CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-2382

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2370

    Last Modified: 16 Apr 2026

    Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2384

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2376

    Last Modified: 16 Apr 2026

    Integer overflow in the PolyPolygon function in Graphics Rendering Engine on Microsoft Windows 98 and Me allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) or EMF image with a sum of entries in the vertext counts array and number of polygons that triggers a heap-based buffer overflow.

    Published: 13 Jun 2006
    2.1
    Low

    CVE-2006-2660

    Last Modified: 16 Apr 2026

    Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.

    Published: 13 Jun 2006
    Unknown

    CVE-2006-3008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2904. Reason: This candidate is a duplicate of CVE-2006-2904. Notes: All CVE users should reference CVE-2006-2904 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-3006

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-3007

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ.

    Published: 13 Jun 2006
    5
    Medium

    CVE-2006-3005

    Last Modified: 16 Apr 2026

    The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2984

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in IntegraMOD 1.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the STYLE_URL parameter. NOTE: it is possible that this issue is resultant from SQL injection.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2985

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in IntegraMOD 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded "'" characters in the STYLE_URL parameter.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2986

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in index.php and the (2) title parameter in myslideshow.php.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2988

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in dictionary.php in Chemical Dictionary allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a browse action.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2993

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp.

    Published: 13 Jun 2006
    5.8
    Medium

    CVE-2006-2994

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in phazizGuestbook 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) url fields, and (4) text field (content parameter).

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2995

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INCDIR parameter in (1) include/nav.php and (2) include/lang.php.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2996

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dir[data] parameter.

    Published: 13 Jun 2006
    5.8
    Medium

    CVE-2006-3001

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkMall 1.0 allow remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: this might be resultant from another vulnerability, since the XSS is reflected in an error message.

    Published: 13 Jun 2006
    5.8
    Medium

    CVE-2006-3002

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in details.php in Easy Ad-Manager allows remote attackers to inject arbitrary web script or HTML via the mbid parameter, which is reflected in an error message. NOTE: on 20060829, the vendor notified CVE that this issue has been fixed.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-3004

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in player.php and (2) keyword parameter when performing a search.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2982

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in (1) footer.php and (2) admin/footer.php.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2991

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2 allow remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element, and possibly other manipulations, in the ringid parameter in (1) next.cgi, (2) stats.cgi, or (3) list.cgi.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-3003

    Last Modified: 16 Apr 2026

    details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant from another vulnerability, since this vector also produces cross-site scripting (XSS). NOTE: on 20060829, the vendor notified CVE that this issue has been fixed.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2908

    Last Modified: 16 Apr 2026

    The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2983

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in cal.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2987

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Dominios Europa PICRATE (aka TAL RateMyPic) 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) voteid, and (3) vfiel parameters to (a) index.php, and via the (4) nick, (5) email, (6) city, (7) messen, and (8) message form field parameters to (b) add.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2990

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2992

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in display.asp in My Photo Scrapbook 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the key_m parameter.

    Published: 13 Jun 2006
    2.6
    Low

    CVE-2006-2997

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the raw parameter in the search field.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2998

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2999

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in OkScripts QuickLinks 1.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2989

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in listpics.asp in ASP ListPics 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the info parameter.

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-3000

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2981

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2972

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in vs_resource.php in Arantius Vice Stats 0.5b and 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2976

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2977

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in big.php in Mafia Moblog 0.6M1 and earlier allows remote attackers to execute arbitrary SQL commands via the img parameter.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2978

    Last Modified: 16 Apr 2026

    Mafia Moblog 0.6M1 and earlier allows remote attackers to obtain the installation path in an error message via a direct request to (1) big.php and (2) upgrade.php.

    Published: 12 Jun 2006
    2.6
    Low

    CVE-2006-2979

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not properly handled in block_forum_topics.php, and (2) item_id parameter in reviews.php, which is not properly handled in block_reviews.php.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2980

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id parameter.

    Published: 12 Jun 2006
    2.6
    Low

    CVE-2006-2974

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp.

    Published: 12 Jun 2006
    2.6
    Low

    CVE-2006-2975

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2973

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c.

    Published: 12 Jun 2006
    4
    Medium

    CVE-2006-2945

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the user profile change functionality in DokuWiki, when Access Control Lists are enabled, allows remote authenticated users to read unauthorized files via unknown attack vectors.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2946

    Last Modified: 16 Apr 2026

    Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2947

    Last Modified: 16 Apr 2026

    Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parameter.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2948

    Last Modified: 16 Apr 2026

    A-CART 2.0 stores the acart2_0.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain username and password information.

    Published: 12 Jun 2006
    6.8
    Medium

    CVE-2006-2949

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do parameter.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2953

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow 2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the sqlType parameter.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2954

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the Project parameter.

    Published: 12 Jun 2006