7.5
    High

    CVE-2006-6551

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tucows Client Code Suite (CCS) 1.2.1015 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _ENV[TCA_HOME] parameter.

    Source:3l3ctric-Cracker
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6550

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use

    Source:Mr-m07
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6546

    Last Modified: 12 Jan 2017

    PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter.

    Source:DeltahackingTEAM
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6545

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:bd0rk
    Published:14 Dec 2006
    6.8
    Medium

    CVE-2006-6544

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Paul Bakoyiannis
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6543

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) login (UserName) and possibly (2) password parameter. NOTE: some of these details are obtained from third party information.

    Source:ajann
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6542

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Bl0od3r
    Published:14 Dec 2006
    7.8
    High

    CVE-2006-6538

    Last Modified: 23 Apr 2026

    D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the wireless link.

    Source:poplix
    Published:14 Dec 2006
    6.8
    Medium

    CVE-2006-6536

    Last Modified: 4 Oct 2017

    Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ShaFuck31
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6526

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.

    Source:DeltahackingTEAM
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6525

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ajann
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6524

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.

    Source:ajann
    Published:14 Dec 2006
    6.8
    Medium

    CVE-2006-6523

    Last Modified: 30 Dec 2016

    Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter.

    Source:Aria-Security Team
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6521

    Last Modified: 28 Oct 2013

    SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.

    Source:Mr_KaLiMaN
    Published:14 Dec 2006
    6.8
    Medium

    CVE-2006-6520

    Last Modified: 28 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php.

    Source:Mr_KaLiMaN
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6519

    Last Modified: 29 Oct 2013

    SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.

    Source:Mr_KaLiMaN
    Published:14 Dec 2006
    6.8
    Medium

    CVE-2006-6518

    Last Modified: 29 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and (7) lien parameters to (a) admin/change.php, and the (8) aa parameter to (b) lire-avis.php.

    Source:Mr_KaLiMaN
    Published:14 Dec 2006
    6.8
    Medium

    CVE-2006-6517

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) categories parameter to (a) index.php3 or (b) galeries.inc.php3.

    Source:AsTrex
    Published:14 Dec 2006
    7.5
    High

    CVE-2006-6516

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) page parameter to (a) index.php3, or the (2) lib_path parameter to (b) authenticate.inc.php3 or (c) lib/exifer/exif.php.

    Source:AsTrex
    Published:14 Dec 2006
    5.1
    Medium

    CVE-2006-6493

    Last Modified: 20 Sept 2016

    Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.

    Source:Solar Eclipse
    Published:13 Dec 2006
    7.5
    High

    CVE-2006-6488

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.

    Source:Kevin Finisterre
    Published:31 Dec 2006
    5.1
    Medium

    CVE-2006-6487

    Last Modified: 6 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter.

    Source:Jesper Jurcenoks
    Published:16 Jan 2007
    6.8
    Medium

    CVE-2006-6479

    Last Modified: 28 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php.

    Source:Mr_KaLiMaN
    Published:12 Dec 2006
    7.5
    High

    CVE-2006-6478

    Last Modified: 28 Oct 2013

    Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c) admin/admin_membre/fiche_membre.php, and the (4) idannonce parameter in (d) admin/admin_annonce/okvalannonce.php and (e) admin/admin_annonce/changeannonce.php.

    Source:Mr_KaLiMaN
    Published:12 Dec 2006
    7.5
    High

    CVE-2006-6462

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.

    Source:Paul Bakoyiannis
    Published:11 Dec 2006
    6.5
    Medium

    CVE-2006-6453

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the link parameter.

    Source:3l3ctric-Cracker
    Published:10 Dec 2006
    6.8
    Medium

    CVE-2006-6451

    Last Modified: 17 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.

    Source:David Vieira-Kurz
    Published:10 Dec 2006
    6.8
    Medium

    CVE-2006-6447

    Last Modified: 27 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.

    Source:St@rExT
    Published:10 Dec 2006
    6.8
    Medium

    CVE-2006-6446

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the D parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:boom3rang
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6445

    Last Modified: 16 Sept 2016

    Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

    Source:Kacper
    Published:10 Dec 2006
    6.8
    Medium

    CVE-2006-6426

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the template_file parameter.

    Source:r0ut3r
    Published:10 Dec 2006
    9
    Critical

    CVE-2006-6425

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.

    Source:Metasploit
    Published:27 Dec 2006
    9
    Critical

    CVE-2006-6424

    Last Modified: 7 Mar 2011

    Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.

    Source:Metasploit
    Published:27 Dec 2006
    10
    Critical

    CVE-2006-6423

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a pre-authentication command followed by a crafted parameter and a long string, as addressed by the ME-10025 hotfix.

    Source:mu-b
    Published:12 Dec 2006
    6
    Medium

    CVE-2006-6421

    Last Modified: 5 Nov 2013

    Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

    Source:Demential
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6417

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.

    Source:tarkus
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6416

    Last Modified: 11 Oct 2013

    Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a URL in the cheminmini parameter to (1) consult/miniseul.php or (2) config.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ajaan
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6414

    Last Modified: 27 Oct 2013

    Multiple SQL injection vulnerabilities in dettaglio.asp in dol storye allow remote attackers to execute arbitrary SQL commands via the (1) id_doc or (2) id_aut parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:WarGame
    Published:10 Dec 2006
    4.6
    Medium

    CVE-2006-6410

    Last Modified: 23 Apr 2026

    Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.

    Source:c0ntex
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6396

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-2006-6199. NOTE: it was later reported that 3.5 is also affected.

    Source:Greg Linares
    Published:8 Dec 2006
    6.8
    Medium

    CVE-2006-6391

    Last Modified: 14 Sept 2016

    Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include arbitrary files via a .. (dot dot) in the config[db_type] parameter to (1) actions_admin/other.php and (2) actions_client/gallery.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Kacper
    Published:8 Dec 2006
    6.8
    Medium

    CVE-2006-6390

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the config[db_type] parameter to (1) categories.php, (2) couriers.php, (3) orders.php, and (4) products.php in actions_admin/; and (5) orders.php and (6) products.php in actions_client/; as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by one of these PHP scripts.

    Source:r0ut3r
    Published:8 Dec 2006
    6.8
    Medium

    CVE-2006-6389

    Last Modified: 27 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.

    Source:SwEET-DeViL
    Published:8 Dec 2006
    7.5
    High

    CVE-2006-6387

    Last Modified: 27 Oct 2013

    Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ivan Markovic
    Published:8 Dec 2006
    4.6
    Medium

    CVE-2006-6383

    Last Modified: 28 Oct 2013

    PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.

    Source:Maksymilian Arciemowicz
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6381

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:ajann
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6380

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Source:ajann
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6379

    Last Modified: 15 Nov 2017

    Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCserve Backup r11.5 SP1 and earlier, ARCserve Backup 9.01 up to 11.1, Enterprise Backup 10.5, and CA Server Protection Suite r2, allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:cybertronic
    Published:10 Dec 2006
    7.5
    High

    CVE-2006-6377

    Last Modified: 23 Apr 2026

    Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt.

    Source:Mr.aFiR
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6376

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.

    Source:flame
    Published:7 Dec 2006