CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-4084

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in phpAutoMembersArea (phpAMA) before 3.2.4 has unknown impact and attack vectors, related to "a potential security exploit which is critical."

    Published: 11 Aug 2006
    3.6
    Low

    CVE-2006-4092

    Last Modified: 16 Apr 2026

    Simpliciti Locked Browser does not properly limit a user's actions to ones within the intended Internet Explorer environment, which allows local users to perform unauthorized actions by visiting a web site that executes a JavaScript window.blur loop to remove focus from the browser window, then pressing CTRL-SHIFT-ESC to invoke the Task Manager.

    Published: 11 Aug 2006
    6.5
    Medium

    CVE-2006-4072

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL commands via the (1) haber_id parameter to haber_detay.asp, and allow remote authenticated users to execute arbitrary SQL commands via the (2) menu_id parameter to menu.asp.

    Published: 11 Aug 2006
    7.5
    High

    CVE-2006-4073

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.

    Published: 11 Aug 2006
    6.8
    Medium

    CVE-2006-4074

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 11 Aug 2006
    6.8
    Medium

    CVE-2006-4079

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic title field).

    Published: 11 Aug 2006
    2.6
    Low

    CVE-2006-4080

    Last Modified: 16 Apr 2026

    DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.

    Published: 11 Aug 2006
    7.5
    High

    CVE-2006-4077

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter.

    Published: 11 Aug 2006
    5.1
    Medium

    CVE-2006-4075

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2) lib/email.inc.php, (3) lib/document.class.php or (4) lib/auth.inc.php.

    Published: 11 Aug 2006
    7.5
    High

    CVE-2006-4078

    Last Modified: 16 Apr 2026

    pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.

    Published: 11 Aug 2006
    5.1
    Medium

    CVE-2006-4076

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/access.inc.php, (2) lib/folders.inc.php, (3) lib/init.inc.php or (4) lib/templates.inc.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 11 Aug 2006
    6.4
    Medium

    CVE-2006-4019

    Last Modified: 16 Apr 2026

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.

    Published: 11 Aug 2006
    2.6
    Low

    CVE-2006-4071

    Last Modified: 16 Apr 2026

    Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.

    Published: 10 Aug 2006
    5.4
    Medium

    CVE-2006-2446

    Last Modified: 16 Apr 2026

    Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the LTP test suite.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4050

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4051

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.

    Published: 10 Aug 2006
    5.1
    Medium

    CVE-2006-4053

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4057

    Last Modified: 16 Apr 2026

    Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a large email attachment.

    Published: 10 Aug 2006
    6.8
    Medium

    CVE-2006-4058

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in archive.php in Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyw parameter when performing a search. NOTE: some details are obtained from third party information.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4060

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4064

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported reported that 2.0 is also affected.

    Published: 10 Aug 2006
    5.1
    Medium

    CVE-2006-4065

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php.

    Published: 10 Aug 2006
    2.6
    Low

    CVE-2006-4066

    Last Modified: 16 Apr 2026

    The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue.

    Published: 10 Aug 2006
    2.1
    Low

    CVE-2006-3813

    Last Modified: 16 Apr 2026

    A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4055

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to (1) include/colorswitch.php, (2) contentimages.class.php, (3) ipfunctions.php, (4) configfunctions.php, (5) printpagedetails.php, or (6) log.class.php. NOTE: the copyright.php vector is already covered by CVE-2006-3993.

    Published: 10 Aug 2006
    5.1
    Medium

    CVE-2006-4062

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter.

    Published: 10 Aug 2006
    4.3
    Medium

    CVE-2006-4069

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submit comment" action.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4052

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4) admin/login.php, (5) admin/menu.php or (6) admin/header.php.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4054

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ME Download System 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) Vb8878b936c2bd8ae0cab parameter to (a) inc/sett_style.php or (b) inc/sett_smilies.php; or the (2) Vb6c4d0e18a204a63b38f, (3) V18a78b93c3adaaae84e2, or (4) V9ae5d2ca9e9e787969ff parameters to (c) inc/datei.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4056

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. NOTE: portions of these details are obtained from third party information.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4059

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) newsscript_lyt.php, (2) newsticker/newsscript_get.php, (3) inc/output/news_theme1.php, (4) inc/output/news_theme2.php, or (5) inc/output/news_theme3.php.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4061

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the rep_par_rapport_racine variable is initialized before use

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4063

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b) usr/extensions/get_blog_meta_info.inc.php, or (c) usr/extensions/get_infochannel.inc.php; or the (2) GLOBALS[root_path] parameter to (d) usr/extensions/get_tree.inc.php.

    Published: 10 Aug 2006
    4.3
    Medium

    CVE-2006-4067

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.

    Published: 10 Aug 2006
    5.1
    Medium

    CVE-2006-4070

    Last Modified: 16 Apr 2026

    Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename.

    Published: 10 Aug 2006
    5
    Medium

    CVE-2006-4068

    Last Modified: 16 Apr 2026

    The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force attacks. NOTE: this script might also allow attackers to generate the server-side "secret" URL without determining the original password, but this possibility was not discussed by the original researcher.

    Published: 10 Aug 2006
    7.5
    High

    CVE-2006-4040

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4041

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Pike before 7.6.86, when using a Postgres database server, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4042

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters.

    Published: 9 Aug 2006
    5
    Medium

    CVE-2006-4043

    Last Modified: 16 Apr 2026

    index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message.

    Published: 9 Aug 2006
    2.1
    Low

    CVE-2006-4049

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the utxconfig utility in Sun Ray Server Software 3.x allows local users to create or overwrite arbitrary files via unknown attack vectors.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4045

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4046

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by the itplayerclass::module::load function, (3) a crafted .ULT file handled by the mpLoadULT function, or (4) a crafted .AMS file handled by the mpLoadAMS function.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4048

    Last Modified: 16 Apr 2026

    Netious CMS 0.4 initializes session IDs based on the client IP address, which allows remote attackers to gain access to the administration section when originating from the same IP address as the administrator. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4044

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4047

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Netious CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 9 Aug 2006
    5
    Medium

    CVE-2006-3122

    Last Modified: 16 Apr 2026

    The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with a 32 byte client-identifier, which causes the packet to be interpreted as a corrupt uid and causes the server to exit with "corrupt lease uid."

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4034

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the DIR parameter.

    Published: 9 Aug 2006
    7.5
    High

    CVE-2006-4035

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in counterchaos.php in CounterChaos 0.48c and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

    Published: 9 Aug 2006
    10
    Critical

    CVE-2006-4037

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 9 Aug 2006