6.8
    Medium

    CVE-2006-6220

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to execute arbitrary SQL commands via the (1) recipeid parameter to recipe.php or the (2) categoryid parameter to list.php.

    Source:GregStar
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6216

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remote attackers to execute arbitrary SQL commands via the hack_id parameter.

    Source:the master
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6214

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid parameter.

    Source:GregStar
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6213

    Last Modified: 16 Sept 2016

    index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value.

    Source:DeltahackingTEAM
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6212

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in centre.php in Site News (site_news) 2.00, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:DaDIsS
    Published:1 Dec 2006
    6.8
    Medium

    CVE-2006-6211

    Last Modified: 11 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to (a) admin/admincore.php, the (2) month parameter to (b) admin/comments.php or (c) admin/entries.php, or the (3) page parameter to (d) admin/logs.php, different vectors than CVE-2006-5064.

    Source:the_Edit0r
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6210

    Last Modified: 25 Oct 2013

    SQL injection vulnerability in listpics.asp in ASP ListPics 5.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:Aria-Security Team
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6209

    Last Modified: 25 Oct 2013

    Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to Item_Show.asp is covered by CVE-2005-2601.

    Source:Aria-Security Team
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6208

    Last Modified: 22 Oct 2013

    Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp.

    Source:laurent gaffie
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6207

    Last Modified: 26 Oct 2013

    SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error

    Source:Aria-Security Team
    Published:1 Dec 2006
    6.8
    Medium

    CVE-2006-6205

    Last Modified: 22 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web script or HTML via the (1) city or (2) State parameter.

    Source:laurent gaffie
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6204

    Last Modified: 22 Oct 2013

    Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid parameter to (b) dirSub.asp; the (3) TYPE_ID parameter to (c) types.asp; the (4) AD_ID parameter to (d) homeDetail.asp; the (5) cat parameter to (e) result.asp; the (6) compare, (7) clear, and (8) adID parameters to (f) compareHomes.asp; and the (9) aminprice, (10) amaxprice, and (11) abedrooms parameters to (g) result.asp.

    Source:laurent gaffie
    Published:1 Dec 2006
    5
    Medium

    CVE-2006-6203

    Last Modified: 31 Oct 2016

    Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:3l3ctric-Cracker
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6202

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in modules/NukeAI/util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to execute arbitrary PHP code via a URL in the AIbasedir parameter.

    Source:DeltahackingTEAM
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6199

    Last Modified: 23 Jun 2010

    Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist.

    Source:mr_me
    Published:1 Dec 2006
    6
    Medium

    CVE-2006-6198

    Last Modified: 25 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addon_configsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.

    Source:Aria-Security Team
    Published:1 Dec 2006
    6.8
    Medium

    CVE-2006-6197

    Last Modified: 26 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.

    Source:lotto fischer
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6195

    Last Modified: 25 Oct 2013

    Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.

    Source:Aria-Security Team
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6193

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in edit.asp in BasicForum 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:bolivar
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6191

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:bolivar
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6189

    Last Modified: 25 Oct 2013

    SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter.

    Source:Aria-Security Team
    Published:1 Dec 2006
    5
    Medium

    CVE-2006-6185

    Last Modified: 23 Oct 2013

    Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.

    Source:the_Edit0r
    Published:1 Dec 2006
    10
    Critical

    CVE-2006-6184

    Last Modified: 27 Oct 2016

    Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command.

    Source:Socket_0x03
    Published:1 Dec 2006
    10
    Critical

    CVE-2006-6183

    Last Modified: 27 Oct 2016

    Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command.

    Source:Liu Qixu
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6181

    Last Modified: 25 Oct 2013

    Multiple SQL injection vulnerabilities in default.asp in ClickTech ClickContact allow remote attackers to execute arbitrary SQL commands via the (1) AlphaSort, (2) In, and (3) orderby parameters.

    Source:Aria-Security Team
    Published:1 Dec 2006
    7.5
    High

    CVE-2006-6177

    Last Modified: 16 Sept 2016

    SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).

    Source:nukedx
    Published:30 Nov 2006
    7.2
    High

    CVE-2006-6173

    Last Modified: 6 Sept 2016

    Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the shared_region_make_private_np_args parameter.

    Source:LMH
    Published:30 Nov 2006
    7.5
    High

    CVE-2006-6160

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:28 Nov 2006
    6.8
    Medium

    CVE-2006-6158

    Last Modified: 25 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.

    Source:SwEET-DeViL
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6157

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter. NOTE: this issue can be leveraged for path disclosure with an invalid pageid parameter.

    Source:Revenge
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6154

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.

    Source:Cold Zero
    Published:28 Nov 2006
    4.3
    Medium

    CVE-2006-6153

    Last Modified: 21 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to inject arbitrary web script or HTML via (1) catname parameter to cat.asp or the (2) minprice parameter to search.asp.

    Source:laurent gaffie
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6152

    Last Modified: 21 Oct 2013

    Multiple SQL injection vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to (a) cat.asp, or the (2) keyword, (3) order, (4) sort, (5) menuSelect, or (6) state parameter to (b) search.asp.

    Source:laurent gaffie
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6151

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in centre.php in Messagerie Locale as of 20061127 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:DaDIsS
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6150

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the OWLLIB_ROOT parameter.

    Source:DeltahackingTEAM
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6149

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in JiRos FAQ Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the tID parameter.

    Source:ajann
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6147

    Last Modified: 24 Oct 2013

    Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.

    Source:laurent gaffie
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6140

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and (2) print.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Wawan Firmansyah
    Published:28 Nov 2006
    5
    Medium

    CVE-2006-6138

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

    Source:Wawan Firmansyah
    Published:28 Nov 2006
    7.5
    High

    CVE-2006-6137

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec parameter to index.php or (2) print parameter to print.php, which is also accessible via the print command to index.php.

    Source:Wawan Firmansyah
    Published:28 Nov 2006
    7.6
    High

    CVE-2006-6133

    Last Modified: 28 Oct 2013

    Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.

    Source:LSsec.com
    Published:28 Nov 2006
    6.2
    Medium

    CVE-2006-6131

    Last Modified: 14 Sept 2016

    Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

    Source:Kevin Finisterre
    Published:28 Nov 2006
    4.9
    Medium

    CVE-2006-6130

    Last Modified: 25 Oct 2013

    Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

    Source:LMH
    Published:28 Nov 2006
    4.6
    Medium

    CVE-2006-6129

    Last Modified: 28 Oct 2013

    Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.

    Source:LMH
    Published:27 Nov 2006
    7.5
    High

    CVE-2006-6125

    Last Modified: 12 Sept 2016

    Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID.

    Source:Laurent Butti
    Published:27 Nov 2006
    6.8
    Medium

    CVE-2006-6124

    Last Modified: 18 Oct 2013

    Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Greg Linares
    Published:26 Nov 2006
    9.3
    Critical

    CVE-2006-6121

    Last Modified: 16 Sept 2016

    Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.

    Source:Tan Chew Keong
    Published:26 Nov 2006
    6.8
    Medium

    CVE-2006-6118

    Last Modified: 25 Oct 2013

    Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Al7ejaz Hacker
    Published:26 Nov 2006
    7.5
    High

    CVE-2006-6117

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.

    Source:ajann
    Published:26 Nov 2006
    7.5
    High

    CVE-2006-6116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Source:ajann
    Published:26 Nov 2006