7.5
    High

    CVE-2006-6763

    Last Modified: 24 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_to_themes parameter in (a) authenticate.php, and the (2) default_path_for_themes parameter in (b) admin.php and (c) upconfig.php.

    Source:mdx
    Published:27 Dec 2006
    6.5
    Medium

    CVE-2006-6761

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.

    Source:Metasploit
    Published:27 Dec 2006
    7.5
    High

    CVE-2006-6760

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) actionsPage or (2) formPage parameter.

    Source:nuffsaid
    Published:27 Dec 2006
    5
    Medium

    CVE-2006-6759

    Last Modified: 26 Sept 2016

    A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer crash) by invoking the RealPlayer.Initialize method with certain arguments.

    Source:shinnai
    Published:27 Dec 2006
    5
    Medium

    CVE-2006-6758

    Last Modified: 21 Sept 2016

    Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the URI.

    Source:str0ke
    Published:27 Dec 2006
    7.8
    High

    CVE-2006-6757

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter.

    Source:ajann
    Published:27 Dec 2006
    5.1
    Medium

    CVE-2006-6756

    Last Modified: 21 Sept 2016

    The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote attackers to gain access to the administration panel via a brute force attack.

    Source:DarkFig
    Published:27 Dec 2006
    5
    Medium

    CVE-2006-6755

    Last Modified: 21 Sept 2016

    Ixprim 1.2 allows remote attackers to obtain sensitive information via a direct request for kernel/plugins/fckeditor2/ixprim_api.php, which reveals the path in an error message.

    Source:DarkFig
    Published:27 Dec 2006
    7.5
    High

    CVE-2006-6752

    Last Modified: 30 Oct 2013

    Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. Also, it is not clear whether this issue crosses security boundaries.

    Source:Umesh Wanve
    Published:27 Dec 2006
    5
    Medium

    CVE-2006-6751

    Last Modified: 20 Sept 2016

    Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain other available or nonexistent commands. NOTE: It was later reported that 5.3.0 is also vulnerable.

    Source:shinnai
    Published:27 Dec 2006
    5
    Medium

    CVE-2006-6750

    Last Modified: 23 Apr 2026

    Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a long PORT command. NOTE: this issue might be related to CVE-2006-2226.

    Source:Jerome Athias
    Published:27 Dec 2006
    7.5
    High

    CVE-2006-6747

    Last Modified: 30 Oct 2013

    SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.

    Source:Mr_KaLiMaN
    Published:27 Dec 2006
    4.3
    Medium

    CVE-2006-6746

    Last Modified: 30 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.

    Source:Mr_KaLiMaN
    Published:27 Dec 2006
    5.8
    Medium

    CVE-2006-6741

    Last Modified: 20 Sept 2016

    Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag.

    Source:Demential
    Published:26 Dec 2006
    7.5
    High

    CVE-2006-6740

    Last Modified: 21 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5) admin_newcomm.inc.php, (6) header_admin.inc.php, (7) header.inc.php, (8) friends.inc.php, (9) menu_u.inc.php, (10) notify.inc.php, (11) body.inc.php, (12) body_admin.inc.php, (13) commrecc.inc.php, (14) do_reg.inc.php, (15) comm_post.inc.php, or (16) menu_v.inc.php in include/, different vectors than CVE-2006-5634. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:nuffsaid
    Published:26 Dec 2006
    7.5
    High

    CVE-2006-6739

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DOCUMENT_ROOT parameter, a different vector than CVE-2006-6689.

    Source:nuffsaid
    Published:26 Dec 2006
    6.8
    Medium

    CVE-2006-6738

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:bd0rk
    Published:26 Dec 2006
    4.3
    Medium

    CVE-2006-6734

    Last Modified: 30 Oct 2013

    Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script or HTML via the catname parameter.

    Source:Linux_Drox
    Published:26 Dec 2006
    4.3
    Medium

    CVE-2006-6733

    Last Modified: 30 Oct 2013

    Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.

    Source:Hacker CooL
    Published:26 Dec 2006
    6.8
    Medium

    CVE-2006-6732

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs parameter.

    Source:bd0rk
    Published:26 Dec 2006
    4.3
    Medium

    CVE-2006-6729

    Last Modified: 15 Nov 2017

    Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Fukumori
    Published:26 Dec 2006
    7.5
    High

    CVE-2006-6726

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.

    Source:bd0rk
    Published:26 Dec 2006
    4
    Medium

    CVE-2006-6724

    Last Modified: 7 Nov 2016

    BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of service (application crash) via a certain invalid PORT command.

    Source:InTeL
    Published:26 Dec 2006
    7.8
    High

    CVE-2006-6723

    Last Modified: 23 Apr 2026

    The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.

    Source:h07
    Published:26 Dec 2006
    7.5
    High

    CVE-2006-6722

    Last Modified: 23 Apr 2026

    Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1.

    Source:H0tTurk-
    Published:23 Dec 2006
    6.8
    Medium

    CVE-2006-6721

    Last Modified: 30 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.

    Source:IMHOT3B
    Published:23 Dec 2006
    7.5
    High

    CVE-2006-6720

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in admin/index_sitios.php in Azucar CMS 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _VIEW parameter.

    Source:nuffsaid
    Published:23 Dec 2006
    5
    Medium

    CVE-2006-6719

    Last Modified: 21 Sept 2016

    The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.

    Source:Federico L. Bossi Bonin
    Published:18 Dec 2006
    7.5
    High

    CVE-2006-6716

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter.

    Source:the master
    Published:23 Dec 2006
    5.1
    Medium

    CVE-2006-6715

    Last Modified: 11 Jan 2017

    PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter.

    Source:nuffsaid
    Published:23 Dec 2006
    7.5
    High

    CVE-2006-6711

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Source:3l3ctric-Cracker
    Published:23 Dec 2006
    7.5
    High

    CVE-2006-6710

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b) common.inc.php, and the CFG[localelangdir] parameter to (c) form_header.php.

    Source:nuffsaid
    Published:23 Dec 2006
    7.5
    High

    CVE-2006-6709

    Last Modified: 18 Oct 2013

    Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.

    Source:laurent gaffie
    Published:23 Dec 2006
    6.8
    Medium

    CVE-2006-6708

    Last Modified: 18 Oct 2013

    Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Source:laurent gaffie
    Published:23 Dec 2006
    7.5
    High

    CVE-2006-6707

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Metasploit
    Published:23 Dec 2006
    6.8
    Medium

    CVE-2006-6703

    Last Modified: 30 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.

    Source:putosoft softputo
    Published:23 Dec 2006
    7.5
    High

    CVE-2006-6697

    Last Modified: 30 Oct 2013

    CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.

    Source:putosoft softputo
    Published:22 Dec 2006
    6.9
    Medium

    CVE-2006-6696

    Last Modified: 23 Apr 2026

    Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.

    Source:anonymous
    Published:22 Dec 2006
    7.5
    High

    CVE-2006-6694

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php.

    Source:Kacper
    Published:21 Dec 2006
    7.5
    High

    CVE-2006-6692

    Last Modified: 17 Feb 2017

    Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2) zabbix_syslog.

    Source:Max Vozeler
    Published:21 Dec 2006
    7.5
    High

    CVE-2006-6691

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php.

    Source:mdx
    Published:21 Dec 2006
    7.5
    High

    CVE-2006-6690

    Last Modified: 30 Oct 2013

    rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.

    Source:D. Fabian
    Published:21 Dec 2006
    6.8
    Medium

    CVE-2006-6686

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.

    Source:nuffsaid
    Published:21 Dec 2006
    5
    Medium

    CVE-2006-6673

    Last Modified: 23 Dec 2016

    WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands.

    Source:shinnai
    Published:21 Dec 2006
    7.5
    High

    CVE-2006-6671

    Last Modified: 20 Sept 2016

    SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ShaFuck31
    Published:21 Dec 2006
    7.5
    High

    CVE-2006-6666

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via a URL in the q parameter.

    Source:Kacper
    Published:20 Dec 2006
    6.8
    Medium

    CVE-2006-6665

    Last Modified: 10 Mar 2011

    Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name tag in a dbr file.

    Source:Metasploit
    Published:20 Dec 2006
    7.5
    High

    CVE-2006-6661

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

    Source:rgod
    Published:20 Dec 2006
    4.3
    Medium

    CVE-2006-6660

    Last Modified: 27 Oct 2016

    The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.

    Source:Federico L. Bossi Bonin
    Published:20 Dec 2006
    5
    Medium

    CVE-2006-6659

    Last Modified: 20 Sept 2016

    The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.

    Source:shinnai
    Published:20 Dec 2006