CVE Feed

    Dashboard / CVE

    1.2
    Low

    CVE-2006-4676

    Last Modified: 16 Apr 2026

    TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.

    Published: 11 Sept 2006
    5
    Medium

    CVE-2006-4681

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter.

    Published: 11 Sept 2006
    6.8
    Medium

    CVE-2006-4671

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter, a different vector than CVE-2006-1154.

    Published: 11 Sept 2006
    7.5
    High

    CVE-2006-4672

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrary PHP code via a URL in the (1) proMod parameter to (a) index.php, or the (2) docroot parameter to (b) index.php or (c) mainpage.php.

    Published: 11 Sept 2006
    2.6
    Low

    CVE-2006-4673

    Last Modified: 16 Apr 2026

    Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

    Published: 11 Sept 2006
    2.6
    Low

    CVE-2006-4650

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.

    Published: 9 Sept 2006
    5
    Medium

    CVE-2006-4651

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in download/index.php, and possibly download.php, in threesquared.net (aka Ben Speakman) Php download allows remote attackers to overwrite arbitrary local files via .. (dot dot) sequence in the file parameter.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4652

    Last Modified: 16 Apr 2026

    (1) Amazing Little Poll and (2) Amazing Little Picture Poll have a default password of "dsapoll", which allows remote attackers to create a new poll by entering default credentials via lp_admin.php.

    Published: 9 Sept 2006
    4.6
    Medium

    CVE-2006-4655

    Last Modified: 16 Apr 2026

    Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4656

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition.

    Published: 9 Sept 2006
    7.2
    High

    CVE-2006-4657

    Last Modified: 16 Apr 2026

    Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying (1) WebProxy.exe or (2) PAVSRV51.EXE.

    Published: 9 Sept 2006
    5
    Medium

    CVE-2006-4658

    Last Modified: 16 Apr 2026

    Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if the user replies to a message, which might allow remote attackers to determine mail usage patterns.

    Published: 9 Sept 2006
    4.3
    Medium

    CVE-2006-4665

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MKPortal M1.1 Rc1 allows remote attackers to inject arbitrary web script or HTML via the ind parameter, possibly related to the PHP_SELF variable. NOTE: Some details are obtained from third party information.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4667

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in (a) class/sessions.class.php, and the (2) timezone_offset and (3) umode parameters in (b) class/xoopsuser.php.

    Published: 9 Sept 2006
    4.3
    Medium

    CVE-2006-4668

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via the task_id parameter in an edit_task command.

    Published: 9 Sept 2006
    5
    Medium

    CVE-2006-4659

    Last Modified: 16 Apr 2026

    The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, which allows remote attackers to cause Panda to classify arbitrary messages as spam via a web page that contains IMG tags with the predictable URLs. NOTE: this issue could also be regarded as a cross-site request forgery (CSRF) vulnerability.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4670

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) includes/cart.inc.php or (2) extras/ext_cats.php.

    Published: 9 Sept 2006
    5
    Medium

    CVE-2006-4294

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 9 Sept 2006
    3.6
    Low

    CVE-2006-4625

    Last Modified: 16 Apr 2026

    PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

    Published: 9 Sept 2006
    5.1
    Medium

    CVE-2006-4654

    Last Modified: 16 Apr 2026

    Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.

    Published: 9 Sept 2006
    5.8
    Medium

    CVE-2006-4660

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed module in AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) allow remote attackers to process arbitrary web script or HTML in the Feeds interface context via the (1) title and (2) description elements within an item element in an RSS feed.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4662

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message in a 0x2711 Type-Length-Value (TLV) type.

    Published: 9 Sept 2006
    7.8
    High

    CVE-2006-4663

    Last Modified: 16 Apr 2026

    The source code tar archive of the Linux kernel 2.6.16, 2.6.17.11, and possibly other versions specifies weak permissions (0666 and 0777) for certain files and directories, which might allow local users to insert Trojan horse source code that would be used during the next kernel compilation. NOTE: another researcher disputes the vulnerability, stating that he finds "Not a single world-writable file or directory." CVE analysis as of 20060908 indicates that permissions will only be weak under certain unusual or insecure scenarios

    Published: 9 Sept 2006
    5.1
    Medium

    CVE-2006-4664

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4666

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b) delete.php, (c) modify.php, (d) admin.php, or (e) modify_go.php.

    Published: 9 Sept 2006
    5
    Medium

    CVE-2006-4653

    Last Modified: 16 Apr 2026

    (1) Amazing Little Poll and (2) Amazing Little Picture Poll store sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password via a direct request for the lp_settings file (lp_settings.inc or lp_settings.php).

    Published: 9 Sept 2006
    2.6
    Low

    CVE-2006-4661

    Last Modified: 16 Apr 2026

    AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick the user into reconfiguring the toolbar.

    Published: 9 Sept 2006
    5.1
    Medium

    CVE-2006-4669

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.

    Published: 9 Sept 2006
    7.5
    High

    CVE-2006-4379

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4641

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Published: 8 Sept 2006
    1.7
    Low

    CVE-2006-4642

    Last Modified: 16 Apr 2026

    AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4643

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the id_joueur parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4644

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the repmod parameter.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4648

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.

    Published: 8 Sept 2006
    6.8
    Medium

    CVE-2006-4646

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module before pathauto_node.inc 1.14.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4649

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.

    Published: 8 Sept 2006
    6.8
    Medium

    CVE-2006-2482

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive vector is covered by CVE-2005-2856.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4647

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4645

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary PHP code via a URL in the bm_content parameter.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4632

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) groupe parameter in addmembre.php and the (2) select parameter in moveto.php.

    Published: 8 Sept 2006
    4.3
    Medium

    CVE-2006-4634

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.

    Published: 8 Sept 2006
    6.5
    Medium

    CVE-2006-4635

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related to the Equation attribute in Web_Extensions - Notitia (I/II). NOTE: due to lack of details, it is not clear whether this issue is file inclusion, static code injection, or another type of issue.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4629

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 8 Sept 2006
    5.1
    Medium

    CVE-2006-4637

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information.

    Published: 8 Sept 2006
    5.1
    Medium

    CVE-2006-4638

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4630

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter.

    Published: 8 Sept 2006
    6.5
    Medium

    CVE-2006-4631

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.

    Published: 8 Sept 2006
    7.5
    High

    CVE-2006-4636

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.

    Published: 8 Sept 2006
    5.1
    Medium

    CVE-2006-4639

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) formulaire_commentaires.php, (2) affichage/liste_news.php, (3) affichage/news_complete.php, or (4) affichage/pagination.php. NOTE: the provenance of some of this information is unknown; some details are obtained from third party information.

    Published: 8 Sept 2006
    4.3
    Medium

    CVE-2006-4628

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in VCD-db before 0.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when handling comments.

    Published: 8 Sept 2006