CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2006-4270

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 21 Aug 2006
    5
    Medium

    CVE-2006-4265

    Last Modified: 16 Apr 2026

    Kaspersky Anti-Hacker 1.8.180, when Stealth Mode is enabled, allows remote attackers to obtain responses to ICMP (1) timestamp and (2) netmask requests, which is inconsistent with the documented behavior of Stealth Mode.

    Published: 21 Aug 2006
    4
    Medium

    CVE-2006-4257

    Last Modified: 16 Apr 2026

    IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.

    Published: 21 Aug 2006
    4
    Medium

    CVE-2006-4258

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, and possibly other types of paths in the file parameter.

    Published: 21 Aug 2006
    2.6
    Low

    CVE-2006-4259

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Fotopholder 1.8 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this might be resultant from a directory traversal vulnerability.

    Published: 21 Aug 2006
    5
    Medium

    CVE-2006-4260

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Fotopholder 1.8 allows remote attackers to read arbitrary directories or files via a .. (dot dot) in the path parameter.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4254

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.

    Published: 21 Aug 2006
    4.3
    Medium

    CVE-2006-4256

    Last Modified: 16 Apr 2026

    index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.

    Published: 21 Aug 2006
    Unknown

    CVE-2006-4261

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4253. Reason: This candidate is a duplicate of CVE-2006-4253. Notes: All CVE users should reference CVE-2006-4253 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Aug 2006
    4.3
    Medium

    CVE-2006-4255

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolder_label form field in the IMP search screen.

    Published: 21 Aug 2006
    4.6
    Medium

    CVE-2006-3506

    Last Modified: 16 Apr 2026

    Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local users with Xsan write access, to execute arbitrary code via unspecified vectors related to "processing a path name."

    Published: 21 Aug 2006
    7.2
    High

    CVE-2006-0948

    Last Modified: 16 Apr 2026

    AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4235

    Last Modified: 16 Apr 2026

    Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to execute arbitrary code via a crafted SMP file.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4239

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_inc parameter.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4240

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4241

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 21 Aug 2006
    5.1
    Medium

    CVE-2006-4242

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4236

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parameter to (a) s01.php, (b) s02.php, (c) s03.php, and (d) s04.php; and possibly a URL located after "shopid=" or "sid=" in the PATH_INFO.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4237

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter.

    Published: 21 Aug 2006
    7.5
    High

    CVE-2006-4238

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in torrents.php in WebTorrent (WTcom) 0.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter in category mode.

    Published: 21 Aug 2006
    7.8
    High

    CVE-2006-4623

    Last Modified: 16 Apr 2026

    The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.

    Published: 21 Aug 2006
    5.1
    Medium

    CVE-2006-4262

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.

    Published: 20 Aug 2006
    4.3
    Medium

    CVE-2006-4224

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the year parameter. NOTE: The page parameter vector is covered by CVE-2006-4009.

    Published: 18 Aug 2006
    Unknown

    CVE-2006-4225

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-3139. Reason: This candidate is a duplicate of CVE-2006-3139. Notes: All CVE users should reference CVE-2006-3139 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Aug 2006
    7.5
    High

    CVE-2006-4234

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

    Published: 18 Aug 2006
    9.3
    Critical

    CVE-2006-4221

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the IBM Access Support eGatherer ActiveX control before 3.20.0284.0 allows remote attackers to execute arbitrary code via a long filename parameter to the RunEgatherer method.

    Published: 18 Aug 2006
    7.5
    High

    CVE-2006-4230

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php in Lizge V.20 Web Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) lizge or (2) bade parameters.

    Published: 18 Aug 2006
    5
    Medium

    CVE-2006-4222

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.

    Published: 18 Aug 2006
    5
    Medium

    CVE-2006-4223

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.

    Published: 18 Aug 2006
    2.6
    Low

    CVE-2006-4231

    Last Modified: 16 Apr 2026

    IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.

    Published: 18 Aug 2006
    1.2
    Low

    CVE-2006-4232

    Last Modified: 16 Apr 2026

    Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.

    Published: 18 Aug 2006
    3.6
    Low

    CVE-2006-4233

    Last Modified: 16 Apr 2026

    Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1) myproxy-admin-adduser, (2) grid-ca-sign, and (3) grid-security-config.

    Published: 18 Aug 2006
    9
    Critical

    CVE-2006-4228

    Last Modified: 16 Apr 2026

    Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 before MP1 20060816 allows remote attackers to bypass authentication and gain privileges via unknown attack vectors in the management interface.

    Published: 18 Aug 2006
    7.5
    High

    CVE-2006-4229

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 18 Aug 2006
    7.5
    High

    CVE-2006-4219

    Last Modified: 16 Apr 2026

    The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.

    Published: 18 Aug 2006
    2.6
    Low

    CVE-2006-4486

    Last Modified: 16 Apr 2026

    Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

    Published: 18 Aug 2006
    7.5
    High

    CVE-2006-4217

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4218

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter parameter.

    Published: 17 Aug 2006
    Unknown

    CVE-2006-4216

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4159. Reason: This candidate is a duplicate of CVE-2006-4159. Notes: All CVE users should reference CVE-2006-4159 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Aug 2006
    6.8
    Medium

    CVE-2006-4195

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4200

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4201

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4202

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4203

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4207

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php.

    Published: 17 Aug 2006
    5
    Medium

    CVE-2006-4208

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4209

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter.

    Published: 17 Aug 2006
    2.6
    Low

    CVE-2006-4210

    Last Modified: 16 Apr 2026

    nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information.

    Published: 17 Aug 2006
    4.3
    Medium

    CVE-2006-4211

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Aug 2006
    7.5
    High

    CVE-2006-4197

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.

    Published: 17 Aug 2006