CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-0459

    Last Modified: 16 Apr 2026

    flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.

    Published: 29 Mar 2006
    7.5
    High

    CVE-2006-1491

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.

    Published: 29 Mar 2006
    5
    Medium

    CVE-2006-1492

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter.

    Published: 29 Mar 2006
    4.3
    Medium

    CVE-2006-1493

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter. NOTE: it is possible that this issue is resultant from CVE-2006-1492.

    Published: 29 Mar 2006
    7.5
    High

    CVE-2006-1489

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters.

    Published: 29 Mar 2006
    4.3
    Medium

    CVE-2006-1487

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.

    Published: 29 Mar 2006
    4.3
    Medium

    CVE-2006-1486

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.

    Published: 29 Mar 2006
    5
    Medium

    CVE-2006-1488

    Last Modified: 16 Apr 2026

    ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message.

    Published: 29 Mar 2006
    7.5
    High

    CVE-2006-1477

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.

    Published: 29 Mar 2006
    7.5
    High

    CVE-2006-1478

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php.

    Published: 29 Mar 2006
    4.3
    Medium

    CVE-2006-1479

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php.

    Published: 29 Mar 2006
    5.1
    Medium

    CVE-2006-1480

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.

    Published: 29 Mar 2006
    4.3
    Medium

    CVE-2006-1482

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 29 Mar 2006
    6.5
    Medium

    CVE-2006-1485

    Last Modified: 16 Apr 2026

    gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Mar 2006
    4.3
    Medium

    CVE-2006-1474

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the "failed" functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter.

    Published: 29 Mar 2006
    2.1
    Low

    CVE-2006-1475

    Last Modified: 16 Apr 2026

    Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.

    Published: 29 Mar 2006
    2.6
    Low

    CVE-2006-1476

    Last Modified: 16 Apr 2026

    Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program.

    Published: 29 Mar 2006
    7.2
    High

    CVE-2006-1484

    Last Modified: 16 Apr 2026

    Genius VideoCAM NB Driver does not drop privileges when saving files, which allows local users to gain privileges by opening arbitrary files via the "save as" dialog.

    Published: 29 Mar 2006
    6.5
    Medium

    CVE-2006-1481

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.

    Published: 29 Mar 2006
    5
    Medium

    CVE-2006-1483

    Last Modified: 16 Apr 2026

    Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.

    Published: 29 Mar 2006
    7.6
    High

    CVE-2006-1550

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.

    Published: 29 Mar 2006
    4.9
    Medium

    CVE-2006-2276

    Last Modified: 16 Apr 2026

    bgpd in Quagga 0.98 and 0.99 before 20060504 allows local users to cause a denial of service (CPU consumption) via a certain sh ip bgp command entered in the telnet interface.

    Published: 29 Mar 2006
    6.5
    Medium

    CVE-2006-4227

    Last Modified: 16 Apr 2026

    MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.

    Published: 29 Mar 2006
    5
    Medium

    CVE-2006-1432

    Last Modified: 16 Apr 2026

    fusionZONE couponZONE 4.2 allows remote attackers to obtain the full path of the web server, and other sensitive information, via invalid values, as demonstrated using manipulations associated with SQL.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1431

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1430

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1423

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1427

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter in cgi-bin/index.cgi, or (10) vsSD parameter in /mods/calendar/index.cgi.

    Published: 28 Mar 2006
    7.5
    High

    CVE-2006-1426

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1422

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter.

    Published: 28 Mar 2006
    2.6
    Low

    CVE-2006-1418

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1416

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1415

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1414

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1413

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1425

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1420

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1428

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1429

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.

    Published: 28 Mar 2006
    Unknown

    CVE-2006-1424

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-1482. Reason: This candidate is a duplicate of CVE-2006-1482. Notes: All CVE users should reference CVE-2006-1482 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1417

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp.

    Published: 28 Mar 2006
    5.1
    Medium

    CVE-2006-1421

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1419

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.

    Published: 28 Mar 2006
    5.8
    Medium

    CVE-2006-1404

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file or (2) function parameter.

    Published: 28 Mar 2006
    7.8
    High

    CVE-2006-1403

    Last Modified: 16 Apr 2026

    Format string vulnerability in the PrintString function in c_console.cpp in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via format string specifiers in strings passed to the console.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1401

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1399

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1406

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword parameters.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1408

    Last Modified: 16 Apr 2026

    Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket.

    Published: 28 Mar 2006
    5.8
    Medium

    CVE-2006-1407

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.

    Published: 28 Mar 2006