CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-0789

    Last Modified: 16 Apr 2026

    Certain unspecified Kyocera printers have a default "admin" account with a blank password, which allows remote attackers to access an administrative menu via a telnet session.

    Published: 19 Feb 2006
    7.5
    High

    CVE-2006-0772

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitrary SQL commands via unspecified vectors in the extended receiving box function.

    Published: 19 Feb 2006
    7.5
    High

    CVE-2006-0775

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable. NOTE: a vector regarding the $date parameter and data.php (date.php) was originally reported, but this appears to be in error.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0776

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 19 Feb 2006
    7.5
    High

    CVE-2006-0777

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to execute arbitrary shell commands via the email parameter, possibly involving shell metacharacters.

    Published: 19 Feb 2006
    7.5
    High

    CVE-2006-0778

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in XMB Forums 1.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) $u2u_select array parameter to u2u.inc.php and (2) $val variable (fidpw0 cookie value) in today.php.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0779

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.

    Published: 19 Feb 2006
    7.5
    High

    CVE-2006-0774

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.

    Published: 19 Feb 2006
    4.3
    Medium

    CVE-2006-0773

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the extended receiving box function.

    Published: 19 Feb 2006
    5
    Medium

    CVE-2006-0768

    Last Modified: 16 Apr 2026

    Kadu 0.4.3 allows remote attackers to cause a denial of service (application crash) via a large number of image send requests.

    Published: 18 Feb 2006
    7.2
    High

    CVE-2006-0769

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.

    Published: 18 Feb 2006
    2.6
    Low

    CVE-2006-0770

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in "advanced details". NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Feb 2006
    6.4
    Medium

    CVE-2006-0771

    Last Modified: 16 Apr 2026

    Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the server kicks the player and records the reason.

    Published: 18 Feb 2006
    5
    Medium

    CVE-2006-0767

    Last Modified: 16 Apr 2026

    CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information.

    Published: 18 Feb 2006
    5
    Medium

    CVE-2006-0042

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers to cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.

    Published: 18 Feb 2006
    10
    Critical

    CVE-2006-0751

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors.

    Published: 18 Feb 2006
    5
    Medium

    CVE-2006-0756

    Last Modified: 16 Apr 2026

    dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php

    Published: 18 Feb 2006
    4.3
    Medium

    CVE-2006-0758

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the $_SERVER['PHP_SELF'] variable.

    Published: 18 Feb 2006
    4.6
    Medium

    CVE-2006-0762

    Last Modified: 16 Apr 2026

    WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement.

    Published: 18 Feb 2006
    4.3
    Medium

    CVE-2006-0763

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.

    Published: 18 Feb 2006
    5.1
    Medium

    CVE-2006-0764

    Last Modified: 16 Apr 2026

    The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455.

    Published: 18 Feb 2006
    7.5
    High

    CVE-2006-0757

    Last Modified: 16 Apr 2026

    Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators.

    Published: 18 Feb 2006
    5.1
    Medium

    CVE-2006-0766

    Last Modified: 16 Apr 2026

    ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.

    Published: 18 Feb 2006
    7.5
    High

    CVE-2006-0750

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.

    Published: 18 Feb 2006
    2.6
    Low

    CVE-2006-0753

    Last Modified: 16 Apr 2026

    Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.

    Published: 18 Feb 2006
    5
    Medium

    CVE-2006-0754

    Last Modified: 16 Apr 2026

    dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php

    Published: 18 Feb 2006
    5.6
    Medium

    CVE-2006-0755

    Last Modified: 16 Apr 2026

    Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product

    Published: 18 Feb 2006
    7.5
    High

    CVE-2006-0759

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts, because $_SERVER['PHP_SELF'] is improperly handled.

    Published: 18 Feb 2006
    2.6
    Low

    CVE-2006-0760

    Last Modified: 16 Apr 2026

    LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.

    Published: 18 Feb 2006
    5.1
    Medium

    CVE-2006-0761

    Last Modified: 16 Apr 2026

    Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.

    Published: 18 Feb 2006
    5.1
    Medium

    CVE-2006-0765

    Last Modified: 16 Apr 2026

    GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs.

    Published: 18 Feb 2006
    5
    Medium

    CVE-2006-0752

    Last Modified: 16 Apr 2026

    Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd.

    Published: 18 Feb 2006
    7.5
    High

    CVE-2006-0460

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.

    Published: 17 Feb 2006
    5
    Medium

    CVE-2006-0738

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address).

    Published: 17 Feb 2006
    5
    Medium

    CVE-2006-0739

    Last Modified: 16 Apr 2026

    eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.

    Published: 17 Feb 2006
    5
    Medium

    CVE-2006-0737

    Last Modified: 16 Apr 2026

    eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.

    Published: 17 Feb 2006
    4.9
    Medium

    CVE-2006-0557

    Last Modified: 16 Apr 2026

    sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.

    Published: 17 Feb 2006
    7.5
    High

    CVE-2006-0679

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).

    Published: 16 Feb 2006
    7.5
    High

    CVE-2006-0721

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.

    Published: 16 Feb 2006
    6.8
    Medium

    CVE-2006-0725

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-2645.

    Published: 16 Feb 2006
    4.3
    Medium

    CVE-2006-0726

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.

    Published: 16 Feb 2006
    7.5
    High

    CVE-2006-0727

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query data, probably involving the profile name.

    Published: 16 Feb 2006
    7.5
    High

    CVE-2006-0728

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.

    Published: 16 Feb 2006
    7.5
    High

    CVE-2006-0729

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.

    Published: 16 Feb 2006
    4
    Medium

    CVE-2006-0731

    Last Modified: 16 Apr 2026

    WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.

    Published: 16 Feb 2006
    2.6
    Low

    CVE-2006-0722

    Last Modified: 16 Apr 2026

    settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.

    Published: 16 Feb 2006
    2.6
    Low

    CVE-2006-0723

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.

    Published: 16 Feb 2006
    2.6
    Low

    CVE-2006-0724

    Last Modified: 16 Apr 2026

    profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.

    Published: 16 Feb 2006
    6.4
    Medium

    CVE-2006-0732

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the grace period has ended. NOTE: SAP Business Connector is an OEM version of webMethods Integration Server. webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port; however, both are discouraged in the documentation. In addition, the attacker must already have acquired administrative privileges through other means.

    Published: 16 Feb 2006
    2.6
    Low

    CVE-2006-0733

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability

    Published: 16 Feb 2006