CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2006-2349

    Last Modified: 16 Apr 2026

    E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, and execute arbitrary code, via a direct request to (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html, or (3) common/html_editor/html_editor.html. NOTE: this can also be used for cross-site scripting (XSS) attacks by uploading cascading style sheet (.CSS) files.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2347

    Last Modified: 16 Apr 2026

    E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL injection.

    Published: 12 May 2006
    5.8
    Medium

    CVE-2006-2340

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password, or (3) User-Agent HTTP header in the Hack Log.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2341

    Last Modified: 16 Apr 2026

    The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI.

    Published: 12 May 2006
    2.1
    Low

    CVE-2006-1859

    Last Modified: 16 Apr 2026

    Memory leak in __setlease in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (memory consumption) via unspecified actions related to an "uninitialised return value," aka "slab leak."

    Published: 12 May 2006
    2.1
    Low

    CVE-2006-1860

    Last Modified: 16 Apr 2026

    lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2339

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2337

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in webcm in the D-Link DSL-G604T Wireless ADSL Router Modem allows remote attackers to read arbitrary files via an absolute path in the getpage parameter.

    Published: 12 May 2006
    2.6
    Low

    CVE-2006-2332

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher found that the web page caused a temporary browser slowdown instead of a crash.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2330

    Last Modified: 16 Apr 2026

    PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2328

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in lib/adodb/server.php in AngelineCMS 0.6.5 and earlier might allow remote attackers to execute arbitrary SQL commands via the query string.

    Published: 12 May 2006
    9.3
    Critical

    CVE-2006-2273

    Last Modified: 16 Apr 2026

    The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable file.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2315

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled

    Published: 12 May 2006
    4.9
    Medium

    CVE-2006-2316

    Last Modified: 16 Apr 2026

    S24EvMon.exe in the Intel PROset/Wireless software, possibly 10.1.0.33, uses a S24EventManagerSharedMemory shared memory section with weak permissions, which allows local users to read or modify passwords or other data, or cause a denial of service.

    Published: 12 May 2006
    4.3
    Medium

    CVE-2006-2321

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: due to lack of details from the researcher, it is not clear whether this overlaps CVE-2004-2207.

    Published: 12 May 2006
    10
    Critical

    CVE-2006-2324

    Last Modified: 16 Apr 2026

    180solutions Zango downloads "required Adware components" without checking integrity or authenticity, which might allow context-dependent attackers to execute arbitrary code by subverting the DNS resolution of static.zangocash.com.

    Published: 12 May 2006
    6.8
    Medium

    CVE-2006-2325

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to inject arbitrary web script or HTML via the read parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Also, this issue might be resultant from directory traversal.

    Published: 12 May 2006
    6.5
    Medium

    CVE-2006-2335

    Last Modified: 16 Apr 2026

    Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. NOTE: the vendor was unable to reproduce this issue in 3.5.x. NOTE: this issue might be due to direct static code injection.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2336

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2326

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to read arbitrary files via directory traversal sequences in the read parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2331

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (dot dot) in the settings[locale] parameter in infusions/last_seen_users_panel/last_seen_users_panel.php, and (2) a .. (dot dot) in the localeset parameter in setup.php. NOTE: the vendor states that this issue might exist due to problems in third party local files.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2318

    Last Modified: 16 Apr 2026

    Incomplete blacklist vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to upload and execute an ASP script via a ".asa" file, which bypasses the check for the ".asp" extension but is executable on the server.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2319

    Last Modified: 16 Apr 2026

    Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2320

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors related to stored procedure calls. NOTE: due to lack of details from the researcher, it is not clear whether this overlaps CVE-2004-2209.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-2323

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2327

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndps_xdr_array function.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2329

    Last Modified: 16 Apr 2026

    AngelineCMS 0.6.5 and earlier allow remote attackers to obtain sensitive information via a direct request for (1) adodb-access.inc.php, (2) adodb-ado.inc.php, (3) adodb-ado_access.inc, (4) adodb-ado_mssql.inc.php, (5) adodb-borland_ibase, (6) adodb-csv.inc.php, (7) adodb-db2.inc.php, (8) adodb-fbsql.inc.php, (9) adodb-firebird.inc.php, (10) adodb-ibase.inc.php, (11) adodb-informix.inc.php, (12) adodb-informix72.inc, (13) adodb-mssql.inc.php, (14) adodb-mssqlpo.inc.php, (15) adodb-mysql.inc.php, (16) adodb-mysqlt.inc.php, (17) adodb-oci8.inc.php, (18) adodb-oci805.inc.php, (19) adodb-oci8po.inc.php, and (20) adodb-odbc.inc.php, which reveal the path in various error messages; and via a direct request for the (21) lib/system/ directory and (22) possibly other lib/ directories, which provide a directory listing and "architecture view."

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2333

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification, which is not properly handled in (1) usercp.php and (2) member.php.

    Published: 12 May 2006
    2.1
    Low

    CVE-2006-2334

    Last Modified: 16 Apr 2026

    The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2338

    Last Modified: 16 Apr 2026

    PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-2317

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to read arbitrary files under the web root via unspecified attack vectors related to the OpenTextFile method in Scripting.FileSystemObject.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2322

    Last Modified: 16 Apr 2026

    The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2300

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.

    Published: 11 May 2006
    7.5
    High

    CVE-2006-2301

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin_default.asp in OzzyWork Galeri allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password fields.

    Published: 11 May 2006
    5.8
    Medium

    CVE-2006-2305

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Jadu CMS allow remote attackers to inject arbitrary web script or HTML via the (1) forename, (2) surname, (3) reg_email, (4) email_conf, (5) company, (6) city, (7) postcode, or (8) telephone parameters to site/scripts/register.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 11 May 2006
    9.3
    Critical

    CVE-2006-2306

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 May 2006
    4.3
    Medium

    CVE-2006-2307

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Website Baker CMS before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a user display name.

    Published: 11 May 2006
    6.4
    Medium

    CVE-2006-2303

    Last Modified: 16 Apr 2026

    Cross-Application Scripting (XAS) vulnerability in ICQ Client 5.04 build 2321 and earlier allows remote attackers to inject arbitrary web script from one application into another via a banner, which is processed in the My Computer zone using the Internet Explorer COM object.

    Published: 11 May 2006
    10
    Critical

    CVE-2006-2304

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the DPRPC library (DPRPCW32.DLL) in Novell Client 4.83 SP3, 4.90 SP2 and 4.91 SP2 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndps_xdr_array function. NOTE: this was originally reported to be a buffer overflow by Novell, but the original cause is an integer overflow.

    Published: 11 May 2006
    7.5
    High

    CVE-2006-2302

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field.

    Published: 11 May 2006
    7.5
    High

    CVE-2006-0994

    Last Modified: 16 Apr 2026

    Multiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, allows remote attackers to execute arbitrary code via a CAB file with "invalid folder count values," which leads to heap corruption.

    Published: 10 May 2006
    5
    Medium

    CVE-2006-2298

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

    Published: 10 May 2006
    5
    Medium

    CVE-2006-0993

    Last Modified: 16 Apr 2026

    The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might allow remote attackers to obtain potentially sensitive information such as configuration settings.

    Published: 10 May 2006
    4
    Medium

    CVE-2006-2297

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Microsoft Infotech Storage System Library (itss.dll) allows user-assisted attackers to execute arbitrary code via a crafted CHM / ITS file that triggers the overflow while decompiling.

    Published: 10 May 2006
    6.8
    Medium

    CVE-2006-7246

    Last Modified: 21 Nov 2024

    NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

    Published: 10 May 2006
    7.5
    High

    CVE-2006-2082

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote attackers to read arbitrary files from the server via ".." sequences in a .pk3 file request.

    Published: 10 May 2006
    7.2
    High

    CVE-2006-0561

    Last Modified: 16 Apr 2026

    Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2277

    Last Modified: 16 Apr 2026

    Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2280

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template parameter.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2281

    Last Modified: 16 Apr 2026

    X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it.

    Published: 9 May 2006