CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-3215

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to bypass the "text analysis", possibly bypassing SPAM and other filters, by sending an e-mail specifying a non-existent or unrecognized character set.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-3206

    Last Modified: 16 Apr 2026

    register.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to create arbitrary accounts via the "[NR]" sequence in the signature field, which is used to separate multiple records.

    Published: 24 Jun 2006
    4.3
    Medium

    CVE-2006-3212

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Jun 2006
    7.5
    High

    CVE-2006-3213

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WeBBoA Hosting 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter to an unspecified script, possibly host/yeni_host.asp.

    Published: 24 Jun 2006
    5
    Medium

    CVE-2006-2918

    Last Modified: 16 Apr 2026

    The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by "replaying the ViewState for a known number."

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3198

    Last Modified: 16 Apr 2026

    Integer overflow in Opera 8.54 and earlier allows remote attackers to execute arbitrary code via a JPEG image with large height and width values, which causes less memory to be allocated than intended.

    Published: 23 Jun 2006
    4.9
    Medium

    CVE-2006-3202

    Last Modified: 16 Apr 2026

    The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by creating an IPv4-mapped IPv6 socket with the SO_TIMESTAMP socket option set, then sending an IPv4 packet through the socket.

    Published: 23 Jun 2006
    5
    Medium

    CVE-2006-3200

    Last Modified: 16 Apr 2026

    Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with a src tag containing a "File://" URI followed by an 8-bit character. NOTE: some third parties were unable to verify this issue.

    Published: 23 Jun 2006
    5.1
    Medium

    CVE-2006-2915

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration.

    Published: 23 Jun 2006
    5
    Medium

    CVE-2006-3199

    Last Modified: 16 Apr 2026

    Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation.

    Published: 23 Jun 2006
    4.9
    Medium

    CVE-2006-3201

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

    Published: 23 Jun 2006
    5.1
    Medium

    CVE-2006-2914

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php, and (6) pm/newpm.php in the default/ directory.

    Published: 23 Jun 2006
    4
    Medium

    CVE-2006-2445

    Last Modified: 16 Apr 2026

    Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.

    Published: 23 Jun 2006
    7.8
    High

    CVE-2006-3085

    Last Modified: 16 Apr 2026

    xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3191

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3168

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut parameters in (a) read.php, and the (3) search and (4) debut parameters in (b) index.php.

    Published: 23 Jun 2006
    6.4
    Medium

    CVE-2006-3194

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) gallery and (2) template parameter.

    Published: 23 Jun 2006
    5.1
    Medium

    CVE-2006-3193

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; multiple files in adminpanel/includes/add_forms/ including (2) addbioform.php, (3) addfliersform.php, (4) addgenmerchform.php, (5) addinterviewsform.php, (6) addlinksform.php, (7) addlyricsform.php, (8) addmembioform.php, (9) addmerchform.php, (10) addmerchpicform.php, (11) addnewsform.php, (12) addphotosform.php, (13) addreleaseform.php, (14) addreleasepicform.php, (15) addrelmerchform.php, (16) addreviewsform.php, (17) addshowsform.php, (18) addwearmerchform.php; (19) adminpanel/includes/mailinglist/disphtmltbl.php, and (20) adminpanel/includes/mailinglist/dispxls.php.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3185

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter.

    Published: 23 Jun 2006
    4
    Medium

    CVE-2006-3184

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.

    Published: 23 Jun 2006
    6.8
    Medium

    CVE-2006-3183

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when (2) updating a profile, (3) posting comments or entries in a blog, (4) uploading files, (5) picture captions, and (6) sending a private message (PM).

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3177

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the destination parameter.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3173

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path[cb] parameter to (a) libraries/comment/postComment.php and (b) modules/poll/poll.php, (2) rel parameter to (c) modules/archive/overview.inc.php, and the (3) actualModuleDir parameter to (d) modules/forum/showThread.inc.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3172

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trailing slash (/) character in the (1) lang_path parameter to (a) cms/plugins/col_man/column.inc.php, (b) cms/plugins/poll/poll.inc.php, (c) cms/plugins/user_managment/usrPortrait.inc.php, (d) cms/plugins/user_managment/user.inc.php, (e) cms/plugins/media_manager/media.inc.php, (f) cms/plugins/events/permanent.eventMonth.inc.php, (g) cms/plugins/events/events.inc.php, and (h) cms/plugins/newsletter2/newsletter.inc.php; (2) path[cb] parameter to (i) modules/guestbook/guestbook.inc.php, (j) modules/shoutbox/shoutBox.php, and (k) modules/sitemap/sitemap.inc.php; and the (3) rel parameter to (l) modules/download/overview.inc.php, (m) modules/download/detailView.inc.php, (n) modules/article/fullarticle.inc.php, (o) modules/article/comments.inc.php, (p) modules/article2/overview.inc.php, (q) modules/article2/fullarticle.inc.php, (r) modules/article2/comments.inc.php, (s) modules/headline/headlineBox.php, and (t) modules/headline/showHeadline.inc.php.

    Published: 23 Jun 2006
    5
    Medium

    CVE-2006-3170

    Last Modified: 16 Apr 2026

    CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty collapse[] or readall parameter to index.php, which reveals the installation path in an error message.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3192

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath parameter in common.php and (2) unspecified vectors in ad.php.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3176

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3175

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3169

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) msg_result and (2) rep_titre parameters in (a) read.php; and the (3) id and (4) parent parameters and (5) CSForum_nom, (6) CSForum_mail, and (7) CSForum_url cookie parameters in (b) ajouter.php.

    Published: 23 Jun 2006
    2.6
    Low

    CVE-2006-4624

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.

    Published: 23 Jun 2006
    5
    Medium

    CVE-2006-3178

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3179

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in tools_ftp_pwaendern.php in Confixx Pro 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the account parameter.

    Published: 23 Jun 2006
    6.8
    Medium

    CVE-2006-3180

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ftp_index.php in Confixx Pro 3.0 allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3181

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to execute arbitrary SQL commands via the browse parameter.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3182

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the uid parameter in the rss page.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3186

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpath parameter to (1) data/footer.php and (2) admin/header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3187

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sharky e-shop 3.05 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) maingroup and (2) secondgroup parameters to (a) search_prod_list.asp, and the (3) maingroup parameter to (b) meny2.asp. NOTE: it is possible that this is resultant from SQL injection or a forced SQL error.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3188

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Sharky e-shop 3.05 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) maingroup and (2) secondgroup parameters to (a) search_prod_list.asp, and the (3) maingroup parameter to (b) meny2.asp. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 23 Jun 2006
    5.8
    Medium

    CVE-2006-3189

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 23 Jun 2006
    7.5
    High

    CVE-2006-3190

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3195

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the template parameter.

    Published: 23 Jun 2006
    5
    Medium

    CVE-2006-3196

    Last Modified: 16 Apr 2026

    index.php in singapore 0.10.0 and earlier allows remote attackers to obtain the installation path via an invalid template parameter, which reveals the path in an error message.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3197

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.

    Published: 23 Jun 2006
    2.6
    Low

    CVE-2006-3174

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter.

    Published: 23 Jun 2006
    5
    Medium

    CVE-2006-3171

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a newline character in the email parameter to ajouter.php.

    Published: 23 Jun 2006
    4.3
    Medium

    CVE-2006-3156

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate eShop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the subid parameter.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3141

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in details.cfm in Tradingeye Shop R4 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3142

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3165

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3163

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters.

    Published: 22 Jun 2006