CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5670

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5674

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter to (1) bb_func_forums.php, (2) bb_functions.php, or (3) the RSS plugin.

    Published: 3 Nov 2006
    4.6
    Medium

    CVE-2006-5664

    Last Modified: 23 Apr 2026

    The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5666

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: some of these details are obtained from third party information.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5672

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.

    Published: 3 Nov 2006
    6.8
    Medium

    CVE-2006-5673

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5671

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in contact.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Nov 2006
    4.6
    Medium

    CVE-2006-5663

    Last Modified: 23 Apr 2026

    IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5665

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 3 Nov 2006
    4.3
    Medium

    CVE-2006-5653

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5660

    Last Modified: 23 Apr 2026

    Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.

    Published: 3 Nov 2006
    6.8
    Medium

    CVE-2006-5661

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5662

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."

    Published: 3 Nov 2006
    2.1
    Low

    CVE-2006-5659

    Last Modified: 23 Apr 2026

    PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Nov 2006
    4.3
    Medium

    CVE-2006-5652

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.

    Published: 3 Nov 2006
    5
    Medium

    CVE-2006-5656

    Last Modified: 23 Apr 2026

    Memory leak in the push_align function in src/util.c in Vilistextum before 2.6.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the tmp_align variable. NOTE: it is not clear whether this is a vulnerability, due to the functionality of the product.

    Published: 3 Nov 2006
    10
    Critical

    CVE-2006-5657

    Last Modified: 23 Apr 2026

    Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors.

    Published: 3 Nov 2006
    4
    Medium

    CVE-2006-5654

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5655

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 3 Nov 2006
    7.6
    High

    CVE-2006-5658

    Last Modified: 23 Apr 2026

    BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path in the filePath parameter to the BW_DeleteTempFile method.

    Published: 3 Nov 2006
    7.5
    High

    CVE-2006-5465

    Last Modified: 23 Apr 2026

    Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.

    Published: 2 Nov 2006
    5
    Medium

    CVE-2006-4839

    Last Modified: 23 Apr 2026

    Sophos Anti-Virus 5.1 allows remote attackers to cause a denial of service (memory consumption) via a file that is compressed with Petite and contains a large number of sections.

    Published: 1 Nov 2006
    6.8
    Medium

    CVE-2006-4704

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."

    Published: 1 Nov 2006
    5
    Medium

    CVE-2006-5646

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that specifies a Window_size of 0.

    Published: 1 Nov 2006
    6.4
    Medium

    CVE-2006-5647

    Last Modified: 23 Apr 2026

    Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."

    Published: 1 Nov 2006
    7.8
    High

    CVE-2006-4517

    Last Modified: 23 Apr 2026

    Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference.

    Published: 1 Nov 2006
    5
    Medium

    CVE-2006-5645

    Last Modified: 23 Apr 2026

    Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5635

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5637

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5638

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5639

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the random number generator in OpenWBEM (Web Based Enterprise Management) 3.2.0 allows attackers to gain privileges via vectors related to "local or HTTP Digest authentication."

    Published: 1 Nov 2006
    10
    Critical

    CVE-2006-5642

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NmnLogger 1.0.0 and earlier has unknown impact and attack vectors related to configuration of mesasge drivers.

    Published: 1 Nov 2006
    6.8
    Medium

    CVE-2006-5643

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5641

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 1 Nov 2006
    5.1
    Medium

    CVE-2006-5636

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.

    Published: 1 Nov 2006
    6.8
    Medium

    CVE-2006-5634

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5640

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 1 Nov 2006
    7.5
    High

    CVE-2006-5629

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5630

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID parameter in a disableforum action in DisableForum.asp and (2) create an arbitrary forum virtual directory via an empty ForumID parameter in an enableforum action in EnableForum.asp.

    Published: 31 Oct 2006
    6.8
    Medium

    CVE-2006-5631

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via arbitrary query strings when the action parameter is not "1", as demonstrated using script in the action parameter, a different vulnerability than CVE-2006-5632.

    Published: 31 Oct 2006
    5
    Medium

    CVE-2006-5633

    Last Modified: 23 Apr 2026

    Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.

    Published: 31 Oct 2006
    6.1
    Medium

    CVE-2006-5632

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5621

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5622

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5623

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in UNISOR Content Management System (CMS) allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass fields.

    Published: 31 Oct 2006
    5.1
    Medium

    CVE-2006-5625

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5620

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a different vector than CVE-2006-4489.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5624

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 31 Oct 2006
    4.3
    Medium

    CVE-2006-5626

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.

    Published: 31 Oct 2006