CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-1846

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML and web script via the ublock parameter, which is saved in the user's personal menu. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, it is unclear whether this issue is a vulnerability, since it is related to the user's personal menu, which presumably is not modifiable by others.

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1847

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to execute arbitrary SQL commands via the user_id parameter in the Your_Home functionality. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1848

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, and (3) date parameter.

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1849

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.

    Published: 19 Apr 2006
    Unknown

    CVE-2006-1845

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-0537. Reason: This candidate is a duplicate of CVE-2006-0537. Notes: All CVE users should reference CVE-2006-0537 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Apr 2006
    6.5
    Medium

    CVE-2006-1853

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.

    Published: 19 Apr 2006
    3.7
    Low

    CVE-2006-1057

    Last Modified: 16 Apr 2026

    Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.

    Published: 19 Apr 2006
    2.1
    Low

    CVE-2006-1056

    Last Modified: 16 Apr 2026

    The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.

    Published: 19 Apr 2006
    3.6
    Low

    CVE-2006-1753

    Last Modified: 16 Apr 2026

    A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 18 Apr 2006
    6.4
    Medium

    CVE-2006-1827

    Last Modified: 16 Apr 2026

    Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.

    Published: 18 Apr 2006
    1.9
    Low

    CVE-2006-1810

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6) Website Address, (7) Email Address, (8) Location, (9) Signature, and (10) Sub-Titles fields in the user profile.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1807

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1799

    Last Modified: 16 Apr 2026

    censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

    Published: 18 Apr 2006
    4.3
    Medium

    CVE-2006-1801

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.

    Published: 18 Apr 2006
    4.3
    Medium

    CVE-2006-1802

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.

    Published: 18 Apr 2006
    4.3
    Medium

    CVE-2006-1803

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.

    Published: 18 Apr 2006
    2.6
    Low

    CVE-2006-1806

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.

    Published: 18 Apr 2006
    6.4
    Medium

    CVE-2006-1812

    Last Modified: 16 Apr 2026

    phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

    Published: 18 Apr 2006
    6.4
    Medium

    CVE-2006-1813

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.

    Published: 18 Apr 2006
    2.1
    Low

    CVE-2006-1814

    Last Modified: 16 Apr 2026

    NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.

    Published: 18 Apr 2006
    2.6
    Low

    CVE-2006-1818

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources instead of the original disclosure.

    Published: 18 Apr 2006
    5.8
    Medium

    CVE-2006-1820

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.

    Published: 18 Apr 2006
    6.4
    Medium

    CVE-2006-1821

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.

    Published: 18 Apr 2006
    2.6
    Low

    CVE-2006-1817

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1805

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.

    Published: 18 Apr 2006
    2.6
    Low

    CVE-2006-1808

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1819

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including access_log. NOTE: in some cases, arbitrary remote file inclusion could be performed under PHP 5 using an SMB share argument such as "\\systemname\sharename".

    Published: 18 Apr 2006
    4.3
    Medium

    CVE-2006-1826

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.

    Published: 18 Apr 2006
    4.9
    Medium

    CVE-2006-1797

    Last Modified: 16 Apr 2026

    The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1798

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1800

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.

    Published: 18 Apr 2006
    5
    Medium

    CVE-2006-1809

    Last Modified: 16 Apr 2026

    index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.

    Published: 18 Apr 2006
    6.4
    Medium

    CVE-2006-1811

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9) Website Address, (10) Email Address, (11) Location, (12) Signature, and (13) Sub-Titles fields in the user profile; or (14) flexbb_password field in a cookie.

    Published: 18 Apr 2006
    2.6
    Low

    CVE-2006-1815

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2006
    5
    Medium

    CVE-2006-1816

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.

    Published: 18 Apr 2006
    5.8
    Medium

    CVE-2006-1822

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.

    Published: 18 Apr 2006
    6.4
    Medium

    CVE-2006-1823

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.

    Published: 18 Apr 2006
    1.2
    Low

    CVE-2006-1824

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.

    Published: 18 Apr 2006
    6.8
    Medium

    CVE-2006-1825

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Published: 18 Apr 2006
    7.5
    High

    CVE-2006-1804

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.

    Published: 18 Apr 2006
    6.8
    Medium

    CVE-2006-1796

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

    Published: 17 Apr 2006
    7.6
    High

    CVE-2006-1793

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.

    Published: 17 Apr 2006
    7.6
    High

    CVE-2006-1794

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).

    Published: 17 Apr 2006
    2.6
    Low

    CVE-2006-1795

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field.

    Published: 17 Apr 2006
    2.1
    Low

    CVE-2006-2071

    Last Modified: 16 Apr 2026

    Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment. NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.

    Published: 17 Apr 2006
    4.3
    Medium

    CVE-2006-1436

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm.

    Published: 15 Apr 2006
    5
    Medium

    CVE-2006-1437

    Last Modified: 16 Apr 2026

    UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.

    Published: 15 Apr 2006
    10
    Critical

    CVE-2006-1792

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a different set of affected versions, and probably a different vulnerability than CVE-2006-1337.

    Published: 15 Apr 2006
    7.5
    High

    CVE-2006-1791

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails.

    Published: 14 Apr 2006
    2.6
    Low

    CVE-2006-1725

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.

    Published: 14 Apr 2006