CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2006-4547

    Last Modified: 16 Apr 2026

    Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (single quote) character in the name, which reveals the details of the underlying SQL query, possibly because of a forced SQL error or SQL injection.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4551

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to execute arbitrary PHP code via (1) the file specified as the value of the format parameter, and possibly (2) the RSS feed.

    Published: 6 Sept 2006
    6.8
    Medium

    CVE-2006-4552

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to inject arbitrary web script or HTML via the RSS feed.

    Published: 6 Sept 2006
    6.8
    Medium

    CVE-2006-4553

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4555

    Last Modified: 16 Apr 2026

    Buffer overflow in the Retro64 / Miniclip CR64Loader ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors involving an HTML document that references the CLSID of the control.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4559

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3) categories/populate.php, (4) comments/populate.php, (5) files/file.php, (6) sections/section.php, (7) sections/populate.php, (8) tables/populate.php, (9) users/user.php, and (10) users/populate.php. The articles/article.php vector is covered by CVE-2006-4532.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4560

    Last Modified: 16 Apr 2026

    Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4561

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.

    Published: 6 Sept 2006
    5
    Medium

    CVE-2006-4562

    Last Modified: 16 Apr 2026

    The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has stated that the default configuration does not proxy DNS queries received on the external interface

    Published: 6 Sept 2006
    5
    Medium

    CVE-2006-4549

    Last Modified: 16 Apr 2026

    CHXO Feedsplitter 2006-01-21 allows remote attackers to read the source code of feedsplitter.php via the showsource function. NOTE: this issue is not a vulnerability in standard distributions, but could be an issue if the source has been modified.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4556

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has stated that the product distribution does not include an index.php file. Also, this might be related to CVE-2006-4242

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4557

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in plugins/plugins.php in Bob Jewell Discloser 0.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the type parameter. NOTE: another researcher has stated that an attacker cannot control the type parameter. As of 20060901, CVE analysis concurs with the dispute

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-3126

    Last Modified: 16 Apr 2026

    c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4544

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ExBB 1.9.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the exbb[home_path] parameter in files in the modules directory including (1) birstday/birst.php (2) birstday/select.php, (3) birstday/profile_show.php, (4) newusergreatings/pm_newreg.php, (5) punish/p_error.php, (6) punish/profile.php, and (7) threadstop/threadstop.php. NOTE: the (8) modules/userstop/userstop.php vector might overlap CVE-2006-4488, although it is for a slightly different product from the same vendor.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4548

    Last Modified: 16 Apr 2026

    e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code via the tinyMCE_imglib_include image/jpeg parameter in e107_handlers/tiny_mce/plugins/ibrowser/ibrowser.php, as demonstrated by a multipart/form-data request. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in e107.

    Published: 6 Sept 2006
    5
    Medium

    CVE-2006-4550

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to read arbitrary XML files via .. (dot dot) sequences in the format parameter with a leading ".", which bypasses a security check.

    Published: 6 Sept 2006
    5.1
    Medium

    CVE-2006-4554

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ReadFile function in the ZOO-processing exports in the BeCubed Compression Plus before 5.0.1.28, as used in products including (1) Tumbleweed EMF, (2) VCOM/Ontrack PowerDesk Pro, (3) Canyon Drag and Zip, (4) Canyon Power File, and (5) Canyon Power File Gold, allow context-dependent attackers to execute arbitrary code via an inconsistent size parameter in a ZOO file header.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4558

    Last Modified: 16 Apr 2026

    DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

    Published: 6 Sept 2006
    6.8
    Medium

    CVE-2006-4543

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game parameter in players mode, the (2) weapon parameter in weaponinfo mode, the (3) st parameter in search mode, the (4) action parameter in actioninfo mode, and the (5) map parameter in mapinfo mode.

    Published: 6 Sept 2006
    6.5
    Medium

    CVE-2006-4546

    Last Modified: 16 Apr 2026

    Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter.

    Published: 6 Sept 2006
    7.5
    High

    CVE-2006-4539

    Last Modified: 16 Apr 2026

    (1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 5 Sept 2006
    6.8
    Medium

    CVE-2006-4540

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 5 Sept 2006
    6.8
    Medium

    CVE-2006-4542

    Last Modified: 16 Apr 2026

    Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

    Published: 5 Sept 2006
    4.6
    Medium

    CVE-2006-4541

    Last Modified: 16 Apr 2026

    RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.

    Published: 5 Sept 2006
    7.5
    High

    CVE-2006-4536

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the podpis parameter.

    Published: 5 Sept 2006
    2.1
    Low

    CVE-2006-4537

    Last Modified: 16 Apr 2026

    NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.

    Published: 5 Sept 2006
    9.3
    Critical

    CVE-2006-4534

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.

    Published: 5 Sept 2006
    4.3
    Medium

    CVE-2006-4339

    Last Modified: 16 Apr 2026

    OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

    Published: 5 Sept 2006
    5
    Medium

    CVE-2006-4096

    Last Modified: 16 Apr 2026

    BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.

    Published: 5 Sept 2006
    3.6
    Low

    CVE-2006-4842

    Last Modified: 23 Apr 2026

    The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

    Published: 5 Sept 2006
    6.8
    Medium

    CVE-2006-3636

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Sept 2006
    2.3
    Low

    CVE-2006-4600

    Last Modified: 16 Apr 2026

    slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).

    Published: 4 Sept 2006
    5
    Medium

    CVE-2006-2941

    Last Modified: 16 Apr 2026

    Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".

    Published: 4 Sept 2006
    4.3
    Medium

    CVE-2006-4525

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.

    Published: 1 Sept 2006
    5
    Medium

    CVE-2006-4523

    Last Modified: 16 Apr 2026

    The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET request.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4533

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, (2) categories.php, (3) news.php, (4) prefs.php, (5) sites.php, (6) subtypes.php, (7) users.php, (8) xmedia.php, (9) frontinc/class.template.php, (10) inc/lib.text.php, (11) install/index.php, (12) install/upgrade.php, and (13) tools/htaccess/index.php. NOTE: other vectors are covered by CVE-2006-3562, CVE-2006-2645, and CVE-2006-0725.

    Published: 1 Sept 2006
    7.2
    High

    CVE-2006-4522

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

    Published: 1 Sept 2006
    2.6
    Low

    CVE-2006-4527

    Last Modified: 16 Apr 2026

    includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion attacks.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4526

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the searchArray[] parameter.

    Published: 1 Sept 2006
    4.3
    Medium

    CVE-2006-4528

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) recherche parameter in recherchemembre.php and the (2) email parameter in test.php.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4529

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in recherchemembre.php in membrepass 1.5. allows remote attackers to execute arbitrary SQL commands via the recherche parameter.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4530

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in include/change.php in membrepass 1.5 allows remote attackers to execute arbitrary PHP code via the aifon parameter, which is injected into include/variable.php.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4531

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4532

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter.

    Published: 1 Sept 2006
    7.5
    High

    CVE-2006-4524

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameters. NOTE: some of these details are obtained from third party information.

    Published: 1 Sept 2006
    4.6
    Medium

    CVE-2006-4507

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the TIFF viewer (possibly libTIFF) in the Photo Viewer in the Sony PlaystationPortable (PSP) 2.00 through 2.80 allows local users to execute arbitrary code via crafted TIFF images. NOTE: due to lack of details, it is not clear whether this is related to other issues such as CVE-2006-3464 or CVE-2006-3465.

    Published: 31 Aug 2006
    4
    Medium

    CVE-2006-4508

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and 0.1.1.x before 0.1.1.23, and (2) ScatterChat before 1.0.2, allows remote attackers operating a Tor entry node to route arbitrary Tor traffic through clients or cause a denial of service (flood) via unspecified vectors.

    Published: 31 Aug 2006
    3.6
    Low

    CVE-2006-4506

    Last Modified: 16 Apr 2026

    idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.

    Published: 31 Aug 2006
    7.5
    High

    CVE-2006-4498

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a different vector than CVE-2006-3922.

    Published: 31 Aug 2006
    4
    Medium

    CVE-2006-4490

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2) scripts/s360v2/s360.exe.

    Published: 31 Aug 2006