CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2006-4873

    Last Modified: 16 Apr 2026

    Jupiter CMS allows remote attackers to obtain sensitive information via a direct request for (1) includes/functions.php, (2) modules/register.php, (3) modules/poll.php, (4) modules/panel.php, (5) modules/pm.php, (6) modules/news.php, (7) modules/templates_change.php, (8) modules/users.php, (9) modules/misc.php, (10) modules/masspm.php, (11) modules/mass-email.php, (12) modules/main-nav.php, (13) modules/login.php, (14) modules/layout.php, (15) modules/hq.php, (16) modules/forum.php, (17) modules/forum-admin.php, (18) modules/events.php, (19) modules/emoticons.php, (20) modules/download.php, (21) modules/blocks.php, (22) modules/ban.php, (23) modules/badwords.php, (24) modules/ads.php, or (25) modules/admin.php, which reveals the installation path in various error messages. NOTE: The modules/online.php vector is already covered by CVE-2006-1679.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4337

    Last Modified: 16 Apr 2026

    Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4335

    Last Modified: 16 Apr 2026

    Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4885

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The bottom.php parameter is already covered by CVE-2006-4826.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4876

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-2191

    Last Modified: 16 Apr 2026

    Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.

    Published: 19 Sept 2006
    Unknown

    CVE-2006-3866

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4868. Reason: This candidate is a duplicate of CVE-2006-4868. Notes: All CVE users should reference CVE-2006-4868 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4336

    Last Modified: 16 Apr 2026

    Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4871

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4872

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4878

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in footer.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to read and include arbitrary local files via a .. (dot dot) sequence in the template parameter. NOTE: this was later reported to affect 1.0.1, and demonstrated for code execution by uploading and accessing an avatar file.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4879

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in profile.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4880

    Last Modified: 16 Apr 2026

    David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) footer.php, (2) template.php, or (3) lastvisit.php, which reveals the installation path in various error messages.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4882

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID parameter.

    Published: 19 Sept 2006
    4.3
    Medium

    CVE-2006-4883

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot BizDirectory allow remote attackers to inject arbitrary web script or HTML via (1) the stylesheet parameter in Feed.php or (2) the message parameter in status.php.

    Published: 19 Sept 2006
    7.2
    High

    CVE-2006-4887

    Last Modified: 16 Apr 2026

    Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4888

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.

    Published: 19 Sept 2006
    3.7
    Low

    CVE-2006-4886

    Last Modified: 16 Apr 2026

    The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clicking the Disable button, possibly due to an interface-related race condition.

    Published: 19 Sept 2006
    9.3
    Critical

    CVE-2006-4868

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4867

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4869

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4870

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php.

    Published: 19 Sept 2006
    4.6
    Medium

    CVE-2006-4866

    Last Modified: 16 Apr 2026

    Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.

    Published: 19 Sept 2006
    6.8
    Medium

    CVE-2006-4858

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 19 Sept 2006
    Unknown

    CVE-2006-4854

    Last Modified: 7 Nov 2023

    Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4864

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in All Enthusiast ReviewPost 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the RP_PATH parameter.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4865

    Last Modified: 16 Apr 2026

    Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors.

    Published: 19 Sept 2006
    4.3
    Medium

    CVE-2006-4856

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Roller WebLogger 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) url parameters; (4) certain content parameters in the preview method; or (5) the q parameter in (a) sitesearch.do.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4859

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and earlier allows remote attackers to upload PHP code to the images/contact folder via a filename with a double extension in the contact_attach parameter in a contact option in index.php, which bypasses an insufficiently restrictive regular expression.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4863

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file. NOTE: CVE also disputes a later report of this vulnerability in 1.2, because the langfile parameter is set to french.php in 1.2

    Published: 19 Sept 2006
    3.6
    Low

    CVE-2006-4246

    Last Modified: 16 Apr 2026

    Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

    Published: 19 Sept 2006
    4.9
    Medium

    CVE-2006-4855

    Last Modified: 16 Apr 2026

    The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4857

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) form_codeword (aka the Password field) parameters.

    Published: 19 Sept 2006
    10
    Critical

    CVE-2006-4860

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in (1) index.php, (2) minixml.inc.php, (3) doc.inc.php, (4) element.inc.php, (5) node.inc.php, (6) treecomp.inc.php, (7) forum.html.php, (8) forum.php, (9) antihack.php, (10) content.php, (11) initglobals.php, and (12) imanager.php in Limbo (aka Lite Mambo) CMS 1.0.4.2 before 20060311 have unknown impact and attack vectors.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4861

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in loginprocess.asp in Mohammed Mehdi Panjwani Complain Center 1 allows remote attackers to execute arbitrary SQL commands via the (1) TxtUser (aka Username) and (2) TxtPass (aka Password) parameters in login.asp.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4862

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.aspx in easypage allows remote attackers to execute arbitrary SQL commands via the srch parameter in the Search page.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4684

    Last Modified: 16 Apr 2026

    The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.

    Published: 19 Sept 2006
    5.1
    Medium

    CVE-2006-4844

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4849

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Published: 19 Sept 2006
    5.1
    Medium

    CVE-2006-4850

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter.

    Published: 19 Sept 2006
    5.1
    Medium

    CVE-2006-4846

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors.

    Published: 19 Sept 2006
    6.5
    Medium

    CVE-2006-4847

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4848

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.php, (6) appreciation.php, (7) partenariat.php, (8) rechercher.php, (9) projet.php, (10) propoexample.php, (11) refererpoint.php, or (12) top50.php. NOTE: this issue has been disputed by a third party researcher, stating that REP_CLASS is initialized in an included file before being used

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4853

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in kategorihaberx.asp.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4852

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter.

    Published: 19 Sept 2006
    5.1
    Medium

    CVE-2006-4845

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tc_config[app_root] parameter.

    Published: 19 Sept 2006
    7.5
    High

    CVE-2006-4851

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in system/_b/contentFiles/gBHTMLEditor.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4334

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.

    Published: 19 Sept 2006
    5
    Medium

    CVE-2006-4338

    Last Modified: 16 Apr 2026

    unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.

    Published: 19 Sept 2006
    7.8
    High

    CVE-2006-4924

    Last Modified: 23 Apr 2026

    sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.

    Published: 19 Sept 2006