CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2006-6123

    Last Modified: 23 Apr 2026

    Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected.

    Published: 26 Nov 2006
    9.3
    Critical

    CVE-2006-6121

    Last Modified: 23 Apr 2026

    Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.

    Published: 26 Nov 2006
    6.8
    Medium

    CVE-2006-6124

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Nov 2006
    4.6
    Medium

    CVE-2006-5965

    Last Modified: 23 Apr 2026

    PassGo SSO Plus 2.1.0.32, and probably earlier versions, uses insecure permissions (Everyone/Full Control) for the PassGo Technologies directory, which allows local users to gain privileges by modifying critical programs.

    Published: 26 Nov 2006
    5.1
    Medium

    CVE-2006-5869

    Last Modified: 23 Apr 2026

    pstotext before 1.9 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a file name.

    Published: 26 Nov 2006
    7.5
    High

    CVE-2006-6111

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873.

    Published: 26 Nov 2006
    7.5
    High

    CVE-2006-6115

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

    Published: 26 Nov 2006
    6.8
    Medium

    CVE-2006-6118

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 26 Nov 2006
    4.3
    Medium

    CVE-2006-6108

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 26 Nov 2006
    7.5
    High

    CVE-2006-6109

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.

    Published: 26 Nov 2006
    7.5
    High

    CVE-2006-6110

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp.

    Published: 26 Nov 2006
    7.5
    High

    CVE-2006-6116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Published: 26 Nov 2006
    7.5
    High

    CVE-2006-6117

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.

    Published: 26 Nov 2006
    5
    Medium

    CVE-2006-6119

    Last Modified: 23 Apr 2026

    mmgallery 1.55 allows remote attackers to obtain sensitive information via a direct request for thumbs.php, which reveals the installation path in various error messages.

    Published: 26 Nov 2006
    Unknown

    CVE-2006-6114

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-5854. Reason: This candidate is a duplicate of CVE-2006-5854. Notes: All CVE users should reference CVE-2006-5854 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Nov 2006
    4.3
    Medium

    CVE-2006-6082

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6083

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 24 Nov 2006
    5
    Medium

    CVE-2006-6085

    Last Modified: 23 Apr 2026

    Kile before 1.9.3 does not assign a backup file the same permissions as the original file, which might allow local users to obtain sensitive information.

    Published: 24 Nov 2006
    4.3
    Medium

    CVE-2006-6087

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6092

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in vehiclelistings.asp in 20/20 Auto Gallery allow remote attackers to execute arbitrary SQL commands via the (1) vehicleID, (2) categoryID_list, (3) sale_type, (4) stock_number, (5) manufacturer, (6) model, (7) vehicleID, (8) year, (9) vin, and (10) listing_price parameters.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6094

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6095

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.

    Published: 24 Nov 2006
    5
    Medium

    CVE-2006-6084

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information.

    Published: 24 Nov 2006
    5.1
    Medium

    CVE-2006-6086

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pear_path parameter.

    Published: 24 Nov 2006
    4.3
    Medium

    CVE-2006-6088

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery field, or the myquery parameter, in search.asp. NOTE: some of these details are obtained from third party information.

    Published: 24 Nov 2006
    4.3
    Medium

    CVE-2006-6089

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) groupname (Group Name), or (3) detail (Message) field.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6090

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BaalAsp forum allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to (a) adminlogin.asp, the (2) name or (3) password parameter to (b) userlogin.asp, or the (3) search parameter to search.asp.

    Published: 24 Nov 2006
    4.3
    Medium

    CVE-2006-6091

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Grim Pirate GrimBB before 2006_11_21 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6093

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.

    Published: 24 Nov 2006
    4.3
    Medium

    CVE-2006-6096

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 24 Nov 2006
    6.8
    Medium

    CVE-2006-6075

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in addpost1.asp in BaalAsp forum allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Nov 2006
    10
    Critical

    CVE-2006-6076

    Last Modified: 23 Apr 2026

    Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6080

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote attackers to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6072

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bpg/publications_list.asp in BPG-InfoTech Easy Publisher and Smart Publisher//Pro 2.7.7 allows remote attackers to execute arbitrary SQL commands via the vjob parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6073

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6074

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.

    Published: 24 Nov 2006
    5
    Medium

    CVE-2006-6077

    Last Modified: 23 Apr 2026

    The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6078

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the cm_basedir parameter.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6079

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LoudMouth 2.4 allow remote attackers to execute arbitrary PHP code via a URL in the mainframe parameter to (1) admin.loudmouth.php or (2) toolbar.loudmouth.php.

    Published: 24 Nov 2006
    7.5
    High

    CVE-2006-6081

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Smarty_Compiler.class.php in Telaen 1.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter.

    Published: 24 Nov 2006
    Unknown

    CVE-2006-5941

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2177. Reason: This candidate is a duplicate of CVE-2005-2177. Notes: All CVE users should reference CVE-2005-2177 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Nov 2006
    6.8
    Medium

    CVE-2006-6169

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.

    Published: 24 Nov 2006
    7.2
    High

    CVE-2006-3973

    Last Modified: 23 Apr 2026

    My Firewall Plus 5.0 Build 1119 does not verify if explorer.exe is running before launching iexplore.exe from the "Test Your Firewall" feature, which allows local users to gain SYSTEM privileges.

    Published: 22 Nov 2006
    2.6
    Low

    CVE-2006-6068

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the cached_album function in functions.php for mAlbum 0.3 and earlier allows remote attackers to list filenames of arbitrary images via a .. (dot dot) in the gal parameter to index.php.

    Published: 22 Nov 2006
    5
    Medium

    CVE-2006-6069

    Last Modified: 23 Apr 2026

    index.php in mAlbum 0.3 and earlier allows remote attackers to obtain the installation path via an invalid gal parameter.

    Published: 22 Nov 2006
    7.5
    High

    CVE-2006-6063

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.

    Published: 22 Nov 2006
    7.5
    High

    CVE-2006-6064

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Message Parsing Interpreter (MPI) in Fuzzball MUCK before 6.07 allow remote attackers to execute arbitrary code via crafted messages.

    Published: 22 Nov 2006
    5.1
    Medium

    CVE-2006-6065

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 22 Nov 2006
    7.5
    High

    CVE-2006-6067

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in 20/20 DataShed (aka Real Estate Listing System) allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) f-email.asp, or the (2) peopleID and (2) sort_order parameters to (b) listings.asp, different vectors than CVE-2006-5955.

    Published: 22 Nov 2006
    7.5
    High

    CVE-2006-6070

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrary SQL commands via the StateCode parameter.

    Published: 22 Nov 2006