CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5952

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field.

    Published: 17 Nov 2006
    6.8
    Medium

    CVE-2006-5942

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter.

    Published: 17 Nov 2006
    7.5
    High

    CVE-2006-5945

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.

    Published: 17 Nov 2006
    5
    Medium

    CVE-2006-5947

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Conxint FTP Server 2.2.0603, and possibly earlier, allow remote attackers to read arbitrary files and list arbitrary directories via directory traversal sequences in (1) DIR (LIST or NLST) and (2) GET (RETR) commands. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Published: 17 Nov 2006
    7.5
    High

    CVE-2006-5928

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5930

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5935

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ShopSystems 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the sessid parameter.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5936

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Nov 2006
    10
    Critical

    CVE-2006-5938

    Last Modified: 23 Apr 2026

    Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors involving an uninitialized variable and a crafted CAB file.

    Published: 16 Nov 2006
    7.8
    High

    CVE-2006-5939

    Last Modified: 23 Apr 2026

    Grisoft AVG Anti-Virus before 7.1.407 allows remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers a divide-by-zero error. NOTE: some of these details are obtained from third party information.

    Published: 16 Nov 2006
    10
    Critical

    CVE-2006-5940

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors related to "Integer Issues" and parsing of .EXE files.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5929

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5926

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in mail.php in Vallheru before 1.0.7 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) to parameters. NOTE: some of these details are obtained from third party information.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5927

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter.

    Published: 16 Nov 2006
    5.1
    Medium

    CVE-2006-5931

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to certain PHP scripts in (1) lib/actions/, (2) lib/displays/, (3) lib/editforms/, (4) lib/functions/, (5) scheme/, and (6) the root directory. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5932

    Last Modified: 23 Apr 2026

    Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5934

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5937

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Grisoft AVG Anti-Virus before 7.1.407 allow remote attackers to execute arbitrary code via crafted (1) CAB or (2) RAR archives that trigger a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Published: 16 Nov 2006
    7.5
    High

    CVE-2006-5933

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Nov 2006
    5
    Medium

    CVE-2006-5897

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the ChatPath parameter to (1) avatar.php, (2) colorhelp_popup.php, (3) color_popup.php, (4) index.php, (5) index1.php, (6) lib/connected_users.lib.php, (7) lib/index.lib.php, and (8) phpMyChat.php3; and the (9) L parameter to logs.php. NOTE: CVE analysis suggests that vector 1 might be incorrect.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5903

    Last Modified: 23 Apr 2026

    Rahul Jonna Gmail File Space (GSpace) allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GSPACE "2174|1|1|1|gs:/ d$" message, which injects a new file into the filesystem; and (2) a GSPACE "|-135|1|1|0|gs:/ d$" message, which creates a folder.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5907

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5908

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Published: 15 Nov 2006
    5
    Medium

    CVE-2006-5909

    Last Modified: 23 Apr 2026

    generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5910

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5914

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter. NOTE: the start, search_order, search_type, and search_area parameters are already covered by CVE-2005-4018.

    Published: 15 Nov 2006
    5
    Medium

    CVE-2006-5916

    Last Modified: 23 Apr 2026

    Intego VirusBarrier X4 allows context-dependent attackers to bypass virus protection by quickly injecting many infected files into the filesystem, which prevents VirusBarrier from processing all the files.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5917

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php.

    Published: 15 Nov 2006
    5.8
    Medium

    CVE-2006-5921

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields. NOTE: this issue may overlap CVE-2006-5195.

    Published: 15 Nov 2006
    5
    Medium

    CVE-2006-5922

    Last Modified: 23 Apr 2026

    index.php in Wheatblog (wB) allows remote attackers to obtain sensitive information via certain values of the postPtr[] and next parameters, which reveals the path in an error message.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5923

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.

    Published: 15 Nov 2006
    5.8
    Medium

    CVE-2006-5924

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Efficient IP iPmanager (IPm) 2.3 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5899

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter. NOTE: this issue has been disputed by a third party, who states that install.php3 is supposed to be deleted after installation and, if not deleted, intentionally allows setting repertoire without an inclusion attack

    Published: 15 Nov 2006
    6.4
    Medium

    CVE-2006-5905

    Last Modified: 23 Apr 2026

    Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.

    Published: 15 Nov 2006
    10
    Critical

    CVE-2006-5912

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Campware Campsite before 2.6.2 has unknown impact and attack vectors, related to a "Security fix for you-know-what," possibly related to encrypted passwords.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5918

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field. NOTE: it is possible that the field value is restricted to files on specific public web sites.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5919

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.

    Published: 15 Nov 2006
    6.8
    Medium

    CVE-2006-5900

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.

    Published: 15 Nov 2006
    5
    Medium

    CVE-2006-5901

    Last Modified: 23 Apr 2026

    Hawking Technology wireless router WR254-CA uses a hardcoded IP address among the set of DNS server IP addresses, which could allow remote attackers to cause a denial of service or hijack the router by attacking or spoofing the server at the hardcoded address. NOTE: it could be argued that this issue reflects an inherent limitation of DNS itself, so perhaps it should not be included in CVE.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5902

    Last Modified: 23 Apr 2026

    viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5906

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter. NOTE: the issue is disputed by other researchers, who observe that $chemin is defined before use

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5911

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/.

    Published: 15 Nov 2006
    6.4
    Medium

    CVE-2006-5913

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/sslnavcancel.htm with the target site in the anchor identifier, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid, or (2) trigger a "The webpage no longer exists" report via a link to res://ieframe.dll/http_410.htm, a variant of CVE-2006-5805.

    Published: 15 Nov 2006
    6.8
    Medium

    CVE-2006-5915

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5920

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying "further analysis reveals that the application is not vulnerable." NOTE: this issue may overlap CVE-2006-5113

    Published: 15 Nov 2006
    5
    Medium

    CVE-2006-5898

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in localization/languages.lib.php3 in PhpMyChat 0.14.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ChatPath parameter.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5904

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MWChat Pro 7.0 allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[MWCHAT_Libs] parameter to (1) about.php, (2) buddy.php, (3) chat.php, (4) dialog.php, (5) head.php, (6) help.php, (7) index.php, and (8) license.php, different vectors than CVE-2005-1869.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-5925

    Last Modified: 23 Apr 2026

    Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.

    Published: 15 Nov 2006
    7.5
    High

    CVE-2006-4688

    Last Modified: 23 Apr 2026

    Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."

    Published: 14 Nov 2006
    2.1
    Low

    CVE-2006-5461

    Last Modified: 23 Apr 2026

    Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.

    Published: 14 Nov 2006