CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-6720

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index_sitios.php in Azucar CMS 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _VIEW parameter.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6721

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6716

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter.

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6722

    Last Modified: 23 Apr 2026

    Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6700

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in @Mail WebMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 23 Dec 2006
    6.5
    Medium

    CVE-2006-6706

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors in certain web pages.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6708

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6709

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.

    Published: 23 Dec 2006
    5
    Medium

    CVE-2006-6699

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter to (1) calendarDialog.jsp or (2) fred.jsp. NOTE: the calendar.jsp vector is covered by CVE-2006-6697.

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6701

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6703

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.

    Published: 23 Dec 2006
    5
    Medium

    CVE-2006-6705

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allow remote attackers to bypass authentication mechanisms on web pages via unknown vectors.

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6711

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Published: 23 Dec 2006
    7.8
    High

    CVE-2006-6714

    Last Modified: 23 Apr 2026

    Multiple memory leaks in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allow remote attackers to cause a denial of service (memory consumption) via invalid LDAP requests.

    Published: 23 Dec 2006
    5.1
    Medium

    CVE-2006-6715

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6704

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "unescaped data in the database."

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6707

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Dec 2006
    7.5
    High

    CVE-2006-6710

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b) common.inc.php, and the CFG[localelangdir] parameter to (c) form_header.php.

    Published: 23 Dec 2006
    10
    Critical

    CVE-2006-6713

    Last Modified: 23 Apr 2026

    Buffer overflow in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allows remote attackers to execute arbitrary code via crafted LDAP requests.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6702

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML via crafted e-mail messages. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Dec 2006
    6.8
    Medium

    CVE-2006-6712

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SugarCRM Open Source 4.5.0f and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in crafted email messages.

    Published: 23 Dec 2006
    1.9
    Low

    CVE-2006-6698

    Last Modified: 23 Apr 2026

    The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome.

    Published: 22 Dec 2006
    7.5
    High

    CVE-2006-6697

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.

    Published: 22 Dec 2006
    6.9
    Medium

    CVE-2006-6696

    Last Modified: 23 Apr 2026

    Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.

    Published: 22 Dec 2006
    7.5
    High

    CVE-2007-3409

    Last Modified: 23 Apr 2026

    Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.

    Published: 22 Dec 2006
    4.3
    Medium

    CVE-2007-3377

    Last Modified: 23 Apr 2026

    Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

    Published: 22 Dec 2006
    7.5
    High

    CVE-2006-6689

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Paristemi 0.8.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the SERVER_DIRECTORY parameter to unspecified scripts, a different vector than CVE-2006-6739. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6690

    Last Modified: 23 Apr 2026

    rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6691

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6692

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2) zabbix_syslog.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6693

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long strings to the (1) zabbix_log and (2) zabbix_syslog functions.

    Published: 21 Dec 2006
    4.3
    Medium

    CVE-2006-6687

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    6.8
    Medium

    CVE-2006-6686

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6688

    Last Modified: 23 Apr 2026

    Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET) allows remote attackers to bypass filtering mechanisms via unknown vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6694

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php.

    Published: 21 Dec 2006
    6.8
    Medium

    CVE-2006-6695

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) error or (2) success parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    5
    Medium

    CVE-2006-6104

    Last Modified: 23 Apr 2026

    The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6681

    Last Modified: 23 Apr 2026

    Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6684

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd before 2.4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long X-Forwarded-For HTTP header. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    4.6
    Medium

    CVE-2006-6680

    Last Modified: 23 Apr 2026

    Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file.

    Published: 21 Dec 2006
    5
    Medium

    CVE-2006-6682

    Last Modified: 23 Apr 2026

    Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remote attackers to determine valid usernames on the system.

    Published: 21 Dec 2006
    7.8
    High

    CVE-2006-6683

    Last Modified: 23 Apr 2026

    Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the PAM configuration, which might allow remote attackers to bypass intended restrictions implemented through PAM.

    Published: 21 Dec 2006
    7.2
    High

    CVE-2006-6685

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6679

    Last Modified: 23 Apr 2026

    Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.

    Published: 21 Dec 2006
    2.6
    Low

    CVE-2006-6677

    Last Modified: 23 Apr 2026

    ESET NOD32 Antivirus before 1.1743 allows remote attackers to cause a denial of service (crash) via a crafted .CHM file that triggers a divide-by-zero error.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6678

    Last Modified: 23 Apr 2026

    The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.

    Published: 21 Dec 2006
    5
    Medium

    CVE-2006-6673

    Last Modified: 23 Apr 2026

    WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands.

    Published: 21 Dec 2006
    2.1
    Low

    CVE-2006-6674

    Last Modified: 23 Apr 2026

    Ozeki HTTP-SMS Gateway 1.0, and possibly earlier, stores usernames and passwords in plaintext in the HKLM\Software\Ozeki\SMSServer\CurrentVersion\Plugins\httpsmsgate registry key, which allows local users to obtain sensitive information.

    Published: 21 Dec 2006
    9.3
    Critical

    CVE-2006-6676

    Last Modified: 23 Apr 2026

    Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

    Published: 21 Dec 2006
    6.8
    Medium

    CVE-2006-6675

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.

    Published: 21 Dec 2006