CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-3161

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the action parameter.

    Published: 22 Jun 2006
    2.6
    Low

    CVE-2006-3160

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in fm.php in ONEdotOH Simple File Manager (SFM) 0.24a and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 22 Jun 2006
    2.1
    Low

    CVE-2006-3159

    Last Modified: 16 Apr 2026

    pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.

    Published: 22 Jun 2006
    5.8
    Medium

    CVE-2006-3157

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Thinkfactory UltimateGoogle 1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3155

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in (a) emailtofriend.pl or (b) violation.pl, (2) seller parameter in (c) vsoa.pl, (3) user parameter in (d) userask.pl or (e) leavefeed.pl, (4) itemnum parameter in userask.pl, (5) category parameter in (f) itemlist.pl, and the (6) query parameter in (g) search.pl.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3154

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3153

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3152

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpTRADER 4.9 SP5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sectio parameter in (a) login.php, (b) write_newad.php, (c) newad.php, (d) printad.php, (e) askseller.php, (f) browse.php, (g) showmemberads.php, (h) note_ad.php, (i) abuse.php, (j) buynow.php, (k) confirm_newad.php, (2) an parameter in (l) printad.php, (m) note_ad.php, (3) who parameter in (n) showmemberads.php, and (4) adnr parameter in (o) buynow.php.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3149

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in topic.php in phpMyForum 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3148

    Last Modified: 16 Apr 2026

    SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php.

    Published: 22 Jun 2006
    6.5
    Medium

    CVE-2006-3147

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of precise details, it is not clear whether this is related to a previously disclosed issue such as CVE-2005-1788.

    Published: 22 Jun 2006
    5
    Medium

    CVE-2006-3146

    Last Modified: 16 Apr 2026

    The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demonstrated by BlueSmack. NOTE: this issue was originally reported for 4.00.23.

    Published: 22 Jun 2006
    5
    Medium

    CVE-2006-3145

    Last Modified: 16 Apr 2026

    Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code when assembling the header, possibly related to an off-by-one error.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3139

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3138

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action parameter in cp/admin_index.php.

    Published: 22 Jun 2006
    9.8
    Critical

    CVE-2006-3136

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3158

    Last Modified: 16 Apr 2026

    index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3150

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in CavoxCms 1.0.16 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3151

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3162

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3164

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in category.php in TPL Design tplShop 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the first_row parameter.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3166

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.

    Published: 22 Jun 2006
    5
    Medium

    CVE-2006-3167

    Last Modified: 16 Apr 2026

    Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified manipulations that produce an error message.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3137

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge eCommerce Shop allows remote attackers to inject arbitrary web script or HTML via the cart_id parameter.

    Published: 22 Jun 2006
    4
    Medium

    CVE-2006-3143

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3144

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3140

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in openCI 1.0 BETA 0.20.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Jun 2006
    5.8
    Medium

    CVE-2006-3132

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3131

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Clubpage allow remote attackers to inject arbitrary web script or HTML via the (1) news_archive, (2) language, and (3) intranetLogin parameters in (a) index.php; the (4) sites_id parameter in (b) sites.php; and the (5) news_id parameter in (c) news_more.php.

    Published: 22 Jun 2006
    7.5
    High

    CVE-2006-3130

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Clubpage allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 22 Jun 2006
    4.3
    Medium

    CVE-2006-3129

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC LinkList 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) view parameters.

    Published: 22 Jun 2006
    5.1
    Medium

    CVE-2006-3014

    Last Modified: 16 Apr 2026

    Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.

    Published: 22 Jun 2006
    4.6
    Medium

    CVE-2006-3128

    Last Modified: 16 Apr 2026

    choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.

    Published: 21 Jun 2006
    7.8
    High

    CVE-2006-3127

    Last Modified: 16 Apr 2026

    Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.

    Published: 21 Jun 2006
    7.5
    High

    CVE-2006-2911

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 21 Jun 2006
    5.1
    Medium

    CVE-2006-2931

    Last Modified: 16 Apr 2026

    CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing certain files.

    Published: 21 Jun 2006
    5
    Medium

    CVE-2006-3104

    Last Modified: 16 Apr 2026

    users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.

    Published: 21 Jun 2006
    5.1
    Medium

    CVE-2006-3102

    Last Modified: 16 Apr 2026

    Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.

    Published: 21 Jun 2006
    4.3
    Medium

    CVE-2006-3110

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters.

    Published: 21 Jun 2006
    4.3
    Medium

    CVE-2006-3108

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover attribute and its value, which bypasses the mail filter.

    Published: 21 Jun 2006
    5.1
    Medium

    CVE-2006-3107

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) admin/modules/news/news_class.php and (b) admin/modules/content/content_class.php, and (2) GLOBALS[where_cms] to (c) admin/modules/block_media/util.media.php. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576, but the vectors are different.

    Published: 21 Jun 2006
    4.3
    Medium

    CVE-2006-3106

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpMyDesktop|Arcade 1.0 allows remote attackers to inject arbitrary web script or HTML via the subsite parameter in the subsite todo.

    Published: 21 Jun 2006
    5
    Medium

    CVE-2006-3112

    Last Modified: 16 Apr 2026

    Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays the output of the phpinfo function.

    Published: 21 Jun 2006
    7.5
    High

    CVE-2006-3111

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr.

    Published: 21 Jun 2006
    4.3
    Medium

    CVE-2006-3109

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.

    Published: 21 Jun 2006
    5
    Medium

    CVE-2006-3105

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in index.php.

    Published: 21 Jun 2006
    4.3
    Medium

    CVE-2006-3103

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.

    Published: 21 Jun 2006
    4.3
    Medium

    CVE-2006-3101

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

    Published: 21 Jun 2006
    5.1
    Medium

    CVE-2006-2942

    Last Modified: 16 Apr 2026

    TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references the Sandbox web instead of the user web, which can then be used to associate the user's login name with the WikiName of a member of the TWikiAdminGroup.

    Published: 20 Jun 2006
    4.9
    Medium

    CVE-2006-3097

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

    Published: 20 Jun 2006