CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2006-0837

    Last Modified: 16 Apr 2026

    IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf, (2) /opt/NeuSecure/etc/cms-3.0.236.buildconf, and (3) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to read sensitive information such as passwords. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.

    Published: 22 Feb 2006
    4.3
    Medium

    CVE-2006-0841

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php. NOTE: item 17 might be subsumed by CVE-2005-4522.

    Published: 22 Feb 2006
    4.3
    Medium

    CVE-2006-0842

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element in an e-mail message, as demonstrated by "java	script:." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Feb 2006
    5
    Medium

    CVE-2006-0847

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.

    Published: 22 Feb 2006
    5
    Medium

    CVE-2006-0839

    Last Modified: 16 Apr 2026

    The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.

    Published: 22 Feb 2006
    7.5
    High

    CVE-2006-0832

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameter.

    Published: 22 Feb 2006
    4.3
    Medium

    CVE-2006-0833

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

    Published: 22 Feb 2006
    3.6
    Low

    CVE-2006-4226

    Last Modified: 16 Apr 2026

    MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.

    Published: 22 Feb 2006
    7.5
    High

    CVE-2006-0821

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Published: 21 Feb 2006
    5
    Medium

    CVE-2006-0822

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in EmuLinker Kaillera Server before 0.99.17 allows remote attackers to cause a denial of service (probably resource consumption) via a crafted packet that causes a "ghost game" to be left on the server.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0823

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.

    Published: 21 Feb 2006
    5
    Medium

    CVE-2006-0827

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 21 Feb 2006
    5
    Medium

    CVE-2006-0828

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to "reduce effectiveness of security features" via unknown attack vectors.

    Published: 21 Feb 2006
    5
    Medium

    CVE-2006-0829

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using "Click Log".

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0825

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain "unauthorized network access" via unknown attack vectors.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0830

    Last Modified: 16 Apr 2026

    The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop.

    Published: 21 Feb 2006
    5
    Medium

    CVE-2006-0826

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to cause a denial of service via a crafted Postscript request.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0824

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0831

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in index.php in Tasarim Rehberi allows remote attackers to execute arbitrary PHP code via a URL in the (1) sayfaadi or (2) sayfa parameter. NOTE: this might be a site-specific issue. If so, it should not be included in CVE.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0805

    Last Modified: 16 Apr 2026

    The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters.

    Published: 21 Feb 2006
    4.3
    Medium

    CVE-2006-0806

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.

    Published: 21 Feb 2006
    5.1
    Medium

    CVE-2006-0807

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents.

    Published: 21 Feb 2006
    6.4
    Medium

    CVE-2006-0808

    Last Modified: 16 Apr 2026

    MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" nodes.

    Published: 21 Feb 2006
    3.5
    Low

    CVE-2006-0810

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.

    Published: 21 Feb 2006
    4.3
    Medium

    CVE-2006-0811

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0809

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php.

    Published: 21 Feb 2006
    7.5
    High

    CVE-2006-0804

    Last Modified: 16 Apr 2026

    Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow.

    Published: 21 Feb 2006
    2.6
    Low

    CVE-2006-0800

    Last Modified: 16 Apr 2026

    Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.

    Published: 20 Feb 2006
    2.6
    Low

    CVE-2006-0802

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation operation.

    Published: 20 Feb 2006
    5.1
    Medium

    CVE-2006-0801

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.

    Published: 20 Feb 2006
    4.6
    Medium

    CVE-2006-0903

    Last Modified: 16 Apr 2026

    MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.

    Published: 20 Feb 2006
    7.5
    High

    CVE-2006-0791

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use.

    Published: 19 Feb 2006
    4
    Medium

    CVE-2006-0799

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL. NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0794

    Last Modified: 16 Apr 2026

    help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0790

    Last Modified: 16 Apr 2026

    Rockliffe MailSite 7.0 and earlier allows remote attackers to cause a denial of service by sending crafted LDAP packets to port 389/TCP, as demonstrated by the ProtoVer LDAP testsuite.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0795

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables.

    Published: 19 Feb 2006
    7.8
    High

    CVE-2006-0797

    Last Modified: 16 Apr 2026

    Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).

    Published: 19 Feb 2006
    5.5
    Medium

    CVE-2006-0798

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0792

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0793

    Last Modified: 16 Apr 2026

    frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0796

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0780

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0781

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.

    Published: 19 Feb 2006
    5.1
    Medium

    CVE-2006-0786

    Last Modified: 16 Apr 2026

    Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for "http://", "ftp://", and "https://" URLs.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0788

    Last Modified: 16 Apr 2026

    Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with "!R!SIOP0", as demonstrated using (1) a connection to to TCP port 9100 or (2) the UNIX lp command.

    Published: 19 Feb 2006
    7.5
    High

    CVE-2006-0782

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0783

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).

    Published: 19 Feb 2006
    6.4
    Medium

    CVE-2006-0785

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions.

    Published: 19 Feb 2006
    4
    Medium

    CVE-2006-0787

    Last Modified: 16 Apr 2026

    wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability. NOTE: since this issue, as described by the original researcher, is entirely dependent on the presence of another vulnerability, it could be argued that Wimpy cannot be responsible for how its data file is processed by applications outside of its control. Since this issue might only be useful as a facilitator manipulation in another vulnerability, perhaps it should not be included in CVE.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0784

    Last Modified: 16 Apr 2026

    D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

    Published: 19 Feb 2006