CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-3394

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3395

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3400

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3401

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3402

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the password parameter when logging in.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3359

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3380

    Last Modified: 16 Apr 2026

    Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3392

    Last Modified: 16 Apr 2026

    Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

    Published: 6 Jul 2006
    6.8
    Medium

    CVE-2006-3396

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 6 Jul 2006
    2.6
    Low

    CVE-2006-3399

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message, a variant of CVE-2004-1632.

    Published: 6 Jul 2006
    6.8
    Medium

    CVE-2006-3358

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3362

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.

    Published: 6 Jul 2006
    2.6
    Low

    CVE-2006-3366

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...".

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3367

    Last Modified: 16 Apr 2026

    Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.

    Published: 6 Jul 2006
    2.1
    Low

    CVE-2006-3373

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary files, related to logfetch running as setuid root.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3375

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3381

    Last Modified: 16 Apr 2026

    SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3389

    Last Modified: 16 Apr 2026

    index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3390

    Last Modified: 16 Apr 2026

    WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

    Published: 6 Jul 2006
    4.3
    Medium

    CVE-2006-3397

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3398

    Last Modified: 16 Apr 2026

    The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.

    Published: 6 Jul 2006
    2.6
    Low

    CVE-2006-3365

    Last Modified: 16 Apr 2026

    V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3372

    Last Modified: 16 Apr 2026

    Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3374

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter.

    Published: 6 Jul 2006
    5.8
    Medium

    CVE-2006-3383

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in mAds 1.0 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover within a URL. NOTE: the provenance of this information is unknown; the details are obtained solely from third party reports.

    Published: 6 Jul 2006
    5.8
    Medium

    CVE-2006-3388

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3354

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3353

    Last Modified: 16 Apr 2026

    Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-bounds memory access, related to an iframe and JavaScript that accesses certain style sheets properties.

    Published: 6 Jul 2006
    6.4
    Medium

    CVE-2006-3352

    Last Modified: 16 Apr 2026

    Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status

    Published: 6 Jul 2006
    5.4
    Medium

    CVE-2006-3351

    Last Modified: 16 Apr 2026

    Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.

    Published: 6 Jul 2006
    4.6
    Medium

    CVE-2006-2451

    Last Modified: 16 Apr 2026

    The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3360

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3404

    Last Modified: 16 Apr 2026

    Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.

    Published: 6 Jul 2006
    4
    Medium

    CVE-2006-3336

    Last Modified: 16 Apr 2026

    TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory.

    Published: 5 Jul 2006
    5.1
    Medium

    CVE-2006-2910

    Last Modified: 16 Apr 2026

    Buffer overflow in jetAudio 6.2.6.8330 (Basic), and possibly other versions, allows user-assisted attackers to execute arbitrary code via an audio file (such as WMA) with long ID Tag values including (1) Title, (2) Author, and (3) Album, which triggers the overflow in the tooltip display string if the sound card driver is disabled or incorrectly installed.

    Published: 5 Jul 2006
    7.2
    High

    CVE-2006-2194

    Last Modified: 16 Apr 2026

    The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.

    Published: 5 Jul 2006
    7.5
    High

    CVE-2006-3347

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP 1.3.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Jul 2006
    7.5
    High

    CVE-2006-3349

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SmS Script allow remote attackers to execute arbitrary SQL commands via the CatID parameter in (1) cat.php and (2) add.php.

    Published: 3 Jul 2006
    4.3
    Medium

    CVE-2006-3345

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and earlier, allows remote attackers to inject arbitrary web script or HTML via a chat line.

    Published: 3 Jul 2006
    7.5
    High

    CVE-2006-3346

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter.

    Published: 3 Jul 2006
    7.5
    High

    CVE-2006-3348

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php.

    Published: 3 Jul 2006
    7.5
    High

    CVE-2006-3344

    Last Modified: 16 Apr 2026

    Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component.

    Published: 3 Jul 2006
    2.6
    Low

    CVE-2006-3338

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.

    Published: 3 Jul 2006
    7.5
    High

    CVE-2006-3341

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp for Xoops allows remote attackers to execute arbitrary SQL commands via the lid parameter.

    Published: 3 Jul 2006
    5
    Medium

    CVE-2006-3339

    Last Modified: 16 Apr 2026

    secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter, which displays the installation path and other system information in an error message.

    Published: 3 Jul 2006
    2.6
    Low

    CVE-2006-3337

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Published: 3 Jul 2006
    5.1
    Medium

    CVE-2006-3340

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the (1) phpbb_root_path parameter in (a) includes/functions_cms.php and the (2) GlobalSettings[templatesDirectory] parameter in multiple files in the "includes" directory including (b) adminSensored.php, (c) adminBoards.php, (d) adminAttachments.php, (e) adminAvatars.php, (f) adminBackupdatabase.php, (g) adminBanned.php, (h) adminForums.php, (i) adminPolls.php, (j) adminSmileys.php, (k) poll.php, and (l) move.php.

    Published: 3 Jul 2006
    7.5
    High

    CVE-2006-3343

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in recipe/cookbook.php in CrisoftRicette 1.0pre15b allows remote attackers to execute arbitrary PHP code via a URL in the crisoftricette parameter.

    Published: 3 Jul 2006
    2.6
    Low

    CVE-2006-3342

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search cmd.

    Published: 3 Jul 2006
    7.2
    High

    CVE-2006-3335

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors.

    Published: 3 Jul 2006