CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2006-1966

    Last Modified: 16 Apr 2026

    An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup posts that suggest that a protection feature is triggering a RST.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1941

    Last Modified: 16 Apr 2026

    Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1945

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1946

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter in pblscg.cgi, and (3) the listno parameter in pblsmb.cgi.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1947

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1949

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in plexcart.pl in NicPlex PlexCart X3 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1943

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1944

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.

    Published: 20 Apr 2006
    4
    Medium

    CVE-2006-1948

    Last Modified: 16 Apr 2026

    The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.

    Published: 20 Apr 2006
    5.1
    Medium

    CVE-2006-1942

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."

    Published: 20 Apr 2006
    4.3
    Medium

    CVE-2006-1950

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1909

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1910

    Last Modified: 16 Apr 2026

    config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Apr 2006
    4.3
    Medium

    CVE-2006-1911

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1 allows remote attackers to inject arbitrary web script or HTML via the attachment content disposition in an HTML attachment.

    Published: 20 Apr 2006
    6.8
    Medium

    CVE-2006-1916

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies parameters.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1917

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1919

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1926

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1928

    Last Modified: 16 Apr 2026

    Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2) CSCsd55531.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1907

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1908

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Apr 2006
    5.8
    Medium

    CVE-2006-1912

    Last Modified: 16 Apr 2026

    MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1914

    Last Modified: 16 Apr 2026

    DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php. NOTE: this information leak might be resultant from a global variable overwrite issue.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1915

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1918

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menuid parameter to (1) index.php or (2) forum.php, or the (3) reporeid_print parameter to print.php.

    Published: 20 Apr 2006
    4.3
    Medium

    CVE-2006-1925

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1929

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Published: 20 Apr 2006
    6.4
    Medium

    CVE-2006-1930

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in userscript.php in Green Minute 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) huserid, (2) pituus, or (3) date parameters. NOTE: this issue has been disputed by the vendor, saying "those parameters mentioned ARE checked (preg_match) before they are used in SQL-query... If someone decided to add SQL-injection stuff to certain parameter, they would see an error text, but only because _nothing_ was passed inside that parameter (to MySQL-database)." As allowed by the vendor, CVE investigated this report on 20060525 and found that the demo site demonstrated a non-sensitive SQL error when given standard SQL injection manipulations

    Published: 20 Apr 2006
    6.4
    Medium

    CVE-2006-1924

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 20 Apr 2006
    6.4
    Medium

    CVE-2006-1922

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.

    Published: 20 Apr 2006
    5.8
    Medium

    CVE-2006-1923

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) RSS/RSS.php and (2) possibly other vectors.

    Published: 20 Apr 2006
    6.4
    Medium

    CVE-2006-1921

    Last Modified: 16 Apr 2026

    nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter.

    Published: 20 Apr 2006
    6.8
    Medium

    CVE-2006-1913

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 20 Apr 2006
    6.4
    Medium

    CVE-2006-1920

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in PMTool 1.2.2 allows remote attackers to execute arbitrary SQL commands via the order parameter in the include files (1) user.inc.php, (2) customer.inc.php, and (3) project.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1927

    Last Modified: 16 Apr 2026

    Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash) via certain MPLS packets, as identified by Cisco bug ID CSCsc77475.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1906

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1898

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash password" issue is already covered by CVE-2006-0103.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1890

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect 1.4 as well.

    Published: 20 Apr 2006
    7.6
    High

    CVE-2006-1900

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."

    Published: 20 Apr 2006
    4.9
    Medium

    CVE-2006-1892

    Last Modified: 16 Apr 2026

    avast! 4 Linux Home Edition 1.0.5 allows local users to modify permissions of arbitrary files via a symlink attack on the /tmp/_avast4_ temporary directory.

    Published: 20 Apr 2006
    6.8
    Medium

    CVE-2006-1888

    Last Modified: 16 Apr 2026

    phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script. NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1884

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1883

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite and Applications 11.5.10CU1 has unknown impact and attack vectors, aka Vuln# APPS05.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1882

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unknown impact and attack vectors, as identified by Vuln# (1) APPS03 in (a) iProcurement; (2) APPS04 in (b) Oracle Application Object Library; (3) APPS06, (4) APPS07, and (5) APPS08 in (c) Oracle Applications Technology Stack; and (6) APPS11 in (d) Oracle Order Capture.

    Published: 20 Apr 2006
    9
    Critical

    CVE-2006-1876

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the (1) GEN_RID_RANGE_BY_AREA and (2) GEN_RID_RANGE functions in the MDSYS.SDO_PRIDX package.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1874

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB09. NOTE: Oracle has not disputed reliable claims that this issue is SQL injection in MDSYS.PRVT_IDX using the (1) EXECUTE_INSERT, (2) EXECUTE_DELETE, (3) EXECUTE_UPDATE, (4) EXECUTE UPDATE, and (5) CRT_DUMMY functions.

    Published: 20 Apr 2006
    9
    Critical

    CVE-2006-1870

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors in the Export component, aka Vuln# DB05. NOTE: details are unavailable from Oracle, but as of 20060427, they have not publicly commented on whether DB05 is the same issue as CVE-2006-2081.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1868

    Last Modified: 16 Apr 2026

    Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1899

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) website parameters.

    Published: 20 Apr 2006
    4.3
    Medium

    CVE-2006-1891

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard 0.1 allows remote attackers to inject arbitrary web script or HTML via a user's profile, possibly using the FormVal_profile parameter. NOTE: it is not clear whether this is a distributable product or a site-specific vulnerability. If it is site-specific, then it should not be included in CVE.

    Published: 20 Apr 2006