CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-3323

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.

    Published: 30 Jun 2006
    5
    Medium

    CVE-2006-3324

    Last Modified: 16 Apr 2026

    The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neededpaks buffer.

    Published: 30 Jun 2006
    7.5
    High

    CVE-2006-3329

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter.

    Published: 30 Jun 2006
    6.8
    Medium

    CVE-2006-3330

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php.

    Published: 30 Jun 2006
    5
    Medium

    CVE-2006-3331

    Last Modified: 16 Apr 2026

    Opera before 9.0 does not reset the SSL security bar after displaying a download dialog from an SSL-enabled website, which allows remote attackers to spoof a trusted SSL certificate from an untrusted website and facilitates phishing attacks.

    Published: 30 Jun 2006
    7.5
    High

    CVE-2006-3332

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters.

    Published: 30 Jun 2006
    2.6
    Low

    CVE-2006-3333

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified parameters, including the (1) frommethod, (2) list, and (3) method, which are reflected in an error message. NOTE: some of these vectors might be resultant from SQL injection.

    Published: 30 Jun 2006
    5
    Medium

    CVE-2006-3325

    Last Modified: 16 Apr 2026

    client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.

    Published: 30 Jun 2006
    2.6
    Low

    CVE-2006-3326

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in QuickZip 3.06.3 allows remote user-assisted attackers to overwrite arbitrary files or directories via .. (dot dot) sequences in filenames within (1) TAR,(2) GZ, and (3) JAR archives. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jun 2006
    4.3
    Medium

    CVE-2006-3327

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Custom dating biz dating script 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) sn20_special_cases parameter ("Special Cases" field) in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name" field) in profile/photo_create.php, and the (3) u parameter in admin/user_view.php.

    Published: 30 Jun 2006
    5.8
    Medium

    CVE-2006-3328

    Last Modified: 16 Apr 2026

    new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal and replay authentication credentials via an IMG tag in the desc parameter ("Ticket Description" field) that points to a URL that captures referer URLs, possibly due to a cross-site scripting (XSS) vulnerability or a leak of credentials in referer URLs.

    Published: 30 Jun 2006
    7.5
    High

    CVE-2006-3334

    Last Modified: 16 Apr 2026

    Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name".

    Published: 30 Jun 2006
    5.1
    Medium

    CVE-2006-3322

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in includes/functions_logging.php in phpRaid 3.0.5, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the log_hack function.

    Published: 30 Jun 2006
    1.2
    Low

    CVE-2006-3118

    Last Modified: 16 Apr 2026

    spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary file before use, which could cause conflicts with other programs that use the same filename, but this is not a distinct issue.

    Published: 30 Jun 2006
    4.3
    Medium

    CVE-2006-3321

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in openforum.asp in OpenForum 1.2 Beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ofdisp and (2) ofmsgid parameters.

    Published: 30 Jun 2006
    4.3
    Medium

    CVE-2006-3319

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.

    Published: 30 Jun 2006
    2.6
    Low

    CVE-2006-3320

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.

    Published: 30 Jun 2006
    5
    Medium

    CVE-2006-2934

    Last Modified: 16 Apr 2026

    SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers to cause a denial of service (crash) via a packet without any chunks, which causes a variable to contain an invalid value that is later used to dereference a pointer.

    Published: 30 Jun 2006
    7.5
    High

    CVE-2006-3376

    Last Modified: 16 Apr 2026

    Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.

    Published: 30 Jun 2006
    Unknown

    CVE-2006-2657

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-3017. Reason: This candidate is a reservation duplicate of CVE-2006-3017. Notes: All CVE users should reference CVE-2006-3017 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-1467

    Last Modified: 16 Apr 2026

    Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3115

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the raid_id parameter.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3116

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.4 and 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) configuration.php, (3) guilds.php, (4) index.php, (5) locations.php, (6) login.php, (7) lua_output.php, (8) permissions.php, (9) profile.php, (10) raids.php, (11) register.php, (12) roster.php, and (13) view.php.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3317

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3316

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) logs.php and (2) users.php, a different set of vectors than CVE-2006-3116.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3318

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters.

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3315

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the osCsid parameter.

    Published: 29 Jun 2006
    2.6
    Low

    CVE-2006-3313

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.

    Published: 29 Jun 2006
    4.3
    Medium

    CVE-2006-3312

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, and (6) link_list parameters in top.inc as included by queries_view_search.php; the (7) msg, (8) component_name, and (9) component_desc parameters in (a) components_copy_content.php, (b) components_modify_content.php, and (c) components_new_content.php; the (10) title, (11) version, and (12) content parameters in design_copy_content.php; the (13) plan_title and (14) plan_content parameters in design_copy_plan_search.php; the (15) title, (16) minor_version, (17) new_version, and (18) content parameters in design_modify_content.php; the (19) title, (20) version, and (21) content parameters in design_new_content.php; the (22) plan_name and (23) plan_desc parameters in design_new_search.php; the (24) file_name parameter in download.php; the (25) username and (26) password parameters in login.php; the (27) title, (28) version, and (29) content parameters in phase_copy_content.php; the (30) content parameter in phase_delete_search.php; the (31) title, (32) minor_version, (33) new_version, and (34) content parameters in phase_modify_content.php; the (35) content, (36) title, (37) version, and (38) content parameters in phase_modify_search.php; the (39) content parameter in phase_view_search.php; the (40) msg, (41) product_name, and (42) product_desc parameters in products_copy_content.php; and possibly the (43) product_name and (44) product_desc parameters in (d) products_copy_search.php, and a large number of additional parameters and executables. NOTE: the vendor notified CVE via e-mail that this issue has been fixed in the 6.8 RC release.

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3314

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the pageid parameter.

    Published: 29 Jun 2006
    5
    Medium

    CVE-2006-3268

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.

    Published: 29 Jun 2006
    5
    Medium

    CVE-2006-3293

    Last Modified: 16 Apr 2026

    parse_notice (TiCPU) in EnergyMech (emech) before 3.0.2 allows remote attackers to cause a denial of service (crash) via empty IRC CTCP NOTICE messages.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3294

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3300

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.

    Published: 29 Jun 2006
    5.1
    Medium

    CVE-2006-3302

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in mod_cbsms.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosC_a_path parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

    Published: 29 Jun 2006
    4.3
    Medium

    CVE-2006-3303

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in pm.php in DeluxeBB 1.07 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) to parameters.

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3307

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Project EROS bbsengine before bbsengine-20060429-1550-jam allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters in the php/comment.php and (2) the getpartialmatches method in php/aolbonics.php.

    Published: 29 Jun 2006
    9.3
    Critical

    CVE-2006-3308

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3309

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Published: 29 Jun 2006
    2.6
    Low

    CVE-2006-3305

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau Webmail 2.7.10, and 2.7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) f_user parameter in index.php, the (2) pag parameter in messages.php, or the (3) lid, (4) tid, and (5) sid parameters in error.php.

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3296

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter.

    Published: 29 Jun 2006
    4.3
    Medium

    CVE-2006-3297

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.php in UebiMiau Webmail 2.7.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the icq parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Jun 2006
    5
    Medium

    CVE-2006-3298

    Last Modified: 16 Apr 2026

    Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll.

    Published: 29 Jun 2006
    2.6
    Low

    CVE-2006-3299

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary web script or HTML via the group parameter.

    Published: 29 Jun 2006
    2.6
    Low

    CVE-2006-3301

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin 2.2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) user_add.php or (2) unit_add.php.

    Published: 29 Jun 2006
    4.3
    Medium

    CVE-2006-3306

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the preparestring function in lib/common.php in Project EROS bbsengine before 20060501-0142-jam, and possibly earlier versions dating back to 2006-02-23, might allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 29 Jun 2006
    4.3
    Medium

    CVE-2006-3295

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 29 Jun 2006
    7.5
    High

    CVE-2006-3304

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter.

    Published: 29 Jun 2006
    7.6
    High

    CVE-2006-3117

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."

    Published: 29 Jun 2006
    7.6
    High

    CVE-2006-2198

    Last Modified: 16 Apr 2026

    OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

    Published: 29 Jun 2006