7.5
    High

    CVE-2006-6369

    Last Modified: 16 Sept 2016

    SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.

    Source:anonymous
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6368

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to search.php.

    Source:DeltahackingTEAM
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6367

    Last Modified: 27 Oct 2013

    Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.

    Source:Aria-Security Team
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6366

    Last Modified: 27 Oct 2013

    Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:En Douli
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6365

    Last Modified: 1 Jun 2013

    SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: the iState parameter is already covered by CVE-2005-3976 and the iPro parameter is already covered by CVE-2005-2047.

    Source:Dedi Dwianto
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6364

    Last Modified: 27 Oct 2013

    Cross-site scripting (XSS) vulnerability in error.php in Inside Systems Mail (ISMail) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Source:Vicente Aguilera Diaz
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6363

    Last Modified: 27 Oct 2013

    Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attackers to inject arbitrary web script or HTML via the ad_name parameter.

    Source:Jesus Olmos Gonzalez
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6360

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.

    Source:GregStar
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6356

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter.

    Source:Detefix
    Published:7 Dec 2006
    10
    Critical

    CVE-2006-6355

    Last Modified: 13 Dec 2013

    SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.

    Source:Aria-Security Team
    Published:7 Dec 2006
    5
    Medium

    CVE-2006-6352

    Last Modified: 23 Apr 2026

    FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file. NOTE: this issue has at least a partial overlap with CVE-2006-6294.

    Source:Evgeny Legerov
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6349

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) the main parameter in a view action (includes/mainpage/view.asp) in default.asp or (2) a query in the search engine.

    Source:ajann
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6343

    Last Modified: 26 Oct 2013

    SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6342

    Last Modified: 23 Oct 2013

    Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp.

    Source:laurent gaffie
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6341

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the apx_root_path parameter to (1) act/act_check_access.php, (2) dsp/dsp_form_booking_ctl.php, and (3) dsp/dsp_bookings.php.

    Source:v1per-haCker
    Published:7 Dec 2006
    5
    Medium

    CVE-2006-6340

    Last Modified: 25 Oct 2013

    keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue crosses security boundaries. If not, then this is not a vulnerability.

    Source:Hessam-x
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6339

    Last Modified: 26 Oct 2013

    SQL injection vulnerability in sites/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to execute arbitrary SQL commands via the show element in a GET request.

    Source:Tim Weber
    Published:7 Dec 2006
    5
    Medium

    CVE-2006-6338

    Last Modified: 16 Sept 2016

    Unrestricted file upload vulnerability in upload/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to upload and execute arbitrary .php files by embedding PHP code in a JPEG or GIF file that is uploaded to inc/images/uploads/userpics/.

    Source:Tim Weber
    Published:7 Dec 2006
    7.5
    High

    CVE-2006-6337

    Last Modified: 27 Oct 2013

    Multiple SQL injection vulnerabilities in giris.asp in Aspee and Dogantepe Ziyaretci Defteri allow remote attackers to execute arbitrary SQL commands via the (1) kullanici or (2) parola parameter.

    Source:ShaFuq31
    Published:7 Dec 2006
    6.8
    Medium

    CVE-2006-6334

    Last Modified: 11 Nov 2016

    Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.

    Source:Elazar
    Published:8 Dec 2006
    7.5
    High

    CVE-2006-6332

    Last Modified: 6 Mar 2011

    Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

    Source:Metasploit
    Published:10 Dec 2006
    6
    Medium

    CVE-2006-6330

    Last Modified: 14 Sept 2016

    index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.

    Source:r0ut3r
    Published:6 Dec 2006
    4.9
    Medium

    CVE-2006-6329

    Last Modified: 14 Sept 2016

    index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.

    Source:r0ut3r
    Published:6 Dec 2006
    4.9
    Medium

    CVE-2006-6328

    Last Modified: 14 Sept 2016

    Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.

    Source:r0ut3r
    Published:6 Dec 2006
    5
    Medium

    CVE-2006-6311

    Last Modified: 28 Oct 2013

    Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.

    Source:xiam.core
    Published:6 Dec 2006
    5
    Medium

    CVE-2006-6310

    Last Modified: 27 Oct 2013

    Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Juan Pablo Lopez
    Published:6 Dec 2006
    4.3
    Medium

    CVE-2006-6300

    Last Modified: 8 Dec 2016

    Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.

    Source:Detefix
    Published:5 Dec 2006
    7.5
    High

    CVE-2006-6298

    Last Modified: 27 Oct 2013

    SQL injection vulnerability in uye_giris_islem.asp in Metyus Okul Yonetim Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) kullanici_ismi and (2) sifre parameters.

    Source:ShaFuck31
    Published:5 Dec 2006
    6.1
    Medium

    CVE-2006-6296

    Last Modified: 23 Apr 2026

    The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.

    Source:h07
    Published:5 Dec 2006
    6.8
    Medium

    CVE-2006-6295

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:bd0rk
    Published:5 Dec 2006
    7.5
    High

    CVE-2006-6293

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file. NOTE: this issue has at least a partial overlap with CVE-2006-6294.

    Source:Evgeny Legerov
    Published:5 Dec 2006
    6.8
    Medium

    CVE-2006-6289

    Last Modified: 16 Sept 2016

    Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the wbb_userid parameter to the top-level URI. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in wBB Lite.

    Source:rgod
    Published:5 Dec 2006
    4.6
    Medium

    CVE-2006-6288

    Last Modified: 14 Nov 2016

    Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long song names, because of an overflow in the CPL_AddPrefixedFile function in CPI_Playlist.c; (2) a skin file with long button names, because of an overflow in the main_skin_check_ini_value function in skin.c; and (3) a skin file with long bitmap filenames, because of an overflow in the main_skin_open function in skin.c.

    Source:Trancek
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6287

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file.

    Source:Greg Linares
    Published:4 Dec 2006
    9
    Critical

    CVE-2006-6284

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in admin.php in Vikingboard 0.1.2 allows remote authenticated administrators to include arbitrary files via a .. (dot dot) sequence in the act parameter.

    Source:laurent gaffie
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6281

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in check_status.php in dicshunary 0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in the dicshunary_root_path parameter.

    Source:DeltahackingTEAM
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6280

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in viewthread.php in Oxygen (O2PHP Bulletin Board) 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-1572.

    Source:DarkFig
    Published:4 Dec 2006
    5
    Medium

    CVE-2006-6277

    Last Modified: 16 Sept 2016

    Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter, a different vector than CVE-2005-3086.

    Source:qobaiashi
    Published:4 Dec 2006
    6.8
    Medium

    CVE-2006-6272

    Last Modified: 25 Oct 2013

    Cross-site scripting (XSS) vulnerability in sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Source:Al7ejaz Hacker
    Published:4 Dec 2006
    9.3
    Critical

    CVE-2006-6261

    Last Modified: 23 Apr 2026

    Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a) NumberofEntries, (b) Length (aka Length1), (c) Filename (aka File1), (d) Title (aka Title1) field, or other unspecified fields.

    Source:Greg Linares
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6255

    Last Modified: 16 Sept 2016

    Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

    Source:DeltahackingTEAM
    Published:4 Dec 2006
    4.3
    Medium

    CVE-2006-6254

    Last Modified: 16 Sept 2016

    administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability.

    Source:DarkFig
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6251

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.

    Source:Metasploit
    Published:4 Dec 2006
    7.8
    High

    CVE-2006-6250

    Last Modified: 23 Apr 2026

    Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist file containing extended ASCII, which causes the Unicode converter to be invoked.

    Source:Greg Linares
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6247

    Last Modified: 26 Oct 2013

    Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci parameter to (1) slideshow.asp or (2) thumbnails.asp.

    Source:Aria-Security Team
    Published:4 Dec 2006
    7.5
    High

    CVE-2006-6243

    Last Modified: 25 Oct 2013

    Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter.

    Source:Aria-Security Team
    Published:4 Dec 2006
    6.8
    Medium

    CVE-2006-6242

    Last Modified: 31 Oct 2016

    Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins/ scripts (2) serendipity_event_bbcode/serendipity_event_bbcode.php, (3) serendipity_event_browsercompatibility/serendipity_event_browsercompatibility.php, (4) serendipity_event_contentrewrite/serendipity_event_contentrewrite.php, (5) serendipity_event_creativecommons/serendipity_event_creativecommons.php, (6) serendipity_event_emoticate/serendipity_event_emoticate.php, (7) serendipity_event_entryproperties/serendipity_event_entryproperties.php, (8) serendipity_event_karma/serendipity_event_karma.php, (9) serendipity_event_livesearch/serendipity_event_livesearch.php, (10) serendipity_event_mailer/serendipity_event_mailer.php, (11) serendipity_event_nl2br/serendipity_event_nl2br.php, (12) serendipity_event_s9ymarkup/serendipity_event_s9ymarkup.php, (13) serendipity_event_searchhighlight/serendipity_event_searchhighlight.php, (14) serendipity_event_spamblock/serendipity_event_spamblock.php, (15) serendipity_event_spartacus/serendipity_event_spartacus.php, (16) serendipity_event_statistics/serendipity_plugin_statistics.php, (17) serendipity_event_templatechooser/serendipity_event_templatechooser.php, (18) serendipity_event_textile/serendipity_event_textile.php, (19) serendipity_event_textwiki/serendipity_event_textwiki.php, (20) serendipity_event_trackexits/serendipity_event_trackexits.php, (21) serendipity_event_weblogping/serendipity_event_weblogping.php, (22) serendipity_event_xhtmlcleanup/serendipity_event_xhtmlcleanup.php, (23) serendipity_plugin_comments/serendipity_plugin_comments.php, (24) serendipity_plugin_creativecommons/serendipity_plugin_creativecommons.php, (25) serendipity_plugin_entrylinks/serendipity_plugin_entrylinks.php, (26) serendipity_plugin_eventwrapper/serendipity_plugin_eventwrapper.php, (27) serendipity_plugin_history/serendipity_plugin_history.php, (28) serendipity_plugin_recententries/serendipity_plugin_recententries.php, (29) serendipity_plugin_remoterss/serendipity_plugin_remoterss.php, (30) serendipity_plugin_shoutbox/serendipity_plugin_shoutbox.php, and and (31) serendipity_plugin_templatedropdown/serendipity_plugin_templatedropdown.php.

    Source:Kacper
    Published:3 Dec 2006
    7.5
    High

    CVE-2006-6237

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitrary SQL commands via the threadvisit Cookie parameter.

    Source:rgod
    Published:3 Dec 2006
    7.5
    High

    CVE-2006-6232

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:CrAsh_oVeR_rIdE
    Published:2 Dec 2006
    5.1
    Medium

    CVE-2006-6225

    Last Modified: 24 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc, (2) polls/functions.inc, (3) spamx/BlackList.Examine.class.php, (4) spamx/DeleteComment.Action.class.php, (5) spamx/EditIPofURL.Admin.class.php, (6) spamx/MTBlackList.Examine.class.php, (7) spamx/MassDelete.Admin.class.php, (8) spamx/MailAdmin.Action.class.php, (9) spamx/MassDelTrackback.Admin.class.php, (10) spamx/EditHeader.Admin.class.php, (11) spamx/EditIP.Admin.class.php, (12) spamx/IPofUrl.Examine.class.php, (13) spamx/Import.Admin.class.php, (14) spamx/LogView.Admin.class.php, and (15) staticpages/functions.inc, in the plugins/ directory.

    Source:Kw3[R]Ln
    Published:2 Dec 2006