CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-6593

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6592

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6595

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via "Manage Resources" and possibly other unspecified components.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6594

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in utilities/usermessages.asp in ScriptMate User Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the mesid parameter.

    Published: 15 Dec 2006
    6.8
    Medium

    CVE-2006-6587

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.

    Published: 15 Dec 2006
    6.4
    Medium

    CVE-2006-6585

    Last Modified: 23 Apr 2026

    The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.

    Published: 15 Dec 2006
    4.4
    Medium

    CVE-2006-6579

    Last Modified: 23 Apr 2026

    Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6588

    Last Modified: 23 Apr 2026

    The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6586

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter in (1) secure.php or (2) checklogin.php in admin/auth/.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6578

    Last Modified: 23 Apr 2026

    Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.

    Published: 15 Dec 2006
    6.8
    Medium

    CVE-2006-6577

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 15 Dec 2006
    6.4
    Medium

    CVE-2006-6580

    Last Modified: 23 Apr 2026

    admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and possibly have other impacts. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6581

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.

    Published: 15 Dec 2006
    6.8
    Medium

    CVE-2006-6582

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) members_username (user) and (2) members_password (password) fields in a login action in members/default.asp, and (3) the Search box. NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6583

    Last Modified: 23 Apr 2026

    ScriptMate User Manager 2.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors related to (1) the Logins box and (2) the Search box.

    Published: 15 Dec 2006
    10
    Critical

    CVE-2006-6584

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in italkplus (Italk+) before 0.92.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 15 Dec 2006
    6.8
    Medium

    CVE-2006-6589

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6590

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6591

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fonctions/template.php in EXlor 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the repphp parameter.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6576

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6575

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the LOGIN_style parameter.

    Published: 15 Dec 2006
    5
    Medium

    CVE-2006-6574

    Last Modified: 23 Apr 2026

    Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.

    Published: 15 Dec 2006
    7.8
    High

    CVE-2006-6569

    Last Modified: 23 Apr 2026

    form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2) chem parameters with a "modfich" floap parameter.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6570

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in GenesisTrader 1.0 allows remote authenticated users to upload arbitrary files via unspecified vectors, possibly involving form.php and the ajoutfich "foap" action.

    Published: 15 Dec 2006
    4
    Medium

    CVE-2006-6565

    Last Modified: 23 Apr 2026

    FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

    Published: 15 Dec 2006
    6.8
    Medium

    CVE-2006-6571

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other parameters.

    Published: 15 Dec 2006
    6.5
    Medium

    CVE-2006-6572

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than CVE-2006-4846. NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2006
    6
    Medium

    CVE-2006-6573

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through 4.2.2 allows remote authenticated users to "gain access to data" and obtain sensitive information via unspecified vectors.

    Published: 15 Dec 2006
    6.6
    Medium

    CVE-2006-6563

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value.

    Published: 15 Dec 2006
    10
    Critical

    CVE-2006-6568

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the phpEx parameter.

    Published: 15 Dec 2006
    10
    Critical

    CVE-2006-6567

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 15 Dec 2006
    7.5
    High

    CVE-2006-6566

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 15 Dec 2006
    4
    Medium

    CVE-2006-6564

    Last Modified: 23 Apr 2026

    FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

    Published: 15 Dec 2006
    4.3
    Medium

    CVE-2006-6105

    Last Modified: 23 Apr 2026

    Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.

    Published: 15 Dec 2006
    10
    Critical

    CVE-2006-5822

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long CONNECT_OPTIONS request, a different issue than CVE-2006-6222.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6304

    Last Modified: 23 Apr 2026

    The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.

    Published: 14 Dec 2006
    10
    Critical

    CVE-2006-4902

    Last Modified: 23 Apr 2026

    The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.

    Published: 14 Dec 2006
    10
    Critical

    CVE-2006-6222

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long request with a malformed length prefix.

    Published: 14 Dec 2006
    4.6
    Medium

    CVE-2006-6474

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6560

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6555

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in EasyFill before 0.5.1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6551

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tucows Client Code Suite (CCS) 1.2.1015 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _ENV[TCA_HOME] parameter.

    Published: 14 Dec 2006
    3.5
    Low

    CVE-2006-6548

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/rearrangeacct. NOTE: the feature parameter to scripts2/dofeaturemanager is already covered by CVE-2006-6198.

    Published: 14 Dec 2006
    4.3
    Medium

    CVE-2006-6547

    Last Modified: 23 Apr 2026

    Buffer overflow in the readAA function in read_aa.cpp in Winamp iPod Plugin (ml_ipod) 2.00 p19 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long tag in an audible.com audiobook (aa) file.

    Published: 14 Dec 2006
    9.3
    Critical

    CVE-2006-6561

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6552

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6553

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Published: 14 Dec 2006
    5
    Medium

    CVE-2006-6554

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Kerio MailServer before 6.3.1 allows remote attackers to cause a denial of service (segmentation fault and service stop) via certain long LDAP queries, as demonstrated by vd_kms6.pm.

    Published: 14 Dec 2006
    7.5
    High

    CVE-2006-6556

    Last Modified: 23 Apr 2026

    The eyeHome function in apps/eyeHome.eyeapp/aplic.php in EyeOS before 0.9.3-3 allows remote attackers to upload and execute arbitrary code via dangerous file extensions that are not all lowercase, which bypasses a cleansing operation.

    Published: 14 Dec 2006
    6.8
    Medium

    CVE-2006-6557

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Skulls! before 0.2.6 have unknown impact and attack vectors, as addressed by "Many security fixes."

    Published: 14 Dec 2006