9
    Critical

    CVE-2006-6652

    Last Modified: 16 Sept 2016

    Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.

    Source:kingcope
    Published:20 Dec 2006
    6.8
    Medium

    CVE-2006-6651

    Last Modified: 28 Apr 2011

    Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corruption and execute arbitrary code via a series of crafted beacon frames. NOTE: some details are obtained solely from third party information.

    Source:Breno Silva Pinto
    Published:20 Dec 2006
    6.8
    Medium

    CVE-2006-6650

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:ajann
    Published:20 Dec 2006
    7.5
    High

    CVE-2006-6648

    Last Modified: 20 Sept 2016

    PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter.

    Source:Al7ejaz Hacker
    Published:20 Dec 2006
    7.5
    High

    CVE-2006-6645

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Source:ajann
    Published:20 Dec 2006
    6.8
    Medium

    CVE-2006-6644

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:ajann
    Published:20 Dec 2006
    5
    Medium

    CVE-2006-6643

    Last Modified: 27 Apr 2011

    Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long arguments.

    Source:Necro
    Published:20 Dec 2006
    7.5
    High

    CVE-2006-6642

    Last Modified: 30 Oct 2013

    SQL injection vulnerability in haber.asp in Contra Haber Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ShaFuck31
    Published:20 Dec 2006
    6.8
    Medium

    CVE-2006-6640

    Last Modified: 29 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.

    Source:Hackers Center Security
    Published:19 Dec 2006
    7.5
    High

    CVE-2006-6635

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the jcms_root_path parameter.

    Source:Kw3[R]Ln
    Published:18 Dec 2006
    7.5
    High

    CVE-2006-6634

    Last Modified: 12 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php, or (3) the CONFIG_EXT[LIB_DIR] parameter to lib/mail.inc.php.

    Source:k1tk4t
    Published:18 Dec 2006
    7.5
    High

    CVE-2006-6633

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in include/yapbb_session.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[include_Bit] parameter.

    Source:Kacper
    Published:18 Dec 2006
    6.8
    Medium

    CVE-2006-6632

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the topdir parameter.

    Source:Kw3[R]Ln
    Published:18 Dec 2006
    6.8
    Medium

    CVE-2006-6631

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter.

    Source:Kw3[R]Ln
    Published:18 Dec 2006
    4.3
    Medium

    CVE-2006-6628

    Last Modified: 23 Apr 2026

    Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.

    Source:DiscoJonny
    Published:18 Dec 2006
    6.8
    Medium

    CVE-2006-6625

    Last Modified: 29 Oct 2013

    Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Jose Miguel Yanez Venegas
    Published:18 Dec 2006
    4
    Medium

    CVE-2006-6624

    Last Modified: 6 Sept 2017

    The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command.

    Source:rgod
    Published:18 Dec 2006
    7.2
    High

    CVE-2006-6619

    Last Modified: 11 Nov 2013

    AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

    Source:Matousec Transparent security
    Published:18 Dec 2006
    7.5
    High

    CVE-2006-6615

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:3l3ctric-Cracker
    Published:18 Dec 2006
    6.8
    Medium

    CVE-2006-6613

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.

    Source:Kacper
    Published:18 Dec 2006
    7.5
    High

    CVE-2006-6612

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath_start parameter.

    Source:v1per-haCker
    Published:18 Dec 2006
    7.5
    High

    CVE-2006-6611

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.

    Source:DeltahackingTEAM
    Published:18 Dec 2006
    6.5
    Medium

    CVE-2006-6604

    Last Modified: 16 Sept 2016

    Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the alias parameter, a different vector than CVE-2006-6328.

    Source:r0ut3r
    Published:15 Dec 2006
    4.3
    Medium

    CVE-2006-6602

    Last Modified: 31 Mar 2017

    explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.

    Source:shinnai
    Published:15 Dec 2006
    4.3
    Medium

    CVE-2006-6601

    Last Modified: 27 Oct 2016

    Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.

    Source:shinnai
    Published:15 Dec 2006
    6
    Medium

    CVE-2006-6599

    Last Modified: 16 Sept 2016

    maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter.

    Source:r0ut3r
    Published:15 Dec 2006
    6.5
    Medium

    CVE-2006-6598

    Last Modified: 16 Sept 2016

    Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the path parameter, a different vector than CVE-2006-6328.

    Source:r0ut3r
    Published:15 Dec 2006
    6.8
    Medium

    CVE-2006-6597

    Last Modified: 29 Oct 2013

    Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option in a telnet:// URI, which is configured to use hawin32.exe.

    Source:Brett Moore
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6593

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6592

    Last Modified: 13 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

    Source:KorsaN
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6590

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.

    Source:ex0
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6586

    Last Modified: 14 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter in (1) secure.php or (2) checklogin.php in admin/auth/.

    Source:DeltahackingTEAM
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6581

    Last Modified: 17 Oct 2013

    PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.

    Source:Firewall
    Published:15 Dec 2006
    6.8
    Medium

    CVE-2006-6577

    Last Modified: 16 Sept 2016

    SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6576

    Last Modified: 28 Jun 2018

    Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.

    Source:cd1zz & iglesiasgg
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6575

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the LOGIN_style parameter.

    Source:DeltahackingTEAM
    Published:15 Dec 2006
    6.8
    Medium

    CVE-2006-6571

    Last Modified: 29 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other parameters.

    Source:Mr_KaLiMaN
    Published:15 Dec 2006
    7.8
    High

    CVE-2006-6569

    Last Modified: 29 Oct 2013

    form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2) chem parameters with a "modfich" floap parameter.

    Source:Mr_KaLiMaN
    Published:15 Dec 2006
    10
    Critical

    CVE-2006-6568

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the phpEx parameter.

    Source:3l3ctric-Cracker
    Published:15 Dec 2006
    10
    Critical

    CVE-2006-6567

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:3l3ctric-Cracker
    Published:15 Dec 2006
    7.5
    High

    CVE-2006-6566

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:bd0rk
    Published:15 Dec 2006
    4
    Medium

    CVE-2006-6565

    Last Modified: 16 Sept 2016

    FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

    Source:shinnai
    Published:15 Dec 2006
    4
    Medium

    CVE-2006-6564

    Last Modified: 16 Sept 2016

    FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

    Source:rgod
    Published:15 Dec 2006
    6.6
    Medium

    CVE-2006-6563

    Last Modified: 29 Aug 2017

    Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value.

    Source:Core Security
    Published:15 Dec 2006
    9.3
    Critical

    CVE-2006-6561

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.

    Source:DiscoJonny
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6560

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:Lu7k
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6559

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute arbitrary SQL commands via the PID parameter.

    Source:ajann
    Published:14 Dec 2006
    5
    Medium

    CVE-2006-6558

    Last Modified: 23 Apr 2026

    Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2) NLST command.

    Source:shinnai
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6553

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Source:3l3ctric-Cracker
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6552

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter.

    Source:HACKERS PAL
    Published:14 Dec 2006