10
    Critical

    CVE-2006-5972

    Last Modified: 9 Mar 2011

    Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.11 beacon request.

    Source:Metasploit
    Published:18 Nov 2006
    7.5
    High

    CVE-2006-5962

    Last Modified: 14 Sept 2016

    Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.

    Source:Security Access Point
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5961

    Last Modified: 27 Oct 2016

    Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The original researcher is reliable.

    Source:c0d3r
    Published:17 Nov 2006
    6.8
    Medium

    CVE-2006-5958

    Last Modified: 16 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c) sendpassword.asp.

    Source:laurent gaffie
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5957

    Last Modified: 16 Oct 2013

    Multiple SQL injection vulnerabilities in INFINICART allow remote attackers to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter in (c) browsesubcat.asp. NOTE: the vendor has disputed this report, saying "The vulnerabilities mentioned were never present in our official released products but only in the unofficial demo version. However we do appreciate the information. We have update our demo version and made sure all those vulnerabilities are fixed.

    Source:laurent gaffie
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5954

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.

    Source:ajann
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5952

    Last Modified: 1 Nov 2017

    SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field.

    Source:ajann
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5951

    Last Modified: 2 Jan 2017

    PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.

    Source:Firewall1954
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5948

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.

    Source:Hidayat Sagita
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5946

    Last Modified: 17 Oct 2013

    SQL injection vulnerability in demo/glossary/glossary.asp in FunkyASP Glossary 1.0 allows remote attackers to execute arbitrary SQL commands via the alpha parameter.

    Source:saps.audit
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5945

    Last Modified: 17 Oct 2013

    Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.

    Source:laurent gaffie
    Published:17 Nov 2006
    6.8
    Medium

    CVE-2006-5944

    Last Modified: 17 Oct 2013

    Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Source:laurent gaffie
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5943

    Last Modified: 17 Oct 2013

    Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.

    Source:laurent gaffie
    Published:17 Nov 2006
    7.5
    High

    CVE-2006-5936

    Last Modified: 17 Oct 2013

    SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Aria-Security Team
    Published:16 Nov 2006
    7.5
    High

    CVE-2006-5934

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.

    Source:ajann
    Published:16 Nov 2006
    7.5
    High

    CVE-2006-5930

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php.

    Source:navairum
    Published:16 Nov 2006
    7.5
    High

    CVE-2006-5928

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php.

    Source:Firewall
    Published:16 Nov 2006
    7.5
    High

    CVE-2006-5925

    Last Modified: 18 Oct 2013

    Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.

    Source:Teemu Salmela
    Published:15 Nov 2006
    5.8
    Medium

    CVE-2006-5924

    Last Modified: 14 Oct 2013

    Cross-site scripting (XSS) vulnerability in index.php in Efficient IP iPmanager (IPm) 2.3 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Source:spaceballyopsolo
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5923

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.

    Source:v1per-haCker
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5920

    Last Modified: 1 Oct 2013

    PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying "further analysis reveals that the application is not vulnerable." NOTE: this issue may overlap CVE-2006-5113

    Source:Root3r_H3ll
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5919

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.

    Source:igi
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5918

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field. NOTE: it is possible that the field value is restricted to files on specific public web sites.

    Source:DigitALL
    Published:15 Nov 2006
    6.8
    Medium

    CVE-2006-5915

    Last Modified: 14 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter.

    Source:laurent gaffie
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5914

    Last Modified: 14 Oct 2013

    SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter. NOTE: the start, search_order, search_type, and search_area parameters are already covered by CVE-2005-4018.

    Source:laurent gaffie
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5911

    Last Modified: 3 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/.

    Source:anonymous
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5910

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.

    Source:Kw3[R]Ln
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5899

    Last Modified: 13 Oct 2013

    PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter. NOTE: this issue has been disputed by a third party, who states that install.php3 is supposed to be deleted after installation and, if not deleted, intentionally allows setting repertoire without an inclusion attack

    Source:Mahmood_ali
    Published:15 Nov 2006
    7.5
    High

    CVE-2006-5895

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:Firewall
    Published:14 Nov 2006
    6.8
    Medium

    CVE-2006-5894

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.

    Source:Kacper
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5893

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/.

    Source:v1per-haCker
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5892

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5891

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5890

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5889

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Craig Heffner
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5888

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5887

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5886

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5885

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.

    Source:ajann
    Published:14 Nov 2006
    3.5
    Low

    CVE-2006-5883

    Last Modified: 16 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir parameters in (b) newuser.html.

    Source:Aria-Security Team
    Published:14 Nov 2006
    8.3
    High

    CVE-2006-5882

    Last Modified: 1 Apr 2017

    Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field.

    Source:H D Moore
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5880

    Last Modified: 23 Apr 2026

    SQL injection vulnerability on the subMenu page in switch.asp in Munch Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:ajann
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-5879

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbitrary SQL commands via the Poll_ID parameter, a different vector than CVE-2006-1353.

    Source:ajann
    Published:14 Nov 2006
    6.4
    Medium

    CVE-2006-5866

    Last Modified: 14 Sept 2016

    Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.

    Source:ajann
    Published:11 Nov 2006
    7.5
    High

    CVE-2006-5865

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language.inc.php in MyAlbum 3.02 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the langs_dir parameter.

    Source:Silahsiz Kuvvetler
    Published:11 Nov 2006
    5.1
    Medium

    CVE-2006-5864

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.

    Source:K-sPecial
    Published:11 Nov 2006
    7.5
    High

    CVE-2006-5863

    Last Modified: 15 Dec 2016

    PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

    Source:v1per-haCker
    Published:11 Nov 2006
    7.5
    High

    CVE-2006-5854

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions.

    Source:Andres Tarasco
    Published:3 Dec 2006
    6.8
    Medium

    CVE-2006-5853

    Last Modified: 14 Oct 2013

    Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject arbitrary web script or HTML via the lang parameter, which is returned to the client in a lang cookie.

    Source:Gemma Hughes
    Published:10 Nov 2006