CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5571

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter.

    Published: 27 Oct 2006
    9.3
    Critical

    CVE-2006-5559

    Last Modified: 23 Apr 2026

    The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5563

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5565

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2) file, (3) module, and (4) func parameters in (a) index.php; and the (5) file parameter in (b) modules.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 27 Oct 2006
    6.4
    Medium

    CVE-2006-5569

    Last Modified: 23 Apr 2026

    FtpXQ Server 3.0.1 installs with two default testing accounts, which allows remote attackers to read or write arbitrary files via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5570

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to read arbitrary files via a .. (dot dot) in the doc parameter.

    Published: 27 Oct 2006
    4.6
    Medium

    CVE-2006-5556

    Last Modified: 23 Apr 2026

    Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5562

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter.

    Published: 27 Oct 2006
    4.3
    Medium

    CVE-2006-5564

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5566

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in premium/index.php in Shop-Script allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the (1) links_exchange, (2) news, (3) search_with_change_category_ability, (4) logging, (5) feedback, (6) show_price, (7) register, (8) answer, (9) productID, and (10) inside parameters.

    Published: 27 Oct 2006
    9.3
    Critical

    CVE-2006-5567

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5561

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5527

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the sys_path parameter.

    Published: 26 Oct 2006
    5
    Medium

    CVE-2006-5528

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.

    Published: 26 Oct 2006
    6.8
    Medium

    CVE-2006-5532

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in rmgs/images.php in RMSOFT Gallery System 2.0 allows remote attackers to inject arbitrary web script or HTML via the kw parameter. NOTE: some of these details are obtained from third party information.

    Published: 26 Oct 2006
    5.1
    Medium

    CVE-2006-5533

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AROUNDMe 0.6.9, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter in template/barnraiser_01/pol_view.tpl.php and other unspecified PHP scripts, a different vector than CVE-2006-5401.

    Published: 26 Oct 2006
    4.3
    Medium

    CVE-2006-5534

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these details are obtained from third party information.

    Published: 26 Oct 2006
    4.3
    Medium

    CVE-2006-5535

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to scripts2/editzonetemplate.

    Published: 26 Oct 2006
    5
    Medium

    CVE-2006-5536

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.

    Published: 26 Oct 2006
    5.1
    Medium

    CVE-2006-5543

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in misc/function.php3 in PHP Generator of Object SQL Database (PGOSD), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 26 Oct 2006
    6.4
    Medium

    CVE-2006-5544

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which causes the address bar to omit some characters from the URL.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5549

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party researcher who states that AMFPHP_BASE is a constant

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5551

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5552

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or application crash) or execute arbitrary code via a long argument to the (1) MAIL FROM or (2) RCPT TO command.

    Published: 26 Oct 2006
    5
    Medium

    CVE-2006-5538

    Last Modified: 23 Apr 2026

    D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to list contents of the cgi-bin directory via unspecified vectors, probably a direct request.

    Published: 26 Oct 2006
    5.1
    Medium

    CVE-2006-5546

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3.0 through 1.4.1 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][classes] parameter.

    Published: 26 Oct 2006
    4.9
    Medium

    CVE-2006-5550

    Last Modified: 23 Apr 2026

    The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5554

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter in albumview.php to upload a text/plain .gif file containing PHP code, which is executed by index.php.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5526

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, and (v) admin/admin_status.php in player/, different vectors than CVE-2006-3045. NOTE: CVE analysis as of 20061026 indicates that files in the admin/ and flash/ directories define foing_root_path before use.

    Published: 26 Oct 2006
    4.3
    Medium

    CVE-2006-5530

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5531

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5539

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5547

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][includes] parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5548

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][directories][classes] parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5555

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execute arbitrary PHP code via the langage parameter.

    Published: 26 Oct 2006
    5.1
    Medium

    CVE-2006-5529

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of these details are obtained from third party information.

    Published: 26 Oct 2006
    5
    Medium

    CVE-2006-5545

    Last Modified: 23 Apr 2026

    Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.

    Published: 26 Oct 2006
    7.8
    High

    CVE-2006-5553

    Last Modified: 23 Apr 2026

    Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certain options.

    Published: 26 Oct 2006
    4.3
    Medium

    CVE-2006-5537

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote attackers to inject arbitrary web script or HTML via the (1) upnp:settings/state or (2) upnp:settings/connection parameters.

    Published: 26 Oct 2006
    4.3
    Medium

    CVE-2006-5516

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters to wakka.php.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5517

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2) email/session.php, (3) entityproperties/session.php, or (4) inc/mail.php.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5518

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) xml2rss.php, (2) config_local.php, (3) rssonate.php, and (4) sql2xml.php in Src/getFeed/inc/.

    Published: 26 Oct 2006
    6.8
    Medium

    CVE-2006-5519

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5520

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions.php in DeltaScripts PHP Classifieds 7.1 allows remote attackers to execute arbitrary PHP code via a URL in the set_path parameter.

    Published: 26 Oct 2006
    6.8
    Medium

    CVE-2006-5524

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

    Published: 26 Oct 2006
    5.1
    Medium

    CVE-2006-5525

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5514

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in quiz.php in Web Group Communication Center (WGCC) 0.5.6b and earlier allows remote attackers to execute arbitrary SQL commands via the qzid parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5521

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5522

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config parameter in (1) main.php or (2) user/account/main.php.

    Published: 26 Oct 2006
    4.3
    Medium

    CVE-2006-5515

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to injected data that is stored by a delivery script and displayed by the admin interface.

    Published: 26 Oct 2006