814

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath parameter.

    Published: 29 Dec 2006
    7.5
    High

    CVE-2006-6816

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel; (4) the sent parameter to (a) login.asp, (b) content.asp, and (c) members.asp in the Remote-WebSite; and (5) the sent parameter to applications/SecureLoginManager/inc_secureloginmanager.asp in the Live Demo.

    Published: 29 Dec 2006
    7.5
    High

    CVE-2006-6818

    Last Modified: 23 Apr 2026

    AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.

    Published: 29 Dec 2006
    3.5
    Low

    CVE-2006-6820

    Last Modified: 23 Apr 2026

    myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Published: 29 Dec 2006
    3.5
    Low

    CVE-2006-6821

    Last Modified: 23 Apr 2026

    myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Published: 29 Dec 2006
    5
    Medium

    CVE-2006-6810

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a denial of service (application crash) via crafted network traffic, which triggers memory corruption.

    Published: 29 Dec 2006
    6.4
    Medium

    CVE-2006-6819

    Last Modified: 23 Apr 2026

    AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.

    Published: 29 Dec 2006
    6.8
    Medium

    CVE-2006-6800

    Last Modified: 23 Apr 2026

    PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6805

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6806

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6807

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6799

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6802

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6801

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the news_cfg[path] parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6803

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6804

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6808

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.

    Published: 28 Dec 2006
    5
    Medium

    CVE-2006-6318

    Last Modified: 23 Apr 2026

    The show_elog_list function in elogd.c in elog 2.6.2 and earlier allows remote authenticated users to cause a denial of service (daemon crash) by attempting to access a logbook whose name begins with "global," which results in a NULL pointer dereference. NOTE: some of these details are obtained from third party information.

    Published: 28 Dec 2006
    6.6
    Medium

    CVE-2006-6797

    Last Modified: 23 Apr 2026

    The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnerability than CVE-2006-6696.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6777

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6778

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6779

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6780

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary SQL commands via the killLimit parameter.

    Published: 28 Dec 2006
    5
    Medium

    CVE-2006-6781

    Last Modified: 23 Apr 2026

    HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[lastName][] parameters, which reveals the path in an error message.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6782

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in pnamazu 2006.02.28 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6787

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6788

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LuckyBot 3 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) run.php or (2) ircbot.class.php.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6789

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6790

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6791

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SelGruFra.asp in chatwm 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) txtUse and (2) txtPas parameters.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6794

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the grup parameter.

    Published: 28 Dec 2006
    6.8
    Medium

    CVE-2006-6796

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ins_file parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6793

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ataturk.php in Okul Merkezi Portal 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 28 Dec 2006
    5.4
    Medium

    CVE-2006-6899

    Last Modified: 23 Apr 2026

    hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6785

    Last Modified: 23 Apr 2026

    The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6795

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6776

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6784

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Netbula Anyboard allows remote attackers to execute arbitrary SQL commands via the user name in the login form.

    Published: 28 Dec 2006
    6.5
    Medium

    CVE-2006-6786

    Last Modified: 23 Apr 2026

    Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6783

    Last Modified: 23 Apr 2026

    logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), possibly because of an authentication bypass. NOTE: some of these details are obtained from third party information.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6792

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Dec 2006
    7.5
    High

    CVE-2006-6773

    Last Modified: 23 Apr 2026

    pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1.

    Published: 27 Dec 2006
    3.5
    Low

    CVE-2006-6775

    Last Modified: 23 Apr 2026

    acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.

    Published: 27 Dec 2006
    6.8
    Medium

    CVE-2006-6770

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.

    Published: 27 Dec 2006
    6.8
    Medium

    CVE-2006-6771

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[PTH][func] parameter in (a) scripts/gallery.scr.php; the (2) GLOBALS[PTH][spaw] parameter in (b) scripts/xtextarea.scr.php; and the (3) GLOBALS[PTH][classes] parameter in (c) sitemap.scr.php, (d) news.scr.php, (e) polls.scr.php, (f) rss.scr.php, (g) search.scr.php in scripts/, and (h) form.fun.php, (i) general.func.php, (j) groups.func.php, (k) js.func.php, (l) sections.func.php, and (m) users.func.php in functions/.

    Published: 27 Dec 2006
    6.8
    Medium

    CVE-2006-6774

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Content Federator 1.0 allows remote attackers to execute arbitrary PHP code via the path parameter. NOTE: some of these details are obtained from third party information.

    Published: 27 Dec 2006
    6.8
    Medium

    CVE-2006-6769

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search_string parameter in (a) setup/transcripts.php, the (2) l parameter in (b) index.php, the (3) login field in (c) phplive/index.php, and the (4) deptid and (5) x parameters in (d) phplive/message_box.php.

    Published: 27 Dec 2006