4.3
    Medium

    CVE-2006-6824

    Last Modified: 22 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d also affect 2.24.

    Source:Lostmon
    Published:29 Dec 2006
    7.5
    High

    CVE-2006-6823

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:DeltahackingTEAM
    Published:29 Dec 2006
    3.5
    Low

    CVE-2006-6822

    Last Modified: 23 Apr 2026

    myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Source:ajann
    Published:29 Dec 2006
    3.5
    Low

    CVE-2006-6821

    Last Modified: 23 Apr 2026

    myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Source:ajann
    Published:29 Dec 2006
    3.5
    Low

    CVE-2006-6820

    Last Modified: 23 Apr 2026

    myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Source:ajann
    Published:29 Dec 2006
    6.4
    Medium

    CVE-2006-6819

    Last Modified: 23 Apr 2026

    AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.

    Source:G4N0K
    Published:29 Dec 2006
    7.5
    High

    CVE-2006-6816

    Last Modified: 2 Nov 2013

    Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel; (4) the sent parameter to (a) login.asp, (b) content.asp, and (c) members.asp in the Remote-WebSite; and (5) the sent parameter to applications/SecureLoginManager/inc_secureloginmanager.asp in the Live Demo.

    Source:Doz
    Published:29 Dec 2006
    6.3
    Medium

    CVE-2006-6814

    Last Modified: 1 Nov 2013

    Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath parameter.

    Source:KAPDA
    Published:29 Dec 2006
    7.5
    High

    CVE-2006-6813

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:29 Dec 2006
    7.5
    High

    CVE-2006-6812

    Last Modified: 21 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.

    Source:Cr@zy_King
    Published:29 Dec 2006
    6.5
    Medium

    CVE-2006-6811

    Last Modified: 23 Apr 2026

    KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a buffer overflow.

    Source:Federico L. Bossi Bonin
    Published:29 Dec 2006
    5
    Medium

    CVE-2006-6810

    Last Modified: 2 Nov 2013

    Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a denial of service (application crash) via crafted network traffic, which triggers memory corruption.

    Source:Critical Security
    Published:29 Dec 2006
    7.5
    High

    CVE-2006-6809

    Last Modified: 21 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir] parameter.

    Source:DeltahackingTEAM
    Published:29 Dec 2006
    6.8
    Medium

    CVE-2006-6808

    Last Modified: 1 Nov 2013

    Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.

    Source:David Kierznowski
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6807

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.

    Source:ajann
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6806

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6805

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6804

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6803

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.

    Source:ajann
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6802

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.

    Source:ajann
    Published:28 Dec 2006
    6.8
    Medium

    CVE-2006-6801

    Last Modified: 8 Dec 2016

    PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the news_cfg[path] parameter.

    Source:bd0rk
    Published:28 Dec 2006
    6.8
    Medium

    CVE-2006-6800

    Last Modified: 23 Apr 2026

    PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.

    Source:Mehmet Ince
    Published:28 Dec 2006
    6.6
    Medium

    CVE-2006-6797

    Last Modified: 20 Sept 2016

    The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnerability than CVE-2006-6696.

    Source:Ruben Santamarta
    Published:28 Dec 2006
    6.8
    Medium

    CVE-2006-6796

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ins_file parameter.

    Source:nuffsaid
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6795

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.

    Source:Mehmet Ince
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6794

    Last Modified: 1 Nov 2013

    SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the grup parameter.

    Source:ShaFuq31
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6793

    Last Modified: 20 Sept 2016

    PHP remote file inclusion vulnerability in ataturk.php in Okul Merkezi Portal 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:ShaFuck31
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6792

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ajann
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6791

    Last Modified: 1 Nov 2013

    SQL injection vulnerability in SelGruFra.asp in chatwm 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) txtUse and (2) txtPas parameters.

    Source:ShaFuq31
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6790

    Last Modified: 20 Sept 2016

    Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php.

    Source:nuffsaid
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6789

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6788

    Last Modified: 1 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in LuckyBot 3 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) run.php or (2) ircbot.class.php.

    Source:Red_Casper
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6787

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:28 Dec 2006
    6.5
    Medium

    CVE-2006-6786

    Last Modified: 23 Apr 2026

    Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.

    Source:BlackHawk
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6785

    Last Modified: 23 Apr 2026

    The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

    Source:BlackHawk
    Published:28 Dec 2006
    5
    Medium

    CVE-2006-6781

    Last Modified: 23 Apr 2026

    HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[lastName][] parameters, which reveals the path in an error message.

    Source:Michael Brooks
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6780

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary SQL commands via the killLimit parameter.

    Source:Michael Brooks
    Published:28 Dec 2006
    6.8
    Medium

    CVE-2006-6779

    Last Modified: 1 Nov 2013

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.

    Source:Ashraf Morad
    Published:28 Dec 2006
    6.8
    Medium

    CVE-2006-6778

    Last Modified: 1 Nov 2013

    Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.

    Source:CorryL
    Published:28 Dec 2006
    6.8
    Medium

    CVE-2006-6777

    Last Modified: 1 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action.

    Source:Linux_Drox
    Published:28 Dec 2006
    7.5
    High

    CVE-2006-6776

    Last Modified: 1 Nov 2013

    Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm.

    Source:Linux_Drox
    Published:28 Dec 2006
    3.5
    Low

    CVE-2006-6775

    Last Modified: 27 Apr 2011

    acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.

    Source:gbr
    Published:27 Dec 2006
    6.8
    Medium

    CVE-2006-6774

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Content Federator 1.0 allows remote attackers to execute arbitrary PHP code via the path parameter. NOTE: some of these details are obtained from third party information.

    Source:DeltahackingTEAM
    Published:27 Dec 2006
    7.5
    High

    CVE-2006-6773

    Last Modified: 20 Sept 2016

    pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1.

    Source:James Gray
    Published:27 Dec 2006
    6.8
    Medium

    CVE-2006-6771

    Last Modified: 27 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[PTH][func] parameter in (a) scripts/gallery.scr.php; the (2) GLOBALS[PTH][spaw] parameter in (b) scripts/xtextarea.scr.php; and the (3) GLOBALS[PTH][classes] parameter in (c) sitemap.scr.php, (d) news.scr.php, (e) polls.scr.php, (f) rss.scr.php, (g) search.scr.php in scripts/, and (h) form.fun.php, (i) general.func.php, (j) groups.func.php, (k) js.func.php, (l) sections.func.php, and (m) users.func.php in functions/.

    Source:nuffsaid
    Published:27 Dec 2006
    6.8
    Medium

    CVE-2006-6770

    Last Modified: 21 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.

    Source:nuffsaid
    Published:27 Dec 2006
    6.8
    Medium

    CVE-2006-6768

    Last Modified: 23 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) main parameter.

    Source:laurent gaffie
    Published:27 Dec 2006
    7.5
    High

    CVE-2006-6767

    Last Modified: 6 Nov 2013

    oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure.

    Source:anonymous
    Published:16 Jan 2007
    6.8
    Medium

    CVE-2006-6765

    Last Modified: 21 Sept 2016

    Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execute arbitrary PHP code via (1) a local filename or FTP/share URI in the config_file parameter or (2) a URL in the ptconf[src] parameter.

    Source:g00ns
    Published:27 Dec 2006
    6.8
    Medium

    CVE-2006-6764

    Last Modified: 24 Nov 2016

    PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.

    Source:mdx
    Published:27 Dec 2006