CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-2797

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4) EventLocationID parameter in (f) delAddress.php; and (5) LocationID parameter in (g) delCategory.php.

    Published: 3 Jun 2006
    6.8
    Medium

    CVE-2006-2798

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php.

    Published: 3 Jun 2006
    7.5
    High

    CVE-2006-2792

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 3 Jun 2006
    6.8
    Medium

    CVE-2006-2795

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XiTi Tracking Script 6 and 7 RC allow remote attackers to inject arbitrary web script or HTML via (1) the xtref parameter in xiti.js and (2) an HTTP Referer header field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Jun 2006
    7.5
    High

    CVE-2006-2793

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.

    Published: 3 Jun 2006
    5
    Medium

    CVE-2006-2791

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in iBoutique.MALL and possibly iBoutique allows remote attackers to read arbitrary files via ".." sequences in the function parameter.

    Published: 3 Jun 2006
    2.6
    Low

    CVE-2006-2789

    Last Modified: 16 Apr 2026

    Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used.

    Published: 2 Jun 2006
    7.2
    High

    CVE-2006-2790

    Last Modified: 16 Apr 2026

    A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileges.

    Published: 2 Jun 2006
    7.5
    High

    CVE-2006-2775

    Last Modified: 16 Apr 2026

    Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wrong URL.

    Published: 2 Jun 2006
    7.5
    High

    CVE-2006-2777

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to execute arbitrary code by using the nsISelectionPrivate interface of the Selection object to add a SelectionListener and create notifications that are executed in a privileged context.

    Published: 2 Jun 2006
    2.6
    Low

    CVE-2006-2766

    Last Modified: 16 Apr 2026

    Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.

    Published: 2 Jun 2006
    5.1
    Medium

    CVE-2006-2767

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the default_path parameter in (1) error.php, (2) index.php, and (3) classes/main_class.php.

    Published: 2 Jun 2006
    5
    Medium

    CVE-2006-2769

    Last Modified: 16 Apr 2026

    The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2773

    Last Modified: 16 Apr 2026

    admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Jun 2006
    6.8
    Medium

    CVE-2006-2774

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in QontentOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_phrase parameter.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2771

    Last Modified: 16 Apr 2026

    admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.

    Published: 2 Jun 2006
    5.1
    Medium

    CVE-2006-2768

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) system_path parameter in a large number of files in the (a) app/edocument/, (b) app/eproject/, (c) app/erek/, and (d) extension/ directories, and the (2) GLOBALS[system_path] parameter in (e) extension/sitemap/sitemap.datatype.php.

    Published: 2 Jun 2006
    6.8
    Medium

    CVE-2006-2772

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Jun 2006
    4.6
    Medium

    CVE-2006-2662

    Last Modified: 16 Apr 2026

    VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges.

    Published: 2 Jun 2006
    5.4
    Medium

    CVE-2006-2770

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an index of the "file" array parameter, as demonstrated by file[0].

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2763

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. It is possible that this is primary to CVE-2006-2678.

    Published: 2 Jun 2006
    4.3
    Medium

    CVE-2006-2755

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.

    Published: 2 Jun 2006
    4.3
    Medium

    CVE-2006-2764

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an IMG tag in a comment field to (1) guestwrite.php or (2) guestbook.php.

    Published: 2 Jun 2006
    4.3
    Medium

    CVE-2006-2757

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) start parameter in (a) index.php; (2) forumID parameter in index.php, (b) newtopic.php, and (c) reply.php; and (3) ID parameter to (d) edit.php.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2654

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar to CVE-2006-1864, but this is a different implementation of smbfs, so it has a different CVE identifier.

    Published: 2 Jun 2006
    5
    Medium

    CVE-2006-2756

    Last Modified: 16 Apr 2026

    Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request. NOTE: CVE analysis suggests that this is a different product, and therefore a different vulnerability, than CVE-2002-1897.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2655

    Last Modified: 16 Apr 2026

    The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/securenets file, which allows remote attackers to bypass intended access restrictions.

    Published: 2 Jun 2006
    7.5
    High

    CVE-2006-2760

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules.php in 4nNukeWare 4nForum 0.91 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2761

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Hitachi HITSENSER3 HITSENSER3/PRP, HITSENSER3/PUP, HITSENSER3/STP, and HITSENSER3/EUP allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2762

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter, which is remotely accessed in an fopen call whose results are used to define a user_inc setting that is used in an include_once call.

    Published: 2 Jun 2006
    2.6
    Low

    CVE-2006-2765

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in news_information.php in Interlink Advantage allows remote attackers to inject arbitrary web script or HTML via the flag parameter.

    Published: 2 Jun 2006
    9.3
    Critical

    CVE-2006-2780

    Last Modified: 16 Apr 2026

    Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.

    Published: 2 Jun 2006
    9.3
    Critical

    CVE-2006-2779

    Last Modified: 16 Apr 2026

    Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.

    Published: 2 Jun 2006
    5.5
    Medium

    CVE-2006-2308

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.

    Published: 2 Jun 2006
    4
    Medium

    CVE-2006-2309

    Last Modified: 16 Apr 2026

    The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests containing dot, space, and slash characters, which reveals the source code of script files.

    Published: 2 Jun 2006
    6.4
    Medium

    CVE-2006-2781

    Last Modified: 16 Apr 2026

    Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.

    Published: 2 Jun 2006
    5
    Medium

    CVE-2006-2754

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.

    Published: 1 Jun 2006
    6.4
    Medium

    CVE-2006-2749

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary SQL commands via the (1) txtCustomField and (2) CustomFieldID array parameters.

    Published: 1 Jun 2006
    5.1
    Medium

    CVE-2006-2747

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo.

    Published: 1 Jun 2006
    6.8
    Medium

    CVE-2006-2746

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao. NOTE: vectors 2 and 3 might be resultant from file inclusion issues.

    Published: 1 Jun 2006
    5.1
    Medium

    CVE-2006-2745

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b) p-editbox.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao.

    Published: 1 Jun 2006
    7.5
    High

    CVE-2006-2742

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

    Published: 1 Jun 2006
    5
    Medium

    CVE-2006-2734

    Last Modified: 16 Apr 2026

    enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote attackers to conduct password guessing attacks by setting the guvenlik parameter to the same value as the hidden gguvenlik parameter, which bypasses a verification step because the gguvenlik parameter is assumed to be immutable by the attacker.

    Published: 1 Jun 2006
    7.6
    High

    CVE-2006-2439

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.

    Published: 1 Jun 2006
    7.5
    High

    CVE-2006-2727

    Last Modified: 16 Apr 2026

    home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter.

    Published: 1 Jun 2006
    2.6
    Low

    CVE-2006-2728

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the pic parameter.

    Published: 1 Jun 2006
    2.6
    Low

    CVE-2006-2729

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Jun 2006
    5.1
    Medium

    CVE-2006-2735

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507.

    Published: 1 Jun 2006
    5.1
    Medium

    CVE-2006-2736

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507.

    Published: 1 Jun 2006
    7.5
    High

    CVE-2006-2737

    Last Modified: 16 Apr 2026

    utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.

    Published: 1 Jun 2006