CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-2955

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b) album.asp.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2956

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in i.List 1.5 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) searchword parameter to search.php or (2) siteurl parameter to add.php.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2957

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2968

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2969

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the input box in quickchat.php, and possibly other manipulations.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2970

    Last Modified: 16 Apr 2026

    videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain sensitive information via a certain id parameter, probably with an invalid value, which reveals the path in an error message.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2971

    Last Modified: 16 Apr 2026

    Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet with fewer than 12 bytes, which results in a long length value to the crc32 function.

    Published: 12 Jun 2006
    2.1
    Low

    CVE-2006-2967

    Last Modified: 16 Apr 2026

    Syworks SafeNET allows local users to bypass restrictions on network resource consumption by editing the policy.dat file.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2943

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CGI-RESCUE WebFORM 4.1 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for this issue are obtained from third party information.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2950

    Last Modified: 16 Apr 2026

    Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_extender.php, which reveals the path in an error message.

    Published: 12 Jun 2006
    6.8
    Medium

    CVE-2006-2951

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.10 and earlier allow remote attackers to inject arbitrary web script and HTML via the (1) Titlesitename or (2) sitename parameter to (a) header.php, (3) nuke_url parameter to (b) meta/meta.php, (4) forum parameter to (c) viewforum.php, (5) post_id, (6) forum, (7) topic, or (8) arbre parameter to (d) editpost.php, or (9) uname or (10) email parameter to (e) user.php.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2959

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2966

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Particle Soft Particle Wiki 1.0.2 allows remote attackers to inject arbitrary web script or HTML via a BR element with an extraneous IMG tag and a STYLE attribute that contains "/**/" comment sequences, which bypasses the XSS protection scheme.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2944

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CGI-RESCUE FORM2MAIL 1.21 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for this issue are obtained from third party information.

    Published: 12 Jun 2006
    5
    Medium

    CVE-2006-2952

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) Default_Theme parameter to header.php or (2) ModPath parameter to modules/cluster-paradise/cluster-E.php.

    Published: 12 Jun 2006
    2.6
    Low

    CVE-2006-2958

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in FilZip 3.05 allows remote attackers to write arbitrary files via a .. (dot dot) in a (1) .rar, (2) .tar, (3) .jar, or (4) .gz file. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2960

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/joomla.php in Joomla! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2962

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2963

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Suchergebnisse.asp in Cabacos Web CMS 3.8.498 and earlier allows remote attackers to inject arbitrary web script or HTML via the suchtext parameter.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2961

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 12 Jun 2006
    7.5
    High

    CVE-2006-2964

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) download.php, (2) manager.php, (3) admin/scripts/category.php, (4) includes/add_allow.php, (5) admin/index.php, and (6) admin/admin/login.php.

    Published: 12 Jun 2006
    4.3
    Medium

    CVE-2006-2965

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."

    Published: 12 Jun 2006
    3.7
    Low

    CVE-2006-2452

    Last Modified: 16 Apr 2026

    GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.

    Published: 9 Jun 2006
    7.5
    High

    CVE-2006-2912

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.

    Published: 9 Jun 2006
    2.6
    Low

    CVE-2006-2913

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.

    Published: 9 Jun 2006
    5.1
    Medium

    CVE-2006-2921

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in cmpro_header.inc.php in Clan Manager Pro (CMPRO) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) cm_ext_server and (2) sitepath parameters.

    Published: 9 Jun 2006
    7.5
    High

    CVE-2006-2926

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL HTTP request.

    Published: 9 Jun 2006
    4.3
    Medium

    CVE-2006-2927

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in post.asp in CodeAvalanche FreeForum (aka CAForum) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_subject and (2) msg_body parameters. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Jun 2006
    5.1
    Medium

    CVE-2006-2928

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter in (1) dialogs/img.php and (2) dialogs/td.php.

    Published: 9 Jun 2006
    5
    Medium

    CVE-2006-2924

    Last Modified: 16 Apr 2026

    Ingate Firewall in the SIP module before 4.4.1 and SIParator before 4.4.1, when TLS is enabled or when SSL/TLS is enabled in the web server, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake.

    Published: 9 Jun 2006
    4.6
    Medium

    CVE-2006-2930

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Grid Engine 5.3 and Sun N1 Grid Engine 6.0, when configured in Certificate Security Protocol (CSP) Mode, allows local users to shut down the grid service or gain access, even if access is denied.

    Published: 9 Jun 2006
    6.4
    Medium

    CVE-2006-2923

    Last Modified: 16 Apr 2026

    The iax_net_read function in the iaxclient open source library, as used in multiple products including (a) LoudHush 1.3.6, (b) IDE FISK 1.35 and earlier, (c) Kiax 0.8.5 and earlier, (d) DIAX, (e) Ziaxphone, (f) IAX Phone, (g) X-lite, (h) MediaX, (i) Extreme Networks ePhone, and (j) iaxComm before 1.2.0, allows remote attackers to execute arbitrary code via crafted IAX 2 (IAX2) packets with truncated (1) full frames or (2) mini-frames, which are detected in a length check but still processed, leading to buffer overflows related to negative length values.

    Published: 9 Jun 2006
    4
    Medium

    CVE-2006-2925

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web interface in Ingate Firewall before 4.4.1 and SIParator before 4.4.1 allows remote attackers to inject arbitrary web script or HTML, and steal cookies, via unspecified vectors related to "XSS exploits" in administrator functionality.

    Published: 9 Jun 2006
    6.8
    Medium

    CVE-2006-2929

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.

    Published: 9 Jun 2006
    5.1
    Medium

    CVE-2006-2922

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php when register_globals is enabled, and (2) listconfigfile[] parameter in (b) galsecurity.lib.php and (c) galimage.lib.php.

    Published: 9 Jun 2006
    7.8
    High

    CVE-2006-2919

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via crafted inputs that trigger memory corruption.

    Published: 9 Jun 2006
    2.6
    Low

    CVE-2006-2920

    Last Modified: 16 Apr 2026

    Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.

    Published: 9 Jun 2006
    5.6
    Medium

    CVE-2006-2448

    Last Modified: 16 Apr 2026

    Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signal_64.c) and cause a denial of service (crash) and possibly read kernel memory on 32-bit systems (signal_32.c).

    Published: 9 Jun 2006
    5
    Medium

    CVE-2006-2902

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is legitimate, as the original researcher seems unsure.

    Published: 8 Jun 2006
    2.6
    Low

    CVE-2006-2903

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 8 Jun 2006
    7.5
    High

    CVE-2006-2904

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Published: 8 Jun 2006
    5.4
    Medium

    CVE-2006-2906

    Last Modified: 16 Apr 2026

    The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop.

    Published: 8 Jun 2006
    5
    Medium

    CVE-2006-2905

    Last Modified: 16 Apr 2026

    Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.

    Published: 8 Jun 2006
    5
    Medium

    CVE-2006-1173

    Last Modified: 16 Apr 2026

    Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.

    Published: 7 Jun 2006
    5
    Medium

    CVE-2006-2901

    Last Modified: 16 Apr 2026

    The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system information via a request to an arbitrary .cfg file, which returns configuration information including passwords.

    Published: 7 Jun 2006
    4
    Medium

    CVE-2006-2900

    Last Modified: 16 Apr 2026

    Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

    Published: 7 Jun 2006
    7.5
    High

    CVE-2006-2879

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in newscomments.php in Alex News-Engine 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Published: 7 Jun 2006
    4.3
    Medium

    CVE-2006-2883

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 7 Jun 2006
    4.3
    Medium

    CVE-2006-2885

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree Open Source 3.0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fDocumentId parameter in view.php and the (2) fSearchableText parameter in /search/simpleSearch.php.

    Published: 7 Jun 2006
    4.3
    Medium

    CVE-2006-2886

    Last Modified: 16 Apr 2026

    view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.

    Published: 7 Jun 2006