CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2006-1175

    Last Modified: 16 Apr 2026

    The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.

    Published: 31 May 2006
    7.2
    High

    CVE-2006-2679

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows local authenticated, interactive users to gain privileges, possibly due to privileges of dialog boxes, aka bug ID CSCsd79265.

    Published: 31 May 2006
    5.8
    Medium

    CVE-2006-2680

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.

    Published: 31 May 2006
    6.8
    Medium

    CVE-2006-2681

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2) inc-common.php.

    Published: 31 May 2006
    6.4
    Medium

    CVE-2006-2682

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _PSL[classdir] parameter.

    Published: 31 May 2006
    4.9
    Medium

    CVE-2006-2687

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).

    Published: 31 May 2006
    6.4
    Medium

    CVE-2006-2688

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector parameter.

    Published: 31 May 2006
    6.8
    Medium

    CVE-2006-2689

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3) perso and (4) aide parameters to (c) an unknown script, probably index.php.

    Published: 31 May 2006
    7.8
    High

    CVE-2006-2690

    Last Modified: 16 Apr 2026

    An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.

    Published: 31 May 2006
    7.5
    High

    CVE-2006-2694

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php.

    Published: 31 May 2006
    5.1
    Medium

    CVE-2006-2695

    Last Modified: 16 Apr 2026

    admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.

    Published: 31 May 2006
    6.8
    Medium

    CVE-2006-2696

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp.

    Published: 31 May 2006
    6.4
    Medium

    CVE-2006-2697

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp.

    Published: 31 May 2006
    7.8
    High

    CVE-2006-2698

    Last Modified: 16 Apr 2026

    Geeklog 1.4.0sr2 and earlier allows remote attackers to obtain the full installation path via a direct request and possibly invalid arguments to (1) layout/professional/functions.php or (2) getimage.php.

    Published: 31 May 2006
    6.8
    Medium

    CVE-2006-2699

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.

    Published: 31 May 2006
    5
    Medium

    CVE-2006-2676

    Last Modified: 16 Apr 2026

    Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.

    Published: 31 May 2006
    7.5
    High

    CVE-2006-2701

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to story submission.

    Published: 31 May 2006
    5
    Medium

    CVE-2006-2702

    Last Modified: 16 Apr 2026

    vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].

    Published: 31 May 2006
    5
    Medium

    CVE-2006-2677

    Last Modified: 16 Apr 2026

    SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path information.

    Published: 31 May 2006
    5.8
    Medium

    CVE-2006-2678

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php.

    Published: 31 May 2006
    5.8
    Medium

    CVE-2006-2684

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search module in CMS Mundo 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.

    Published: 31 May 2006
    4
    Medium

    CVE-2006-2685

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (2) base_stat_common.php, and (3) includes/base_include.inc.php.

    Published: 31 May 2006
    6.4
    Medium

    CVE-2006-2686

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder.

    Published: 31 May 2006
    5
    Medium

    CVE-2006-2692

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.

    Published: 31 May 2006
    7.1
    High

    CVE-2006-2693

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin/admin_hacks_list.php in Nivisec Hacks List 1.20 and earlier for phpBB, when register_globals is enabled, allows remote attackers to read arbitrary files via a ".." in the phpEx parameter.

    Published: 31 May 2006
    6.4
    Medium

    CVE-2006-2683

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter.

    Published: 31 May 2006
    5
    Medium

    CVE-2006-2691

    Last Modified: 16 Apr 2026

    Unspecified "information leakage" vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to access arbitrary images, including dynamically generated images, via unknown vectors.

    Published: 31 May 2006
    5.1
    Medium

    CVE-2006-2700

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter.

    Published: 31 May 2006
    5
    Medium

    CVE-2006-3082

    Last Modified: 16 Apr 2026

    parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.

    Published: 31 May 2006
    7.5
    High

    CVE-2006-2753

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.

    Published: 31 May 2006
    4.3
    Medium

    CVE-2006-2663

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in iFlance 1.1 allow remote attackers to inject arbitrary web script or HTML via certain inputs to (1) acc_verify.php or (2) project.php.

    Published: 30 May 2006
    5.8
    Medium

    CVE-2006-2664

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in iFdate 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password fields, or certain other input text boxes.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2665

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2666

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.

    Published: 30 May 2006
    5.8
    Medium

    CVE-2006-2670

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ChatPat 1.0 allow remote attackers to inject arbitrary web script or HTML via a chat message in (1) fastchat.php and (2) fastshow.php.

    Published: 30 May 2006
    5
    Medium

    CVE-2006-2671

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ChatPat 1.0 allows remote attackers to execute arbitrary SQL commands via the nickname field.

    Published: 30 May 2006
    6.8
    Medium

    CVE-2006-2672

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Realty Pro One allow remote attackers to inject arbitrary web script or HTML via the (1) listingid parameter to (a) images.php, (b) index_other.php, or (c) request_info.php; (2) propertyid parameter to (d) searchlookup.php, (3) id parameter to (e) images.php, or (4) agentid parameter to (f) request_info.php. NOTE: some of these issues might be resultant from SQL injection.

    Published: 30 May 2006
    6.8
    Medium

    CVE-2006-2673

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.html in Bulletin Board Elite-Board (E-Board) 1.1 allows remote attackers to inject arbitrary web script or HTML via the search box.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2674

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Tamber Forum 1.9.13 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) frm_id parameter to (a) show_forum.asp, (2) a search field to (b) forum_search.asp, (3) Email address or (4) Password to (c) admin/index.asp, (5) frm_cat_id parameter to (d) browse_forum_cat.asp, or (6) Message Subject or (7) Message Text field to (e) post_message.asp.

    Published: 30 May 2006
    4.3
    Medium

    CVE-2006-2669

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) cid parameter in products.php.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2668

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3) modules/credits/help.php.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2667

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

    Published: 30 May 2006
    5.1
    Medium

    CVE-2006-2675

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters.

    Published: 30 May 2006
    7.8
    High

    CVE-2006-2659

    Last Modified: 16 Apr 2026

    libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial of service (CPU consumption) via unknown vectors involving usernames that contain the "=" (equals) character, which is not properly handled during encoding.

    Published: 30 May 2006
    4.3
    Medium

    CVE-2006-2634

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2636

    Last Modified: 16 Apr 2026

    newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".

    Published: 30 May 2006
    4.3
    Medium

    CVE-2006-2643

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject arbitrary web script or HTML via the user_error_message parameter.

    Published: 30 May 2006
    4
    Medium

    CVE-2006-2644

    Last Modified: 16 Apr 2026

    AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2645

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-0725.

    Published: 30 May 2006
    7.5
    High

    CVE-2006-2650

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.

    Published: 30 May 2006