CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5228

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) up_login, (2) up_pass, or (3) up_num_tasks parameters.

    Published: 10 Oct 2006
    9.3
    Critical

    CVE-2006-3435

    Last Modified: 23 Apr 2026

    PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.

    Published: 10 Oct 2006
    4.3
    Medium

    CVE-2006-3436

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".

    Published: 10 Oct 2006
    9.3
    Critical

    CVE-2006-3876

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.

    Published: 10 Oct 2006
    7.5
    High

    CVE-2006-5226

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Published: 10 Oct 2006
    7.5
    High

    CVE-2006-5222

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2) includes/logger_engine.php.

    Published: 10 Oct 2006
    6.8
    Medium

    CVE-2006-5227

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in TorrentFlux 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the $user_agent variable, probably obtained from the User-Agent HTTP header, and possibly (2) the $ip_resolved variable.

    Published: 10 Oct 2006
    7.5
    High

    CVE-2006-5225

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AAIportal before 1.4.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Oct 2006
    Unknown

    CVE-2006-4170

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4812. Reason: This candidate is a reservation duplicate of CVE-2006-4812. Notes: All CVE users should reference CVE-2006-4812 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Oct 2006
    4.6
    Medium

    CVE-2006-5218

    Last Modified: 23 Apr 2026

    Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.

    Published: 9 Oct 2006
    5.1
    Medium

    CVE-2006-5219

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

    Published: 9 Oct 2006
    5.1
    Medium

    CVE-2006-5220

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePath in (1) files in the programm/lib/ directory including (a) WYApplication.php, (b) WYDocument.php, (c) WYEditor.php, (d) WYElement.php, (e) WYFile.php, (f) WYHTMLTag.php, (g) WYImage.php, (h) WYLanguage.php, (i) WYLink.php, (j) WYPath.php, (k) WYPopupWindowLink.php, (l) WYSelectMenu.php, and (m) WYTextArea.php; (2) files in the programm/elements/ directory including (n) WYGalleryElement.php, (o) WYGuestbookElement.php, (p) WYImageElement.php, (q) WYLogonButtonElement.php, (r) WYLongTextElement.php, (s) WYLoopElement.php, (t) WYMenuElement.php, and (u) WYShortTextElement.php; and (3) programm/webyep.php.

    Published: 9 Oct 2006
    6.4
    Medium

    CVE-2006-5211

    Last Modified: 23 Apr 2026

    Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6.5.0.1418, 7.0 before 7.0.0.1257, and 7.3 before 7.3.0.1053 allow remote attackers to remove OfficeScan clients via a certain HTTP request that invokes the OfficeScan CGI program.

    Published: 9 Oct 2006
    5
    Medium

    CVE-2006-5212

    Last Modified: 23 Apr 2026

    Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6.5.0.1418, 7.0 before 7.0.0.1257, and 7.3 before 7.3.0.1053 allow remote attackers to delete files via a modified filename parameter in a certain HTTP request that invokes the OfficeScan CGI program.

    Published: 9 Oct 2006
    3.6
    Low

    CVE-2006-5213

    Last Modified: 23 Apr 2026

    Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).

    Published: 9 Oct 2006
    7.5
    High

    CVE-2006-5217

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifre) parameters.

    Published: 9 Oct 2006
    7.5
    High

    CVE-2006-5216

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.

    Published: 9 Oct 2006
    5.1
    Medium

    CVE-2006-5203

    Last Modified: 23 Apr 2026

    Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits the "Manage Forums" link in the Admin control panel.

    Published: 9 Oct 2006
    2.1
    Low

    CVE-2006-5204

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.

    Published: 9 Oct 2006
    5
    Medium

    CVE-2006-5205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used.

    Published: 9 Oct 2006
    7.5
    High

    CVE-2006-5206

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.

    Published: 9 Oct 2006
    5.1
    Medium

    CVE-2006-5207

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter.

    Published: 9 Oct 2006
    7.5
    High

    CVE-2006-5208

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php.

    Published: 9 Oct 2006
    7.5
    High

    CVE-2006-5209

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 9 Oct 2006
    4
    Medium

    CVE-2006-5201

    Last Modified: 23 Apr 2026

    Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.

    Published: 9 Oct 2006
    5
    Medium

    CVE-2006-5202

    Last Modified: 23 Apr 2026

    Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.

    Published: 9 Oct 2006
    7.8
    High

    CVE-2006-5196

    Last Modified: 23 Apr 2026

    The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.

    Published: 6 Oct 2006
    5
    Medium

    CVE-2006-5197

    Last Modified: 23 Apr 2026

    PDshopPro stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) /pdshoppro.mdb, (2) /data/pdshoppro.mdb, or (3) /shoppro/data/pdshoppro.mdb.

    Published: 6 Oct 2006
    6.8
    Medium

    CVE-2006-5195

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Wheatblog 1.0 and 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 6 Oct 2006
    4.3
    Medium

    CVE-2006-5194

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in net2ftp 0.93 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5142

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in CA BrightStor ARCserve Backup R11.5 client and server allows remote attackers to execute arbitrary code via long messages to the CheyenneDS Mailslot.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5143

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with opcode (4) 0x2b or (5) 0x2d in ASCORE.dll in the Message Engine RPC Server (msgeng.exe); (6) a long hostname on TCP port 41523 to ASBRDCST.DLL in the Discovery Service (casdscsvc.exe); or unspecified vectors related to the (7) Job Engine Service.

    Published: 6 Oct 2006
    5.1
    Medium

    CVE-2006-5186

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5187

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5189

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in funzioni/lib/show_hlp.php in klinza professional cms 5.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appl[APPL] parameter.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5182

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5193

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir parameter.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5183

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Dayfox Designs Dayfox Blog 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the slogin parameter in the (1) adminlog.php, (2) postblog.php, (3) index.php, or (4) index2.php script in /edit.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5184

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in PKR Internet Taskjitsu before 2.0.6 allows remote attackers to execute arbitrary SQL commands via the key parameter, when the limit query parameter is set to customerid.

    Published: 6 Oct 2006
    4.3
    Medium

    CVE-2006-5190

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5185

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.

    Published: 6 Oct 2006
    5
    Medium

    CVE-2006-5188

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in webGENEius GOOP Gallery 2.0.2 allows remote attackers to read or list data from certain files or directories via unspecified vectors.

    Published: 6 Oct 2006
    5.1
    Medium

    CVE-2006-5191

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5192

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPGREETZ_INCLUDE_DIR parameter.

    Published: 6 Oct 2006
    6.2
    Medium

    CVE-2006-5178

    Last Modified: 23 Apr 2026

    Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

    Published: 6 Oct 2006
    7.5
    High

    CVE-2006-5180

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter, a different vector than CVE-2006-5102.

    Published: 6 Oct 2006
    7.6
    High

    CVE-2006-5175

    Last Modified: 2 May 2025

    Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows remote attackers to modify configurations or delete arbitrary data via unspecified vectors.

    Published: 6 Oct 2006
    9.3
    Critical

    CVE-2006-5176

    Last Modified: 23 Apr 2026

    Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the signature field of NTLM Type 1 messages".

    Published: 6 Oct 2006
    9.3
    Critical

    CVE-2006-5177

    Last Modified: 23 Apr 2026

    The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted base64 encoded NTLM Type 1 messages, which trigger a buffer over-read.

    Published: 6 Oct 2006
    5.4
    Medium

    CVE-2006-5179

    Last Modified: 23 Apr 2026

    Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification, a related issue to CVE-2006-2940.

    Published: 6 Oct 2006