CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2006-3767

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in showprofile.php in Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file in txtcomment parameter, which is used when posting a comment.

    Published: 21 Jul 2006
    5
    Medium

    CVE-2006-3835

    Last Modified: 16 Apr 2026

    Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.

    Published: 21 Jul 2006
    2.6
    Low

    CVE-2007-3835

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and 4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a resource id that can be discovered through a search.

    Published: 21 Jul 2006
    5
    Medium

    CVE-2006-3757

    Last Modified: 16 Apr 2026

    index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain sensitive information via empty (1) _GET[], (2) _SESSION[], (3) _POST[], (4) _COOKIE[], or (5) _SESSION[] array parameters, which reveals the installation path in an error message. NOTE: this issue might be resultant from a global overwrite vulnerability.

    Published: 21 Jul 2006
    6.8
    Medium

    CVE-2006-3748

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 20 Jul 2006
    6.8
    Medium

    CVE-2006-3749

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 20 Jul 2006
    7.5
    High

    CVE-2006-3754

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter.

    Published: 20 Jul 2006
    4.3
    Medium

    CVE-2006-3756

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Geeklog 1.4.0sr4 and earlier, and 1.3.11sr6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when validating comments in (1) lib-comment.php (1.4.0sr4) or (2) comment.php (0.3.11sr6).

    Published: 20 Jul 2006
    6.8
    Medium

    CVE-2006-3751

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 20 Jul 2006
    7.5
    High

    CVE-2006-3752

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters.

    Published: 20 Jul 2006
    6.4
    Medium

    CVE-2006-3753

    Last Modified: 16 Apr 2026

    setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash.

    Published: 20 Jul 2006
    7.5
    High

    CVE-2006-3755

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 20 Jul 2006
    6.8
    Medium

    CVE-2006-3750

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 20 Jul 2006
    2.6
    Low

    CVE-2006-3731

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted attackers to cause a denial of service (crash) via a form with a multipart/form-data encoding and a user-uploaded file. NOTE: a third party has claimed that this issue might be related to the LiveHTTPHeaders extension.

    Published: 19 Jul 2006
    5
    Medium

    CVE-2006-3732

    Last Modified: 16 Apr 2026

    Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information.

    Published: 19 Jul 2006
    7.5
    High

    CVE-2006-3733

    Last Modified: 16 Apr 2026

    jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute arbitrary Java code via an invokeOp action in the BSHDeployer jboss.scripts service name.

    Published: 19 Jul 2006
    7.5
    High

    CVE-2006-3736

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 19 Jul 2006
    4.3
    Medium

    CVE-2006-3737

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.

    Published: 19 Jul 2006
    3.6
    Low

    CVE-2006-3589

    Last Modified: 16 Apr 2026

    vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

    Published: 19 Jul 2006
    2.6
    Low

    CVE-2006-3729

    Last Modified: 16 Apr 2026

    DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, which leads to an integer overflow and a null dereference.

    Published: 19 Jul 2006
    8.8
    High

    CVE-2006-3730

    Last Modified: 16 Apr 2026

    Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.

    Published: 19 Jul 2006
    5.1
    Medium

    CVE-2006-3735

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the m2f_root_path parameter to (1) m2f/m2f_phpbb204.php, (2) m2f/m2f_forum.php, (3) m2f/m2f_mailinglist.php or (4) m2f/m2f_cron.php.

    Published: 19 Jul 2006
    7.2
    High

    CVE-2006-3734

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

    Published: 19 Jul 2006
    6.5
    Medium

    CVE-2006-3726

    Last Modified: 16 Apr 2026

    Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary code via a long argument to the LIST command.

    Published: 19 Jul 2006
    2.1
    Low

    CVE-2006-3725

    Last Modified: 16 Apr 2026

    Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc and (2) HKLM\SYSTEM\CurrentControlSet\Services\SymEvent registry keys.

    Published: 19 Jul 2006
    6.8
    Medium

    CVE-2006-3728

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption."

    Published: 19 Jul 2006
    7.5
    High

    CVE-2006-3727

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_id, (3) gr_3_id, and (4) doc_id parameters in (a) index.php; the (5) uid and (6) pwd parameters in (b) php/esa.php; and possibly other vectors related to files in php/lib/ including (c) del.php, (d) download_backup.php, (e) navig.php, (f) restore.php, (g) set_12.php, (h) set_14.php, and (i) upd_doc.php.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3700

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.

    Published: 19 Jul 2006
    9
    Critical

    CVE-2006-3701

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Dictionary component in Oracle Database 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors, aka Oracle Vuln# DB05.

    Published: 19 Jul 2006
    9
    Critical

    CVE-2006-3699

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 and 9.2.0.6 has unknown impact and attack vectors, aka Oracle Vuln# DB02.

    Published: 19 Jul 2006
    5
    Medium

    CVE-2006-3706

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 has unknown impact and attack vectors, aka Oracle Vuln# AS01.

    Published: 19 Jul 2006
    3.6
    Low

    CVE-2006-3707

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 and 9.0.3.1 has unknown impact and attack vectors, aka Oracle Vuln# AS02.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3708

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, 10.1.2.0.2, and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS03.

    Published: 19 Jul 2006
    5
    Medium

    CVE-2006-3709

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS04.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3710

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# (1) AS05 and (2) AS08.

    Published: 19 Jul 2006
    4
    Medium

    CVE-2006-3713

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and attack vectors, aka Oracle Vuln# AS09.

    Published: 19 Jul 2006
    5
    Medium

    CVE-2006-3714

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS10.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3715

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Calendar for Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka Oracle Vuln# OCS01.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3718

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Exchange for Oracle E-Business Suite and Applications 6.2.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS16 and (2) APPS17.

    Published: 19 Jul 2006
    5
    Medium

    CVE-2006-3712

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3722

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.4 Bundle #16, 8.8 Bundle #10, and 8.9 Bundle #3 has unknown impact and attack vectors, aka Oracle Vuln# PSE01.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3723

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.8 with Enforcer Portal Pack Bundle #10 and 8.9 Bundle #3 has unknown impact and attack vectors, aka Oracle Vuln# PSE02.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3724

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in JD Edwards HTML Server for Oracle OneWorld Tools EnterpriseOne Tools 8.95 and 8.96 has unknown impact and attack vectors, aka Oracle Vuln# JDE01.

    Published: 19 Jul 2006
    5.5
    Medium

    CVE-2006-3720

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Enterprise Config Management for Oracle Enterprise Manager 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# EM02.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3698

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB01 is related to multiple SQL injection vulnerabilities in SYS.DBMS_CDC_IMPDP using the (a) IMPORT_CHANGE_SET, (b) IMPORT_CHANGE_TABLE, (c) IMPORT_CHANGE_COLUMN, (d) IMPORT_SUBSCRIBER, (e) IMPORT_SUBSCRIBED_TABLE, (f) IMPORT_SUBSCRIBED_COLUMN, (g) VALIDATE_IMPORT, (h) VALIDATE_CHANGE_SET, (i) VALIDATE_CHANGE_TABLE, and (j) VALIDATE_SUBSCRIPTION procedures, and that DB03 is for SQL injection in the MAIN procedure for SYS.KUPW$WORKER.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3702

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB06 in Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, and (9) DBC01 for OCI; (10) DB16 for Query Rewrite/Summary Mgmt; (11) DB17, (12) DB18, (13) DB19, (14) DBC02, (15) DBC03, and (16) DBC04 for RPC; and (17) DB20 for Semantic Analysis. NOTE: as of 20060719, Oracle has not disputed third party claims that DB06 is related to "SQL injection" using DBMS_EXPORT_EXTENSION with a modified ODCIIndexGetMetadata routine and a call to GET_DOMAIN_INDEX_METADATA, in which case DB06 might be CVE-2006-2081.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3704

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Oracle ODBC Driver for Oracle Database 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# 10.1.0.4.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3705

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3717

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS03 and (2) APPS04 for Oracle Application Object Library; and (3) APPS20 for Oracle XML Gateway.

    Published: 19 Jul 2006
    10
    Critical

    CVE-2006-3721

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Management Service for Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors, aka Oracle Vuln# EM03 and EM04.

    Published: 19 Jul 2006