CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2006-2597

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2585. Reason: This candidate is a duplicate of CVE-2006-2585. Notes: All CVE users should reference CVE-2006-2585 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 May 2006
    6.4
    Medium

    CVE-2006-2585

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 May 2006
    6.4
    Medium

    CVE-2006-2589

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable that is overwritten with static data in the extracted source code.

    Published: 25 May 2006
    4.3
    Medium

    CVE-2006-2605

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatbox, probably involving the ctext parameter to send.php.

    Published: 25 May 2006
    Unknown

    CVE-2006-2599

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2587. Reason: This candidate is a duplicate of CVE-2006-2587. Notes: All CVE users should reference CVE-2006-2587 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 May 2006
    Unknown

    CVE-2006-2596

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2584. Reason: This candidate is a duplicate of CVE-2006-2584. Notes: All CVE users should reference CVE-2006-2584 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 May 2006
    4.3
    Medium

    CVE-2006-2584

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in post.php in SkyeBox 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it was likely prompted by a vague announcement from a researcher who incorrectly referred to the product as "SkyeShoutbox."

    Published: 25 May 2006
    5.8
    Medium

    CVE-2006-2586

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the HTTP_REFERER header in an HTTP request.

    Published: 25 May 2006
    7.5
    High

    CVE-2006-2656

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.

    Published: 25 May 2006
    5.1
    Medium

    CVE-2006-2568

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2569

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2570

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue.

    Published: 24 May 2006
    7.2
    High

    CVE-2006-2574

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.

    Published: 24 May 2006
    5
    Medium

    CVE-2006-2575

    Last Modified: 16 Apr 2026

    The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (crash) via a client flag (frameNum) that is greater than 41, which triggers an assert error.

    Published: 24 May 2006
    5.1
    Medium

    CVE-2006-2576

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) lib.simplesel.php, (b) lib.filelist.php, (c) tree.documents.php, (d) lib.repo.php, and (e) lib.php, and (2) GLOBALS[where_scs] to (f) lib.teleskill.php. NOTE: this issue might be resultant from a global overwrite vulnerability.

    Published: 24 May 2006
    5.1
    Medium

    CVE-2006-2577

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) where_cms, (2) where_lms, (3) where_upgrade, (4) BBC_LIB_PATH, and (5) BBC_LANGUAGE_PATH parameters in various unspecified scripts. NOTE: the provenance of some of this information is unknown; the details are obtained solely from third party information.

    Published: 24 May 2006
    5.1
    Medium

    CVE-2006-2573

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in DGBook 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, (4) address, (5) comment, and (6) ip parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 May 2006
    2.6
    Low

    CVE-2006-2572

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) email, and (4) address parameters.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2549

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names.

    Published: 24 May 2006
    2.6
    Low

    CVE-2006-2571

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.html in Alkacon OpenCms 6.0.0, 6.0.2, and 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search action.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2579

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 and 5.5 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2580

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allow remote attackers to gain privileged access, execute arbitrary commands, or create arbitrary files via unknown vectors.

    Published: 24 May 2006
    5.1
    Medium

    CVE-2006-2578

    Last Modified: 16 Apr 2026

    admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter.

    Published: 24 May 2006
    5
    Medium

    CVE-2006-2566

    Last Modified: 16 Apr 2026

    Alstrasoft Article Manager Pro 1.6 allows remote attackers to obtain sensitive information via (1) a quote character or possibly an invalid value in the action parameter in a request to mrarticles.php or (2) a login QUERY_STRING to admin.php without any additional parameters, which reveal the path in various error messages.

    Published: 24 May 2006
    4.3
    Medium

    CVE-2006-2567

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style Sheets (CSS) property of a STYLE attribute of an element.

    Published: 24 May 2006
    4.3
    Medium

    CVE-2006-2564

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) posting a listing, (3) posting an event, (4) adding comments, or (5) sending a message.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2565

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid.

    Published: 24 May 2006
    4.3
    Medium

    CVE-2006-2553

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. This issue appears to be independent from a different issue that involves the same vector.

    Published: 24 May 2006
    6.4
    Medium

    CVE-2006-2554

    Last Modified: 16 Apr 2026

    Buffer overflow in the tell_player_surr_changes function in Genecys 0.2 and earlier might allow remote attackers to execute arbitrary code via long arguments.

    Published: 24 May 2006
    5.8
    Medium

    CVE-2006-2558

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2559

    Last Modified: 16 Apr 2026

    Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2560

    Last Modified: 16 Apr 2026

    Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2561

    Last Modified: 16 Apr 2026

    Edimax BR-6104K router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter (possibly within NewInternalClient), which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.

    Published: 24 May 2006
    7.5
    High

    CVE-2006-2562

    Last Modified: 16 Apr 2026

    ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.

    Published: 24 May 2006
    5
    Medium

    CVE-2006-2555

    Last Modified: 16 Apr 2026

    The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (colon) separator, which triggers a null dereference.

    Published: 24 May 2006
    4
    Medium

    CVE-2006-1466

    Last Modified: 16 Apr 2026

    Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

    Published: 24 May 2006
    5.8
    Medium

    CVE-2006-2556

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 24 May 2006
    6.4
    Medium

    CVE-2006-2557

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.

    Published: 24 May 2006
    5
    Medium

    CVE-2006-2552

    Last Modified: 16 Apr 2026

    Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in functions.php.

    Published: 24 May 2006
    2.1
    Low

    CVE-2006-2551

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the kernel in HP-UX B.11.00 allows local users to cause an unspecified denial of service via unknown vectors.

    Published: 23 May 2006
    2.6
    Low

    CVE-2006-2545

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and (2) unspecified inputs in lostid.php, probably the searchthis parameter. NOTE: one or more of these vectors might be resultant from SQL injection.

    Published: 23 May 2006
    5.1
    Medium

    CVE-2006-2550

    Last Modified: 16 Apr 2026

    perlpodder before 0.5 allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548.

    Published: 23 May 2006
    5
    Medium

    CVE-2006-2540

    Last Modified: 16 Apr 2026

    Privacy leak in install.php for Diesel PHP Job Site sends sensitive information such as user credentials to an e-mail address controlled by the product developers.

    Published: 23 May 2006
    10
    Critical

    CVE-2006-2547

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the sapdba command in SAP with Informix before 700, and 700 up to patch 100, allows local users to execute arbitrary commands via unknown vectors related to "insecure environment variable" handling.

    Published: 23 May 2006
    2.1
    Low

    CVE-2006-2542

    Last Modified: 16 Apr 2026

    xmcdconfig in xmcd for Debian GNU/Linux 2.6-17.1 creates /var/lib/cddb and /var/lib/xmcd/discog with world writable permissions, which allows local users to cause a denial of service (disk consumption).

    Published: 23 May 2006
    5.1
    Medium

    CVE-2006-2544

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php and (2) id parameter in stats.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

    Published: 23 May 2006
    5
    Medium

    CVE-2006-2546

    Last Modified: 16 Apr 2026

    A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, which could allow attackers to gain privileges.

    Published: 23 May 2006
    7.5
    High

    CVE-2006-2548

    Last Modified: 16 Apr 2026

    Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.

    Published: 23 May 2006
    7.5
    High

    CVE-2006-2541

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands via the layid parameter to (1) login.asp and (2) main.asp.

    Published: 23 May 2006
    5.1
    Medium

    CVE-2006-2543

    Last Modified: 16 Apr 2026

    Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php.

    Published: 23 May 2006