CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2006-3134

    Last Modified: 16 Apr 2026

    Buffer overflow in GraceNote CDDBControl ActiveX Control, as used by multiple products that use Gracenote CDDB, allows remote attackers to execute arbitrary code via a long option string.

    Published: 27 Jun 2006
    10
    Critical

    CVE-2006-3232

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."

    Published: 27 Jun 2006
    7.5
    High

    CVE-2006-3234

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters.

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3235

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc parameters.

    Published: 27 Jun 2006
    7.5
    High

    CVE-2006-3236

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in thinkWMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) index.php or (b) printarticle.php, and the (2) catid parameter in index.php.

    Published: 27 Jun 2006
    4.3
    Medium

    CVE-2006-3240

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.

    Published: 27 Jun 2006
    7.5
    High

    CVE-2006-3243

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter.

    Published: 27 Jun 2006
    5.1
    Medium

    CVE-2006-3244

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php.

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3245

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters.

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3246

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in show.php in GL-SH Deaf Forum 6.4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the sort parameter.

    Published: 27 Jun 2006
    7.5
    High

    CVE-2006-3239

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter.

    Published: 27 Jun 2006
    Unknown

    CVE-2006-3248

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4011. Reason: This candidate is a duplicate of CVE-2005-4011. Notes: All CVE users should reference CVE-2005-4011 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3230

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 27 Jun 2006
    7.5
    High

    CVE-2006-3238

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in VBZooM 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) MemberID parameter to rank.php, and the (2) QuranID parameter to lng.php.

    Published: 27 Jun 2006
    4.3
    Medium

    CVE-2006-3231

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."

    Published: 27 Jun 2006
    4.3
    Medium

    CVE-2006-3233

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in Open WebMail (OWM) 2.52, and other versions released before 06/18/2006, allows remote attackers to inject arbitrary web script or HTML via the from field. NOTE: some third party sources have mentioned the "to" and "from" fields, although CVE analysis shows that these are associated with the previous version, a different executable, and a different CVE.

    Published: 27 Jun 2006
    7.5
    High

    CVE-2006-3249

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the vendor has disputed this report, stating "If a non positive integer or non-integer is used for the page parameter for a search URL, the search query will use a negative number for the LIMIT clause. This causes the query to break, showing no results. It IS NOT however a sql injection error." While the original report is from a researcher with mixed accuracy, as of 20060703, CVE does not have any additional information regarding this issue

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3241

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in messages.php in XennoBB 1.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the tid parameter.

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3237

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Enterprise Groupware System (EGS) 1.2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter.

    Published: 27 Jun 2006
    2.6
    Low

    CVE-2006-3247

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in show.php in GL-SH Deaf Forum 6.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) page, and (3) action parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jun 2006
    4.3
    Medium

    CVE-2006-3229

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Open WebMail (OWM) 2.52, and other versions released before 05/12/2006, allows remote attackers to inject arbitrary web script or HTML via the (1) To and (2) From fields in openwebmail-main.pl, and possibly (3) other unspecified vectors related to "openwebmailerror calls that need to display HTML."

    Published: 27 Jun 2006
    4.6
    Medium

    CVE-2006-2935

    Last Modified: 16 Apr 2026

    The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer overflow.

    Published: 27 Jun 2006
    4
    Medium

    CVE-2006-3469

    Last Modified: 16 Apr 2026

    Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.

    Published: 27 Jun 2006
    9.3
    Critical

    CVE-2006-3228

    Last Modified: 16 Apr 2026

    Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.

    Published: 26 Jun 2006
    2.6
    Low

    CVE-2006-3225

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.

    Published: 26 Jun 2006
    7.5
    High

    CVE-2006-3226

    Last Modified: 16 Apr 2026

    Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server port for an administration session, which allows remote attackers to bypass authentication via various methods, aka "ACS Weak Session Management Vulnerability."

    Published: 26 Jun 2006
    5.4
    Medium

    CVE-2006-3224

    Last Modified: 16 Apr 2026

    Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself.

    Published: 26 Jun 2006
    2.6
    Low

    CVE-2006-3227

    Last Modified: 16 Apr 2026

    Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ASCII characters with the 8th bit set, which could be stripped by Internet Explorer to render legible text, but not when using other browsers. NOTE: there has been significant discussion about this issue, and as of 20060625, it is not clear where the responsibility for this issue lies, although it might be due to vagueness within the associated standards. NOTE: this might only be exploitable with certain encodings.

    Published: 26 Jun 2006
    4.6
    Medium

    CVE-2006-2196

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at raised privileges.

    Published: 26 Jun 2006
    2.6
    Low

    CVE-2006-2311

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page.

    Published: 26 Jun 2006
    5
    Medium

    CVE-2006-2310

    Last Modified: 16 Apr 2026

    BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.

    Published: 26 Jun 2006
    4.6
    Medium

    CVE-2006-3011

    Last Modified: 16 Apr 2026

    The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

    Published: 26 Jun 2006
    7.8
    High

    CVE-2006-2936

    Last Modified: 16 Apr 2026

    The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) by writing more data to the serial port than the hardware can handle, which causes the data to be queued.

    Published: 26 Jun 2006
    4.6
    Medium

    CVE-2006-2933

    Last Modified: 16 Apr 2026

    kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop.

    Published: 25 Jun 2006
    7.5
    High

    CVE-2006-3218

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Published: 24 Jun 2006
    7.5
    High

    CVE-2006-3219

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.

    Published: 24 Jun 2006
    7.5
    High

    CVE-2006-3220

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3222

    Last Modified: 16 Apr 2026

    The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.

    Published: 24 Jun 2006
    7.5
    High

    CVE-2006-3221

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction.

    Published: 24 Jun 2006
    10
    Critical

    CVE-2006-3203

    Last Modified: 16 Apr 2026

    The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3204

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which is set in the pass_env cookie.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3205

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.

    Published: 24 Jun 2006
    5.1
    Medium

    CVE-2006-3210

    Last Modified: 16 Apr 2026

    Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3216

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages.

    Published: 24 Jun 2006
    2.6
    Low

    CVE-2006-3217

    Last Modified: 16 Apr 2026

    JaguarEditControl (JEdit) ActiveX Control 1.1.0.20 and earlier allows remote attackers to obtain sensitive information, such as the username and MAC and IP addresses, by setting the test field to certain values such as 2404 or 2790, then reading the information from the .JText field.

    Published: 24 Jun 2006
    7.2
    High

    CVE-2006-3209

    Last Modified: 16 Apr 2026

    The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. NOTE: this issue has been disputed by third parties, who state that the Task scheduler is limited to the Administrators group by default upon installation

    Published: 24 Jun 2006
    4.3
    Medium

    CVE-2006-3211

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments parameter.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3214

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Hitachi Groupmax Address Server 7 and earlier, and Groupmax Mail Server 7 and earlier allows remote attackers to cause a denial of service (product "stop") via unspecified vectors involving "unexpected requests".

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3207

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in newpost.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the id parameter, as demonstrated by injecting a Perl CGI script using "[NR]" sequences in the message parameter, then calling close.php with modified id and t_id parameters to chmod the script. NOTE: this issue might be resultant from dynamic variable evaluation.

    Published: 24 Jun 2006
    6.5
    Medium

    CVE-2006-3208

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which are stored as configuration settings. NOTE: this issue can be exploited by remote attackers by leveraging other vulnerabilities in UPB.

    Published: 24 Jun 2006