CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5523

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5513

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in GeoNetwork opensource before 2.0.3 allows remote attackers to execute arbitrary SQL commands, and complete a login, via unspecified vectors.

    Published: 26 Oct 2006
    7.5
    High

    CVE-2006-5382

    Last Modified: 23 Apr 2026

    3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string and conduct unauthorized actions via unspecified "normally restricted management packets on the device" that cause the community string to be returned.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5501

    Last Modified: 23 Apr 2026

    Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the downloadFileDirectory property, a different vulnerability than CVE-2006-5502.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5502

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the AddPictureNoAlbum method, a different vulnerability than CVE-2006-5501.

    Published: 25 Oct 2006
    4.3
    Medium

    CVE-2006-5503

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 25 Oct 2006
    4.3
    Medium

    CVE-2006-5504

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action parameter.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5508

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the User-Agent HTTP header.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5509

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.

    Published: 25 Oct 2006
    6.4
    Medium

    CVE-2006-5510

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, as demonstrated by uploading a .gif file that contains PHP code.

    Published: 25 Oct 2006
    2.6
    Low

    CVE-2006-5511

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum parameter.

    Published: 25 Oct 2006
    4.3
    Medium

    CVE-2006-5512

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5506

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5507

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Der Dirigent (DeDi) 1.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_dedi[dedi_path] parameter in (1) find.php, (2) insert_line.php, (3) fullscreen.php, (4) changecase.php, (5) insert_link.php, (6) insert_table.php, (7) table_cellprop.php, (8) table_prop.php, (9) table_rowprop.php, (10) insert_page.php, and possibly insert_marquee.php in backend/external/wysiswg/popups/.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5505

    Last Modified: 23 Apr 2026

    Multiple PHP file inclusion vulnerabilities in 2BGal 3.0 allow remote attackers to execute arbitrary PHP code via the lang parameter to (1) admin/configuration.inc.php, (2) admin/creer_album.inc.php, (3) admin/changepwd.php.inc, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5490

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Segue Content Management System (CMS) before 1.5.8 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5491

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in include/index.php in UltraCMS 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

    Published: 25 Oct 2006
    4
    Medium

    CVE-2006-5492

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (document contents) via unspecified attack vectors related to "grants."

    Published: 25 Oct 2006
    4.3
    Medium

    CVE-2006-5496

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Timothy Claason KnowledgeBank 1.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) index.php, (2) addknowledge.php, and (3) addscreenshot.php.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5497

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5488

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in XchangeBoard 1.70, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginNick parameter during login. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 25 Oct 2006
    5
    Medium

    CVE-2006-5489

    Last Modified: 23 Apr 2026

    Research in Motion (RIM) BlackBerry Enterprise Server 4.1 SP2 before Hotfix 1 for IBM Lotus Domino might allow attackers with meeting organizer privileges to cause a denial of service (application hang) via a deleted recurrent meeting instance when changing the attendee's calendar meeting time.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5494

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5495

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_red2 parameter to (a) _msdazu_pdata/redaktion/artikel/up/index.php; (b) addtort.php, (c) colorpik2.php, (d) colorpik3.php, (e) extras_menu.php, (f) farbpalette.php, (g) lese_inc.php, and (h) newfile.php in _msdazu_share/richtext/; the (2) path_scr_dat2 parameter to (i)_msdazu_share/share/insert1.php; the (3) path_red parameter to (j) _msdazu_share/extras/downloads/index.php; and unspecified parameters in other files.

    Published: 25 Oct 2006
    6.8
    Medium

    CVE-2006-5499

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Serendipity (s9y) 1.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the media manager administration page.

    Published: 25 Oct 2006
    5.1
    Medium

    CVE-2006-5500

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the checkUser function in inc/DBInterface.php in XchangeBoard 1.70 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userNick or (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5493

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 25 Oct 2006
    7.5
    High

    CVE-2006-5498

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.

    Published: 25 Oct 2006
    5
    Medium

    CVE-2006-5467

    Last Modified: 23 Apr 2026

    The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent ID.

    Published: 25 Oct 2006
    2.1
    Low

    CVE-2006-5483

    Last Modified: 23 Apr 2026

    p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, which should only be settable by root.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5485

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SpeedBerg 1.2beta1 allow remote attackers to execute arbitrary PHP code via a URL in the SPEEDBERG_PATH parameter to (1) entrancePage.tpl.php, (2) generalToolBox.tlb.php, (3) myToolBox.tlb.php, (4) scriplet.inc.php, (5) simplePage.tpl.php, (6) speedberg.class.php, and (7) standardPage.tpl.php.

    Published: 24 Oct 2006
    5
    Medium

    CVE-2006-5484

    Last Modified: 23 Apr 2026

    SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.

    Published: 24 Oct 2006
    4.3
    Medium

    CVE-2006-5486

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.

    Published: 24 Oct 2006
    2.1
    Low

    CVE-2006-5482

    Last Modified: 23 Apr 2026

    ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-4177

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the NCP engine in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted NCP over IP packet that causes NCP to read more data than intended.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5471

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) cfg_dir and (2) lib_dir parameters.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5474

    Last Modified: 23 Apr 2026

    The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.

    Published: 24 Oct 2006
    6.8
    Medium

    CVE-2006-5475

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

    Published: 24 Oct 2006
    2.6
    Low

    CVE-2006-5477

    Last Modified: 23 Apr 2026

    Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5478

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5481

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in 2le.net Castor PHP Web Builder 1.1.1 allow remote attackers to execute arbitrary PHP code via the rootpath parameter in (1) lib/code.php, (2) lib/dbconnect.php, (3) lib/error.php, (4) lib/menu.php, and other unspecified files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5473

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Description.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the lib_dir parameter. NOTE: this issue is disputed by CVE as of 20061023, since there is no Description.php file included in the product, and the existing "Description" file contains documentation, not functioning code

    Published: 24 Oct 2006
    5.1
    Medium

    CVE-2006-5480

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5472

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter in (1) lib/registry.lib.php, (2) lib/sqlcompose.lib.php, and (3) lib/sqlsearch.lib.php.

    Published: 24 Oct 2006
    7.5
    High

    CVE-2006-5476

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.

    Published: 24 Oct 2006
    5
    Medium

    CVE-2006-5479

    Last Modified: 23 Apr 2026

    The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."

    Published: 24 Oct 2006
    10
    Critical

    CVE-2006-4509

    Last Modified: 23 Apr 2026

    Integer overflow in the evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request.

    Published: 24 Oct 2006
    10
    Critical

    CVE-2006-4510

    Last Modified: 23 Apr 2026

    The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request containing a value that is larger than the number of objects transmitted, which triggers an invalid free of unallocated memory.

    Published: 24 Oct 2006
    4.3
    Medium

    CVE-2006-3455

    Last Modified: 23 Apr 2026

    The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.

    Published: 23 Oct 2006
    7.8
    High

    CVE-2006-5445

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SIP channel driver (channels/chan_sip.c) in Asterisk 1.2.x before 1.2.13 and 1.4.x before 1.4.0-beta3 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors that result in the creation of "a real pvt structure" that uses more resources than necessary.

    Published: 23 Oct 2006