CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-2282

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to the avatar parameter in register.php.

    Published: 9 May 2006
    6.8
    Medium

    CVE-2006-2284

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php.

    Published: 9 May 2006
    5.1
    Medium

    CVE-2006-2285

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.

    Published: 9 May 2006
    2.1
    Low

    CVE-2006-2289

    Last Modified: 16 Apr 2026

    Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors.

    Published: 9 May 2006
    6.8
    Medium

    CVE-2006-2290

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in kommentar.php in 2005-Comments-Script allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) email, and (3) url parameter.

    Published: 9 May 2006
    5.8
    Medium

    CVE-2006-2291

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar_new.asp in IA-Calendar allows remote attackers to inject arbitrary web script or HTML via the TypeName1 parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2292

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in IA-Calendar allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in (a) calendar_new.asp and (b) default.asp, and (2) ID parameter in (c) calendar_detail.asp. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 9 May 2006
    6.8
    Medium

    CVE-2006-2294

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2296

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-0034

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-1184

    Last Modified: 16 Apr 2026

    Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2278

    Last Modified: 16 Apr 2026

    SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow parameter to (c) showcat.php; or the (3) rows parameter to index.php.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2279

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameters in (b) misc.php.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2283

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid 2.9.5 through 3.0.b3 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) auth.php and (2) auth_phpbb when the phpBB portal is enabled, and via a URL in the smf_root_path parameter in (3) auth.php and (4) auth_SMF when the SMF portal is enabled.

    Published: 9 May 2006
    6.8
    Medium

    CVE-2006-2286

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4) extAuthSource, (5) thisAuthSource, (6) main_configuration_file_path, (7) phpDigIncCn, and (8) drs parameters to (a) testheaderpage.php and (b) resourcelinker.inc.php.

    Published: 9 May 2006
    5.8
    Medium

    CVE-2006-2287

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Vision Source 0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the fields in a user's profile.

    Published: 9 May 2006
    3.6
    Low

    CVE-2006-2288

    Last Modified: 16 Apr 2026

    Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS name conflicts.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2295

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2293

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-0027

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2042

    Last Modified: 16 Apr 2026

    Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.

    Published: 9 May 2006
    5.8
    Medium

    CVE-2006-2243

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2244

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2247

    Last Modified: 16 Apr 2026

    WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2248

    Last Modified: 16 Apr 2026

    Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension.

    Published: 9 May 2006
    4.3
    Medium

    CVE-2006-2249

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2250

    Last Modified: 16 Apr 2026

    CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2251

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2252

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2253

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL in the statitpath parameter.

    Published: 9 May 2006
    5.8
    Medium

    CVE-2006-2246

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry.

    Published: 9 May 2006
    2.6
    Low

    CVE-2006-2258

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2259

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to execute arbitrary SQL commands via the txtLogon parameter.

    Published: 9 May 2006
    4.3
    Medium

    CVE-2006-2260

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2261

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 9 May 2006
    2.6
    Low

    CVE-2006-2262

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2266

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Chirpy! 0.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 9 May 2006
    4.3
    Medium

    CVE-2006-2269

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2270

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter.

    Published: 9 May 2006
    5.1
    Medium

    CVE-2006-2161

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2239

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows remote attackers to execute arbitrary SQL commands via the nid parameter.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2240

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the (1) web cache or (2) web proxy in Fujitsu NetShelter/FW allows remote attackers to cause a denial of service (device unresponsiveness) via certain DNS packets, as demonstrated by the OUSPG PROTOS DNS test suite.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2256

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the eqdkp_root_path parameter.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2268

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably involving the (1) checkuser and (2) checkpass parameters to (a) admin/index.php, and (3) username and (4) password parameters to (b) index.php. NOTE: it was later reported that 0.0.6 is also affected.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-0515

    Last Modified: 16 Apr 2026

    Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspection, aka bugs CSCsc67612, CSCsc68472, and CSCsd81734.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-1172

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature.

    Published: 9 May 2006
    6.4
    Medium

    CVE-2006-2241

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a different vulnerability than CVE-2006-2175.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2242

    Last Modified: 16 Apr 2026

    acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command.

    Published: 9 May 2006
    5.8
    Medium

    CVE-2006-2257

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 allows remote attackers to inject arbitrary web script or HTML via the curr_year parameter.

    Published: 9 May 2006
    2.6
    Low

    CVE-2006-2265

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 May 2006