CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2006-4754

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.

    Published: 13 Sept 2006
    7.5
    High

    CVE-2006-4748

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in F-ART BLOG:CMS 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) xagent, (2) xpath, (3) xreferer, and (4) xdns parameters in (a) admin/plugins/NP_Log.php, and the (5) pitem parameter in (b) admin/plugins/NP_Poll.php; and allow remote authenticated users to execute arbitrary SQL commands via the (6) pageRef parameter in (c) admin/plugins/NP_Referrer.php.

    Published: 13 Sept 2006
    7.5
    High

    CVE-2006-4756

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to execute arbitrary SQL commands via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 13 Sept 2006
    5
    Medium

    CVE-2006-4731

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).

    Published: 13 Sept 2006
    5.1
    Medium

    CVE-2006-4385

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4386

    Last Modified: 16 Apr 2026

    Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4388

    Last Modified: 16 Apr 2026

    Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4389

    Last Modified: 16 Apr 2026

    Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object.

    Published: 12 Sept 2006
    9.3
    Critical

    CVE-2006-0001

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.

    Published: 12 Sept 2006
    4.3
    Medium

    CVE-2006-0032

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.

    Published: 12 Sept 2006
    7.6
    High

    CVE-2006-3442

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Pragmatic General Multicast (PGM) in Microsoft Windows XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted multicast message.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4382

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4384

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-3873

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4381

    Last Modified: 16 Apr 2026

    Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie.

    Published: 12 Sept 2006
    Unknown

    CVE-2006-4180

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is a reservation duplicate of another identifier and was never published. Notes: none

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-3311

    Last Modified: 16 Apr 2026

    Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.

    Published: 12 Sept 2006
    6.8
    Medium

    CVE-2006-4640

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.

    Published: 12 Sept 2006
    4.3
    Medium

    CVE-2006-4711

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sage allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4713

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4714

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path parameter.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4720

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.

    Published: 12 Sept 2006
    6.8
    Medium

    CVE-2006-4718

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in livre_or.php in KorviBlog 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) prenom, (2) emailFrom, or (3) body parameters.

    Published: 12 Sept 2006
    6.8
    Medium

    CVE-2006-4708

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4721

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the language Cookie parameter, as demonstrated by executing PHP code via a log file.

    Published: 12 Sept 2006
    5
    Medium

    CVE-2006-2658

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.

    Published: 12 Sept 2006
    5
    Medium

    CVE-2006-4705

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 12 Sept 2006
    6.8
    Medium

    CVE-2006-4706

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via a url BBCode tag that contains a javascript URI with an SGML numeric character reference and an embedded space, as demonstrated using "java& #115;cript," a different vulnerability than CVE-2006-3761.

    Published: 12 Sept 2006
    6.8
    Medium

    CVE-2006-4707

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/global.php (aka the Admin CP login form) in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the query string ($_SERVER[PHP_SELF]).

    Published: 12 Sept 2006
    5
    Medium

    CVE-2006-4709

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in topic.php in Vikingboard 0.1b allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Published: 12 Sept 2006
    4.3
    Medium

    CVE-2006-4710

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4716

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.

    Published: 12 Sept 2006
    6.8
    Medium

    CVE-2006-4712

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScript in a content:encoded element within an item element in an RSS feed, as demonstrated by four example content:encoded elements that use XMLHttpRequest to read arbitrary local files, aka "Cross Context Scripting."

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4715

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4717

    Last Modified: 16 Apr 2026

    The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentication requirements and spoof identities of arbitrary users via unspecified vectors.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4719

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) index.php or (2) pop.php.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4722

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) index.php and possibly (2) collector.php.

    Published: 12 Sept 2006
    5.1
    Medium

    CVE-2006-4723

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_globals and WebAdmin is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SoftParserFileXml parameter.

    Published: 12 Sept 2006
    7.5
    High

    CVE-2006-4997

    Last Modified: 23 Apr 2026

    The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed pointer dereference).

    Published: 12 Sept 2006
    7.2
    High

    CVE-2006-3739

    Last Modified: 16 Apr 2026

    Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based buffer overflow.

    Published: 12 Sept 2006
    7.2
    High

    CVE-2006-3740

    Last Modified: 16 Apr 2026

    Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.

    Published: 12 Sept 2006
    Unknown

    CVE-2006-4341

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4340. Reason: This candidate was withdrawn by its CNA. It is a reservation duplicate of CVE-2006-4340. Notes: All CVE users should reference CVE-2006-4340 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta

    Published: 11 Sept 2006
    7.5
    High

    CVE-2006-4674

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.

    Published: 11 Sept 2006
    7.5
    High

    CVE-2006-4677

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in contrib/yabbse/poc.php in phpopenchat before 3.0.2 allows remote attackers to execute arbitrary PHP code via the sourcedir parameter. NOTE: this issue was disputed by a third-party researcher who stated that the _REQUEST parameters were dynamically unset at the beginning of the file. Another researcher noted, and CVE agrees, that the unset PHP function can be bypassed (CVE-2006-3017). If this issue is due to a vulnerability in PHP, then it should be excluded from CVE

    Published: 11 Sept 2006
    7.5
    High

    CVE-2006-4678

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php.

    Published: 11 Sept 2006
    5
    Medium

    CVE-2006-4679

    Last Modified: 16 Apr 2026

    DokuWiki before 2006-03-09c enables the debug feature by default, which allows remote attackers to obtain sensitive information by calling doku.php with the X-DOKUWIKI-DO HTTP header set to "debug".

    Published: 11 Sept 2006
    4
    Medium

    CVE-2006-4680

    Last Modified: 16 Apr 2026

    The Remote UI in Canon imageRUNNER includes usernames and passwords when exporting an address book, which allows context-dependent attackers to obtain sensitive information.

    Published: 11 Sept 2006
    5
    Medium

    CVE-2006-4682

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.

    Published: 11 Sept 2006
    7.5
    High

    CVE-2006-4675

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2006-03-09c allows remote attackers to upload executable files into the data/media folder via unspecified vectors.

    Published: 11 Sept 2006
    5
    Medium

    CVE-2006-4683

    Last Modified: 16 Apr 2026

    IBM Director before 5.10 allows remote attackers to obtain sensitive information from HTTP headers via HTTP TRACE.

    Published: 11 Sept 2006