CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-4935

    Last Modified: 16 Apr 2026

    The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

    Published: 23 Sept 2006
    5
    Medium

    CVE-2006-4940

    Last Modified: 16 Apr 2026

    login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.

    Published: 23 Sept 2006
    4.6
    Medium

    CVE-2006-4942

    Last Modified: 16 Apr 2026

    Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.

    Published: 23 Sept 2006
    7.5
    High

    CVE-2006-4944

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.

    Published: 23 Sept 2006
    5
    Medium

    CVE-2006-4939

    Last Modified: 16 Apr 2026

    backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

    Published: 23 Sept 2006
    4
    Medium

    CVE-2006-4938

    Last Modified: 16 Apr 2026

    help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

    Published: 23 Sept 2006
    10
    Critical

    CVE-2006-4936

    Last Modified: 16 Apr 2026

    Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.

    Published: 23 Sept 2006
    6.4
    Medium

    CVE-2006-4901

    Last Modified: 16 Apr 2026

    Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend.exe with the desired arguments.

    Published: 22 Sept 2006
    5.5
    Medium

    CVE-2006-4900

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function.

    Published: 22 Sept 2006
    5
    Medium

    CVE-2006-4899

    Last Modified: 16 Apr 2026

    The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message.

    Published: 22 Sept 2006
    7.2
    High

    CVE-2006-3509

    Last Modified: 16 Apr 2026

    Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames.

    Published: 21 Sept 2006
    7.2
    High

    CVE-2006-3507

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.

    Published: 21 Sept 2006
    7.2
    High

    CVE-2006-3508

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4921

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to starnet/modules/include/include.php. NOTE: some of these details are obtained from third party information.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4918

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) env_dir parameter to (a) blank.php, (b) admin.php, or (c) builddb.php, and the (2) script_root parameter to blank.php.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4920

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to (1) starnet/modules/sn_allbum/slideshow.php, and (2) starnet/themes/editable/main.inc.php.

    Published: 21 Sept 2006
    2.6
    Low

    CVE-2006-4919

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter.

    Published: 21 Sept 2006
    5
    Medium

    CVE-2006-4922

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions.

    Published: 21 Sept 2006
    4.3
    Medium

    CVE-2006-4923

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter.

    Published: 21 Sept 2006
    4.3
    Medium

    CVE-2006-4917

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname parameter.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4916

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in uye_profil.asp in Tekman Portal (TR) 1.0 allows remote attackers to execute arbitrary SQL commands via the uye_id parameter.

    Published: 21 Sept 2006
    4.3
    Medium

    CVE-2006-4915

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4913

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4912

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script parameter.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4911

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Cisco IPS 5.0 before 5.0(6p2) and 5.1 before 5.1(2), when running in inline or promiscuous mode, allows remote attackers to bypass traffic inspection via a "crafted sequence of fragmented IP packets".

    Published: 21 Sept 2006
    5
    Medium

    CVE-2006-4910

    Last Modified: 16 Apr 2026

    The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4904

    Last Modified: 16 Apr 2026

    Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote file inclusion via the xcart_dir parameter.

    Published: 21 Sept 2006
    2.6
    Low

    CVE-2006-4914

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in A.l-Pifou 1.8p2 allows remote attackers to read arbitrary files via ".." sequences in the ze_langue_02 cookie, as demonstrated by using the choix_lng parameter to choix_langue.php to indirectly set the cookie, then accessing livre_dor.php to trigger the inclusion from inc/change_lang_ck.php, possibly related to livre_livre.php. NOTE: the livre_livre.php relationship has been reported by some third party sources.

    Published: 21 Sept 2006
    2.6
    Low

    CVE-2006-4909

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly handled when the appliance sends a meta-refresh.

    Published: 21 Sept 2006
    5
    Medium

    CVE-2006-4908

    Last Modified: 16 Apr 2026

    OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL containing an * (asterisk) wildcard, which displays all matching file and directory information.

    Published: 21 Sept 2006
    5
    Medium

    CVE-2006-4907

    Last Modified: 16 Apr 2026

    OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4906

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter.

    Published: 21 Sept 2006
    7.5
    High

    CVE-2006-4905

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Artmedic Links 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, which is processed by the readfile function.

    Published: 21 Sept 2006
    6.4
    Medium

    CVE-2006-4438

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.

    Published: 20 Sept 2006
    7.5
    High

    CVE-2006-5170

    Last Modified: 23 Apr 2026

    pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

    Published: 20 Sept 2006
    5
    Medium

    CVE-2006-4897

    Last Modified: 16 Apr 2026

    CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4893

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4891

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 19 Sept 2006
    Unknown

    CVE-2006-4896

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4785. Reason: This candidate is a duplicate of CVE-2006-4785. Notes: All CVE users should reference CVE-2006-4785 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4898

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appconf[rootpath] parameter.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4892

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 19 Sept 2006
    4.3
    Medium

    CVE-2006-4894

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4895

    Last Modified: 16 Apr 2026

    IDevSpot NexieAffiliate 1.9 and earlier allows remote attackers to delete arbitrary affiliates via a modified id parameter to delete.php.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4890

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) fckeditor/editor/dialog/fck_link.php.

    Published: 19 Sept 2006
    5.1
    Medium

    CVE-2006-4889

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php; (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories; and the (12) preview.php, (13) log.php, (14) index.php, (15) config.php, and (16) admin.php in the (c) admin directory, a different set of vectors than CVE-2006-4788.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4875

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possibly files with arbitrary extensions, to gallery/albums/public.

    Published: 19 Sept 2006
    4.3
    Medium

    CVE-2006-4884

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 19 Sept 2006
    4.3
    Medium

    CVE-2006-4881

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.php; the (3) txt_error and (4) txt_templatenotexist parameters in (c) template.php; the (5) split parameter in certain files, as demonstrated by (d) editprofile.php, (e) search.php, (f) index.php, and (g) pm.php; and the (6) txt_login parameter in (h) loginline.php; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) txt_logout parameter in (i) loginline.php.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4877

    Last Modified: 16 Apr 2026

    Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) index.php, (2) profile.php, and (3) header.php.

    Published: 19 Sept 2006
    4.3
    Medium

    CVE-2006-4874

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title], (6) language[Mass-Email form desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3], and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title], (11) language[Forgotten desc], (12) language[Forgotten desc2], (13) language[Forgotten desc3], (14) language[Forgotten desc4], and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc], (17) language[Search view desc2], (18) language[Search view desc3], (19) language[Search view desc4], (20) language[Search view desc5], (21) language[Search view desc6], (22) language[Search view desc7], and (23) language[Search view desc8] parameters in (e) modules/search.php.

    Published: 19 Sept 2006