CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-1110

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message.

    Published: 9 Mar 2006
    7.5
    High

    CVE-2006-1094

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.

    Published: 9 Mar 2006
    4.3
    Medium

    CVE-2006-1097

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.

    Published: 9 Mar 2006
    5
    Medium

    CVE-2006-1101

    Last Modified: 16 Apr 2026

    The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrated using SV_EXT tag data in the Cube engine, which is not properly handled by getint.

    Published: 9 Mar 2006
    5
    Medium

    CVE-2006-1105

    Last Modified: 16 Apr 2026

    Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.

    Published: 9 Mar 2006
    5
    Medium

    CVE-2006-0049

    Last Modified: 16 Apr 2026

    gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.

    Published: 9 Mar 2006
    5
    Medium

    CVE-2006-1074

    Last Modified: 16 Apr 2026

    Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.

    Published: 9 Mar 2006
    4.3
    Medium

    CVE-2006-1080

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.

    Published: 9 Mar 2006
    7.5
    High

    CVE-2006-1081

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Published: 9 Mar 2006
    10
    Critical

    CVE-2006-1085

    Last Modified: 16 Apr 2026

    admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.

    Published: 9 Mar 2006
    6.5
    Medium

    CVE-2006-1087

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability.

    Published: 9 Mar 2006
    5
    Medium

    CVE-2006-1088

    Last Modified: 16 Apr 2026

    PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.

    Published: 9 Mar 2006
    Unknown

    CVE-2006-1086

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-1083. Reason: This candidate is a duplicate of CVE-2006-1083. Notes: All CVE users should reference CVE-2006-1083 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Mar 2006
    7.5
    High

    CVE-2006-1076

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.

    Published: 9 Mar 2006
    4.3
    Medium

    CVE-2006-1082

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4) cell_title_background_color and (5) browse_cat_name parameters in browse.php, the (6) gamefile parameter in displaygame.php, and (7) possibly other parameters in unspecified PHP scripts.

    Published: 9 Mar 2006
    5
    Medium

    CVE-2006-1329

    Last Modified: 16 Apr 2026

    The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".

    Published: 9 Mar 2006
    4.9
    Medium

    CVE-2006-0744

    Last Modified: 16 Apr 2026

    Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.

    Published: 9 Mar 2006
    4.3
    Medium

    CVE-2006-1077

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters.

    Published: 9 Mar 2006
    8.4
    High

    CVE-2006-1078

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.

    Published: 9 Mar 2006
    7.2
    High

    CVE-2006-1079

    Last Modified: 16 Apr 2026

    htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.

    Published: 9 Mar 2006
    7.5
    High

    CVE-2006-1083

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other parameters, to (a) admin.php and (b) other unspecified scripts. NOTE: the admin.php/option[language] vector can be used by remote unauthenticated attackers to include arbitrary files in conjunction with CVE-2006-1085.

    Published: 9 Mar 2006
    7.5
    High

    CVE-2006-1084

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to click.php.

    Published: 9 Mar 2006
    7.5
    High

    CVE-2006-1075

    Last Modified: 16 Apr 2026

    Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in a level (aka .lxl) file.

    Published: 9 Mar 2006
    4.3
    Medium

    CVE-2006-1071

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 8 Mar 2006
    6.4
    Medium

    CVE-2006-1073

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.

    Published: 8 Mar 2006
    4.3
    Medium

    CVE-2006-1070

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.

    Published: 8 Mar 2006
    4.3
    Medium

    CVE-2006-1072

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.

    Published: 8 Mar 2006
    10
    Critical

    CVE-2006-1069

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1065

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.

    Published: 7 Mar 2006
    4.9
    Medium

    CVE-2006-1068

    Last Modified: 16 Apr 2026

    Netgear 614 and 624 routers, possibly running VXWorks, allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1067

    Last Modified: 16 Apr 2026

    Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1062

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.

    Published: 7 Mar 2006
    2.6
    Low

    CVE-2006-1064

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1051

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1063

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox".

    Published: 7 Mar 2006
    2.1
    Low

    CVE-2006-1050

    Last Modified: 16 Apr 2026

    Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the vendor has disputed this vulnerability, stating that "The kwikpay.mdb file supplied with kwikpay is a template for the database structure of user databases created by kwikpay and to store a demonstration payroll. It does not contain any sensitive user information. When a user payroll database is opened, the encryption of the database is checked and if the database is not encrypted, the user is prompted to encrypt the database, but the choice is the customers.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-0047

    Last Modified: 16 Apr 2026

    packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1031

    Last Modified: 16 Apr 2026

    config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1032

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1036

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to "permissions."

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1037

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1044

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1046

    Last Modified: 16 Apr 2026

    server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.

    Published: 7 Mar 2006
    10
    Critical

    CVE-2006-1047

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1048

    Last Modified: 16 Apr 2026

    Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3) Newsfeeds, (4) Weblinks, (5) Content, (6) Content Section, (7) Content Category, (8) Contact items, or (9) Contact Search, (10) Content Search, (11) Newsfeed Search, or (12) Weblink Search.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1033

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1034

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1035

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.

    Published: 7 Mar 2006
    6.4
    Medium

    CVE-2006-1039

    Last Modified: 16 Apr 2026

    SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.

    Published: 7 Mar 2006
    6.4
    Medium

    CVE-2006-1042

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Gregarius 0.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) folder parameter to feed.php or (2) rss_query parameter to search.php.

    Published: 7 Mar 2006