CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-2174

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter.

    Published: 4 May 2006
    6.4
    Medium

    CVE-2006-2175

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php.

    Published: 4 May 2006
    5.8
    Medium

    CVE-2006-2176

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter.

    Published: 4 May 2006
    4.3
    Medium

    CVE-2006-2177

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 4 May 2006
    5.8
    Medium

    CVE-2006-2178

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2 might be resultant from SQL injection.

    Published: 4 May 2006
    7.5
    High

    CVE-2006-2179

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.

    Published: 4 May 2006
    7.2
    High

    CVE-2006-2183

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in Truecrypt 4.1, when running suid root on Linux, allows local users to execute arbitrary commands and gain privileges via a modified PATH environment variable that references a malicious mount command.

    Published: 4 May 2006
    4.3
    Medium

    CVE-2006-2184

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHPKB Knowledge Base allows remote attackers to inject arbitrary web script or HTML via the searchkeyword parameter. NOTE: the issue was originally disputed by the vendor, but on 20060519, the vendor notified CVE that "We have fixed all the mentioned issues and now the search section of PHPKB script is free from any XSS issues."

    Published: 4 May 2006
    5
    Medium

    CVE-2006-2186

    Last Modified: 16 Apr 2026

    zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the path in an error message.

    Published: 4 May 2006
    6.8
    Medium

    CVE-2006-2187

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.

    Published: 4 May 2006
    6.4
    Medium

    CVE-2006-2173

    Last Modified: 16 Apr 2026

    Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code via a long (1) PORT or (2) PASS followed by the MLSD command, or (2) the remote server interface, as demonstrated by the Infigo FTPStress Fuzzer.

    Published: 4 May 2006
    4.3
    Medium

    CVE-2006-2181

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php.

    Published: 4 May 2006
    10
    Critical

    CVE-2006-2189

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: this issue can be used to trigger path disclosure. In addition, it might be primary to vector 1 in CVE-2006-1135.

    Published: 4 May 2006
    2.6
    Low

    CVE-2006-2165

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php. NOTE: this issue might be resultant from SQL injection.

    Published: 4 May 2006
    2.1
    Low

    CVE-2006-2166

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password.

    Published: 4 May 2006
    6.4
    Medium

    CVE-2006-2182

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Config_rootdir parameter.

    Published: 4 May 2006
    6.8
    Medium

    CVE-2006-2190

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter in (1) openwebmail-send.pl, (2) openwebmail-advsearch.pl, (3) openwebmail-folder.pl, (4) openwebmail-prefs.pl, (5) openwebmail-abook.pl, (6) openwebmail-read.pl, (7) openwebmail-cal.pl, and (8) openwebmail-webdisk.pl. NOTE: the openwebmail-main.pl vector is already covered by CVE-2005-2863.

    Published: 4 May 2006
    7.5
    High

    CVE-2006-2164

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.

    Published: 4 May 2006
    5
    Medium

    CVE-2006-2169

    Last Modified: 16 Apr 2026

    RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.

    Published: 4 May 2006
    7.5
    High

    CVE-2006-2172

    Last Modified: 16 Apr 2026

    Buffer overflow in Gene6 FTP Server 3.1.0 allows remote authenticated attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to (1) MKD or (2) XMKD, as demonstrated by the Infigo FTPStress Fuzzer.

    Published: 4 May 2006
    6.4
    Medium

    CVE-2006-2180

    Last Modified: 16 Apr 2026

    Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long argument to the (1) NLST or (2) APPE commands, as demonstrated by the Infigo FTPStress Fuzzer.

    Published: 4 May 2006
    6.8
    Medium

    CVE-2006-2188

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Body field of a private message (PM), (2) BBCode, or (3) a forum post.

    Published: 4 May 2006
    Unknown

    CVE-2006-2192

    Last Modified: 19 Jun 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 4 May 2006
    5
    Medium

    CVE-2006-2162

    Last Modified: 16 Apr 2026

    Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before 2.3 allows remote attackers to execute arbitrary code via a negative content length (Content-Length) HTTP header.

    Published: 3 May 2006
    7.5
    High

    CVE-2006-2152

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.

    Published: 3 May 2006
    4.3
    Medium

    CVE-2006-2153

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in HTM_PASSWD in DirectAdmin Hosting Management allows remote attackers to inject arbitrary web script or HTML via the domain parameter.

    Published: 3 May 2006
    7.2
    High

    CVE-2006-2154

    Last Modified: 16 Apr 2026

    EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the File>Open dialog.

    Published: 3 May 2006
    4.6
    Medium

    CVE-2006-2155

    Last Modified: 16 Apr 2026

    EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 allows local users to execute arbitrary code by replacing the Retrospect.exe file, possibly due to improper file permissions.

    Published: 3 May 2006
    6.4
    Medium

    CVE-2006-2156

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) sequences in the help_file parameter.

    Published: 3 May 2006
    7.5
    High

    CVE-2006-2151

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.

    Published: 3 May 2006
    6.4
    Medium

    CVE-2006-2150

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter.

    Published: 3 May 2006
    7.5
    High

    CVE-2006-2157

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to "slideshow". NOTE: This is a different vulnerability than CVE-2005-4246.

    Published: 3 May 2006
    6.4
    Medium

    CVE-2006-2158

    Last Modified: 16 Apr 2026

    Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.

    Published: 3 May 2006
    5
    Medium

    CVE-2006-2159

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.

    Published: 3 May 2006
    4.3
    Medium

    CVE-2006-2160

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp (Russcom.Loginphp) allows remote attackers to inject arbitrary web script or HTML via the username field when registering.

    Published: 3 May 2006
    6.4
    Medium

    CVE-2006-2149

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by including a GIF that contains PHP code.

    Published: 3 May 2006
    5
    Medium

    CVE-2006-2223

    Last Modified: 16 Apr 2026

    RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

    Published: 3 May 2006
    5
    Medium

    CVE-2006-2224

    Last Modified: 16 Apr 2026

    RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

    Published: 3 May 2006
    7.5
    High

    CVE-2006-2148

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in client.c in CGI:IRC (CGIIRC) before 0.5.8 might allow remote attackers to execute arbitrary code via (1) cookies or (2) the query string.

    Published: 2 May 2006
    3.6
    Low

    CVE-2006-2147

    Last Modified: 16 Apr 2026

    resmgrd in resmgr for SUSE Linux and other distributions does not properly handle when access to a USB device is granted by using "usb:<bus>,<dev>" notation, which grants access to all USB devices and allows local users to bypass intended restrictions. NOTE: this is a different vulnerability than CVE-2005-4788.

    Published: 2 May 2006
    2.1
    Low

    CVE-2006-1526

    Last Modified: 16 Apr 2026

    Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.

    Published: 2 May 2006
    5.1
    Medium

    CVE-2006-2134

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 2 May 2006
    7.5
    High

    CVE-2006-2135

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 2 May 2006
    7.5
    High

    CVE-2006-2136

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 2 May 2006
    7.5
    High

    CVE-2006-2137

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Published: 2 May 2006
    4.3
    Medium

    CVE-2006-2138

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.

    Published: 2 May 2006
    6.4
    Medium

    CVE-2006-2142

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

    Published: 2 May 2006
    4.3
    Medium

    CVE-2006-2143

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.

    Published: 2 May 2006
    6.4
    Medium

    CVE-2006-2144

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.

    Published: 2 May 2006
    6.4
    Medium

    CVE-2006-2145

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.

    Published: 2 May 2006