7.5
    High

    CVE-2006-6115

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

    Source:ajann
    Published:26 Nov 2006
    7.5
    High

    CVE-2006-6111

    Last Modified: 20 Oct 2013

    Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873.

    Source:laurent gaffie
    Published:26 Nov 2006
    7.5
    High

    CVE-2006-6109

    Last Modified: 18 Oct 2013

    Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.

    Source:laurent gaffie
    Published:26 Nov 2006
    5
    Medium

    CVE-2006-6104

    Last Modified: 30 Oct 2013

    The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

    Source:jose.palanco
    Published:21 Dec 2006
    4
    Medium

    CVE-2006-6097

    Last Modified: 15 Nov 2017

    GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.

    Source:Teemu Salmela
    Published:21 Nov 2006
    4.3
    Medium

    CVE-2006-6096

    Last Modified: 8 Dec 2016

    Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:laurent gaffie
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6095

    Last Modified: 8 Dec 2016

    Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.

    Source:laurent gaffie
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6094

    Last Modified: 8 Dec 2016

    Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp.

    Source:laurent gaffie
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6093

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.

    Source:irvian
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6092

    Last Modified: 20 Oct 2013

    Multiple SQL injection vulnerabilities in vehiclelistings.asp in 20/20 Auto Gallery allow remote attackers to execute arbitrary SQL commands via the (1) vehicleID, (2) categoryID_list, (3) sale_type, (4) stock_number, (5) manufacturer, (6) model, (7) vehicleID, (8) year, (9) vin, and (10) listing_price parameters.

    Source:laurent gaffie
    Published:24 Nov 2006
    4.3
    Medium

    CVE-2006-6088

    Last Modified: 18 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery field, or the myquery parameter, in search.asp. NOTE: some of these details are obtained from third party information.

    Source:Aria-Security Team
    Published:24 Nov 2006
    4.3
    Medium

    CVE-2006-6087

    Last Modified: 24 Oct 2013

    Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Source:the_Edit0r
    Published:24 Nov 2006
    5.1
    Medium

    CVE-2006-6086

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pear_path parameter.

    Source:DeltahackingTEAM
    Published:24 Nov 2006
    5
    Medium

    CVE-2006-6084

    Last Modified: 16 Sept 2016

    Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information.

    Source:Security Access Point
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6083

    Last Modified: 24 Oct 2013

    SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:laurent gaffie
    Published:24 Nov 2006
    4.3
    Medium

    CVE-2006-6082

    Last Modified: 24 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.

    Source:laurent gaffie
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6080

    Last Modified: 22 Oct 2013

    Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote attackers to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter.

    Source:Aria-Security Team
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6078

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the cm_basedir parameter.

    Source:Matdhule
    Published:24 Nov 2006
    10
    Critical

    CVE-2006-6076

    Last Modified: 10 Mar 2011

    Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.

    Source:Metasploit
    Published:24 Nov 2006
    7.5
    High

    CVE-2006-6070

    Last Modified: 16 Sept 2016

    SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrary SQL commands via the StateCode parameter.

    Source:ajann
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6067

    Last Modified: 20 Oct 2013

    Multiple SQL injection vulnerabilities in 20/20 DataShed (aka Real Estate Listing System) allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) f-email.asp, or the (2) peopleID and (2) sort_order parameters to (b) listings.asp, different vectors than CVE-2006-5955.

    Source:laurent gaffie
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6066

    Last Modified: 18 Oct 2013

    Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.

    Source:Benjamin Moss
    Published:22 Nov 2006
    5.1
    Medium

    CVE-2006-6065

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:bd0rk
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6063

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.

    Source:Metasploit
    Published:22 Nov 2006
    5.1
    Medium

    CVE-2006-6062

    Last Modified: 28 Oct 2013

    Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.

    Source:LMH
    Published:22 Nov 2006
    10
    Critical

    CVE-2006-6059

    Last Modified: 21 Oct 2013

    Buffer overflow in MA521nd5.SYS driver 5.148.724.2003 for NetGear MA521 PCMCIA adapter allows remote attackers to execute arbitrary code via (1) beacon or (2) probe 802.11 frame responses with an long supported rates information element. NOTE: this issue was reported as a "memory corruption" error, but the associated exploit code suggests that it is a buffer overflow.

    Source:Laurent Butti
    Published:22 Nov 2006
    10
    Critical

    CVE-2006-6055

    Last Modified: 1 Apr 2017

    Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code via a 802.11 beacon request with a long Rates information element (IE).

    Source:H D Moore
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6051

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Crackers_Child
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6050

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in ClickTech Texas Rank'em allow remote attackers to execute arbitrary SQL commands via the (1) selPlayer parameter to player.asp or the (2) tournament_id parameter to tournaments.asp.

    Source:Aria-Security Team
    Published:22 Nov 2006
    5.8
    Medium

    CVE-2006-6047

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

    Source:Revenge
    Published:22 Nov 2006
    6.8
    Medium

    CVE-2006-6045

    Last Modified: 16 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URL in the path[skin] parameter to (1) adminfoot.php, (2) adminhead.php, or (3) adminlogin.php.

    Source:w4ck1ng
    Published:22 Nov 2006
    6.8
    Medium

    CVE-2006-6044

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the textFile parameter.

    Source:Al7ejaz Hacker
    Published:22 Nov 2006
    6.8
    Medium

    CVE-2006-6042

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_bottom parameter.

    Source:nuffsaid
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6041

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to (1) index.php, (2) module/forum/forum.php, (3) unspecified files under module/, and (4) unspecified files under administration/module/.

    Source:SlimTim10
    Published:22 Nov 2006
    6.8
    Medium

    CVE-2006-6040

    Last Modified: 20 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action.

    Source:insanity
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6039

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter.

    Source:SHiKaA
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6038

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:SHiKaA
    Published:22 Nov 2006
    6.8
    Medium

    CVE-2006-6035

    Last Modified: 21 Oct 2013

    Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the FADDR parameter.

    Source:Katatafish
    Published:22 Nov 2006
    7.5
    High

    CVE-2006-6029

    Last Modified: 14 Sept 2016

    SQL injection vulnerability in vir_Login.asp in Property Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the UserName field.

    Source:ajann
    Published:21 Nov 2006
    5
    Medium

    CVE-2006-6028

    Last Modified: 8 Nov 2016

    Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence or absolute file path in the file parameter.

    Source:Craig Heffner
    Published:21 Nov 2006
    9.3
    Critical

    CVE-2006-6027

    Last Modified: 20 Oct 2013

    Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.

    Source:Michal Bucko
    Published:21 Nov 2006
    10
    Critical

    CVE-2006-6026

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request that contains an invalid LoadTestPassword field.

    Source:Winny Thomas
    Published:21 Nov 2006
    6.8
    Medium

    CVE-2006-6022

    Last Modified: 20 Oct 2013

    Cross-site scripting (XSS) vulnerability in login_form.asp in BestWebApp Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:laurent gaffie
    Published:21 Nov 2006
    7.5
    High

    CVE-2006-6021

    Last Modified: 20 Oct 2013

    SQL injection vulnerability in the login component in BestWebApp Dating Site allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Source:laurent gaffie
    Published:21 Nov 2006
    6.8
    Medium

    CVE-2006-6020

    Last Modified: 18 Oct 2013

    Cross-site scripting (XSS) vulnerability in announce.php in Blog Torrent Preview 0.92 allows remote attackers to inject arbitrary web script or HTML via the left parameter.

    Source:the_Edit0r
    Published:21 Nov 2006
    5
    Medium

    CVE-2006-6015

    Last Modified: 17 Oct 2013

    Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression.

    Source:jbh_cg
    Published:21 Nov 2006
    7.5
    High

    CVE-2006-5987

    Last Modified: 17 Oct 2013

    SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote attackers to execute arbitrary SQL commands via the a parameter.

    Source:Aria-Security Team
    Published:20 Nov 2006
    6
    Medium

    CVE-2006-5983

    Last Modified: 8 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user parameter to (a) CMD_SHOW_RESELLER or (b) CMD_SHOW_USER in the Admin level; the (2) TYPE parameter to (c) CMD_TICKET_CREATE or (d) CMD_TICKET, the (3) user parameter to (e) CMD_EMAIL_FORWARDER_MODIFY, (f) CMD_EMAIL_VACATION_MODIFY, or (g) CMD_FTP_SHOW, and the (4) name parameter to (h) CMD_EMAIL_LIST in the User level; or the (5) user parameter to (i) CMD_SHOW_USER in the Reseller level.

    Source:Aria-Security Team
    Published:20 Nov 2006
    7.5
    High

    CVE-2006-5976

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: some of these details are obtained from third party information.

    Source:Security Access Point
    Published:20 Nov 2006
    6.8
    Medium

    CVE-2006-5975

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.

    Source:Security Access Point
    Published:20 Nov 2006